WPScan
Vulnerability scanner Directory evidence: Unverified

WPScan

WPScan is a security scanner used for security scanning, malware checks, vulnerability assessment, certificate review; it appears in server logs as `WPScan`.

WPScan
Operator WPScan
Risk Caution

Overview

WPScan is a security scanner used for security scanning, malware checks, vulnerability assessment, certificate review, and site-safety analysis.

Its primary user-agent pattern is WPScan.

WPScan is Unverified at the identity-evidence level. The listed identity remains useful for detection, but this record does not currently contain authoritative evidence sufficient to authenticate the identity claim.

Robots.txt behavior is not currently confirmed.

WPScan should be monitored first, then rate-limited or blocked if the crawl rate, paths, or behavior are unwanted.

Identity

User-Agent Pattern
WPScan
HTTP Agent Examples
WPScan
Robots Token
WPScan
Identity Type
Observed
Evidence Method
Treat `WPScan` as an identity signal only. Confirm it with current operator documentation, cryptographic verification, forward-confirmed reverse DNS, source-network ownership, or other authoritative evidence before trusting the claimed identity.

Classification

Type
Vulnerability scanner
Kind
Vulnerability scanner
Family
WPScan
Purpose
Vulnerability scanning

Behavior and handling

Common Use
WPScan is used for security scanning, malware checks, vulnerability assessment, certificate review, and site-safety analysis.
Detection Notes
WPScan traffic is primarily detected by the `WPScan` user-agent pattern. Compare source IPs, reverse DNS, request paths, and crawl cadence before trusting the traffic.
Respects robots.txt
Unknown
Spoofing Risk
WPScan has medium spoofing risk because user-agent strings can be copied; pair the match with DNS, IP, behavior, or operator evidence.
Risk
Caution
Recommended Handling
Monitor

Rules and controls

Robots.txt Snippet
# robots.txt behavior is unconfirmed. Do not rely on this rule without verification.

Relationships

Operator
WPScan Checked 2026-08-07

Relationships without an Evidence link are normalized from the canonical directory record. They should not be interpreted as independent proof of physical presence or request origin.

Similar Bots

Vulnerability scanner Unverified

OpenVAS

Greenbone / OpenVAS

OpenVAS
Vulnerability scanner Unverified

Nuclei

ProjectDiscovery

Nuclei
Vulnerability scanner Unverified

Nessus

Tenable

Nessus
Vulnerability scanner Unverified

Acunetix

Acunetix

Acunetix
Ecommerce Verified

ZipchatBot

Zipchat Inc

ZipchatBot