Wpscan
WPScan is a black-box WordPress security scanner used to identify vulnerabilities, security weaknesses, and misconfigurations in WordPress core installations, plugins, and themes by leveraging its continuously updated vulnerability database. The tool performs remote enumeration and security assessments to detect outdated components, exposed sensitive files, weak passwords, and other security issues that could be exploited by attackers.