WPScan.org

WordPress Plugin Security Scanner

WordPress plugins are the #1 attack surface for WordPress sites — they're installed by millions of sites and written by developers with varying security expertise. Before installing a custom or premium plugin, upload the ZIP here to scan its PHP, JavaScript, and HTML files for SQL injection, XSS, file inclusion, command injection, hardcoded credentials, and 40+ other vulnerability patterns.

What WP Scan detects

  • SQL injection via unsanitized input in custom queries
  • Cross-site scripting in plugin front-end output
  • Local and remote file inclusion vulnerabilities
  • Hardcoded API keys, passwords, or database credentials
  • CSRF vulnerabilities — missing nonce checks on admin actions
  • Insecure direct object references in AJAX handlers

Scan your WordPress files now — free

Drop your ZIP here

or click to browse · up to 20 MB free

Want to see what a Premium report looks like?

View a real scan with line numbers, fix guides, and secure code for every finding.

View sample report →

Common questions

See exact line numbers and fix guides for every finding

Upgrade to Premium — from $7.99/mo →