{"repo":"Plecost/plecost","free":true,"listed":false,"github":"https://github.com/Plecost/plecost","clone":"git clone https://github.com/Plecost/plecost.git","description":"Plecost - Professional WordPress Security Scanner","language":"Python","stars":381,"topics":["security","security-tools","vulnerability","wordpress"],"license":null,"category":"security-tools","readme_excerpt":"Plecost Professional WordPress Security Scanner Async-first, library-friendly, no external API required. --- Table of Contents - What is Plecost? - Plecost vs WPScan - Quick Start - Installation - CVE Database - CVE Detection Engine - Scanning - Detection Modules - WooCommerce Security - WP eCommerce Security - Output Formats - Library Usage - Environment Variables - Architecture - Troubleshooting - Local Test Environment - Who's Using Plecost in Production - License --- What is Plecost? Plecost detects vulnerabilities in WordPress installations — core, plugins, and themes — and correlates findings against a daily-updated local CVE database. It runs as a CLI tool, a Python library, or inside task queues like Celery, with a consistent and automation-friendly output format. No Ruby. No API key. No subscription. No data sent to third parties on every scan. Used in production by Astrópalo — see who's using Plecost. Plecost vs WPScan Plecost was built from scratch to fix the limitations teams hit in production when using WPScan: API rate caps, external data dependencies, no library API, no async architecture, and a narrow detection surface. At a Glance Capability Plecost v4 WPScan --- :---: :---: Language / runtime Python 3.11+ Ruby Async concurrent scanning ✅ httpx + asyncio ❌ Python library API ✅ from plecost import Scanner ❌ API key required ❌ never ⚠️ required for CVE data CVE data — free tier limit ✅ unlimited (local DB) ❌ 25 API tokens/day Offline scanning (CVEs included) ✅ ","default_branch":null,"files":null,"tree":[],"storefront":"/r/Plecost","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Plecost/plecost/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}