{"repo":"Chocapikk/wpprobe","free":true,"listed":false,"github":"https://github.com/Chocapikk/wpprobe","clone":"git clone https://github.com/Chocapikk/wpprobe.git","description":"A fast WordPress plugin enumeration tool","language":"Go","stars":931,"topics":["bug-bounty","enumeration","exploit","pentest","recon","rest-api","security","security-tools","wordfence","wordpress"],"license":"MIT","category":"security-tools","readme_excerpt":"\"Because why scan blind when WordPress exposes itself?\" --- WPProbe A fast WordPress plugin and theme scanner that detects installed plugins via REST API enumeration and themes from HTML discovery, then maps them to known vulnerabilities. Over 5000 plugins detectable without brute-force, thousands more with it. Important: Wordfence API Change Since March 9, 2026, Wordfence deprecated their v2 API. All WPProbe versions prior to v0.10.16 have broken update-db functionality. You need to update WPProbe. By default, wpprobe update-db fetches a pre-built database from this repo (updated every 2h via CI), so no API key is needed. If you want to fetch directly from Wordfence yourself, you can optionally set up a free API key: 1. Create an account at wordfence.com 2. Go to Account Integrations and generate an API key 3. Set it via environment variable or --api-key flag Quick Start Scanning Modes Mode Method Stealth Coverage ------ -------- --------- ---------- stealthy (default) REST API endpoint matching + HTML theme discovery High 5000+ plugins + themes bruteforce Direct directory checks Low 10k+ plugins hybrid Stealthy first, then brute-force Medium Maximum Installation Docker with file mounting Usage Scanning Vulnerability Database Set WORDFENCE API KEY for Wordfence database updates (free). Set WPSCAN API TOKEN for WPScan database updates (Enterprise plan only). Self-Update How It Works Stealthy mode queries exposed REST API routes ( ?rest route=/ ) and matches discovered endpoin","default_branch":null,"files":null,"tree":[],"storefront":"/r/Chocapikk","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Chocapikk/wpprobe/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}