
WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.
Ethical WordPress vulnerability scanner β real-time CVE correlation, OWASP mapping, AI-powered analysis, and consent-based testing.
Quick Start Β Β·Β Documentation Β Β·Β Docker Β Β·Β AI Features Β Β·Β Star on GitHub
Scan overview Β· severity breakdown |
Findings Β· CVE/OWASP badges Β· filter bar |
Argus is a production-ready WordPress security scanner that puts ethics first. Built for penetration testers, security researchers, and WordPress administrators, it combines traditional vulnerability scanning with cutting-edge AI analysis to deliver actionable insights.
--diff last compares scans to track remediation progress| Check Category | Safe Mode | Aggressive | Details |
|---|---|---|---|
| WordPress Detection | β | β | Version fingerprinting via meta tags, readme, RSS, assets |
| Plugins & Themes | 100 plugins | 447 plugins | Version detection (4 methods) + real-time CVE/CVSS correlation |
| Sensitive Files | 74 paths | 437 paths | wp-config backups, .env, SQL dumps, .git, debug logs, PHP tools |
| User Enumeration | 3 methods | 6 methods | Author IDOR, REST API, HTML parsing + oEmbed, login error, XML-RPC |
| Security Headers | β | β | HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy |
| Misconfigurations | β | β | XML-RPC, debug mode, directory listing, file editor |
| Login Security | β | β | 2FA, CAPTCHA, brute-force protection, open registration, password policy |
| Web Crawl | β | β | robots.txt, sitemap.xml, HTML comments, link discovery (depth 1) |
# One command, comprehensive analysis
python -m argus --target https://example.com --html
Track remediation progress between scans:
# Compare this scan against the previous one
python -m argus --target https://example.com --html --diff last
# Or reference a specific scan ID
python -m argus --target https://example.com --html --diff 42
The diff section shows:
Choose your AI provider based on your needs:
| Provider | Best For | Speed | Cost/scan | Privacy |
|---|---|---|---|---|
| OpenAI gpt-4o-mini (default) | Best value | β‘ ~40s | π° ~$0.006 | π Standard |
| OpenAI gpt-4o | Production quality | β‘ ~40s | π° ~$0.05 | π Standard |
| Anthropic claude-3-5-haiku | Privacy-focused | β‘ ~55s | π° ~$0.02 | π Enhanced |
| Ollama (Local) | Complete privacy | π’ ~28min | π° Free | π 100% Offline |
Analysis Modes:
--ai-agent): Enriched with live NVD CVE data and WPVulnerability.net lookups (free APIs)--ai-compare): Side-by-side analysis from multiple providers in parallel--ai-stream): Real-time token output as the AI generates--ai-budget): Cost cap enforcement with configurable abort thresholdJSON Reports (Machine-Readable)