wpsecscan is an open-source CLI tool for defensive security scanning of WordPress sites. It performs over 200 checks, aggregates CVEs, supports AI-assisted remediation, and covers multiple compliance frameworks, making it valuable for security professionals and administrators.
In the Penetration testing & red teaming space, wpsecscan takes a focused approach. It focuses on automating comprehensive security scanning and remediation for WordPress sites. wpsecscan is an open-source project aimed at security professionals and WordPress administrators. wpsecscan is open source under the AGPL-3.0 license. It ships for the command line, and it can be self-hosted.
It is developed by Bryan Flowers, and it first shipped in 2026. Development happens publicly on GitHub with 238 commits in the last 90 days. Key capabilities include wordPress scanning, CVE aggregation, and AI remediation.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do