Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
argus-wp-watcher β€” WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting. | Kitploit
Tools/GitHubGitHub/rodhnin/argus-wp-watcher
Vulnerability ScannersInformation GatheringWeb SecurityPenetration TestingMisconfigurationLearning & EducationCrawlerAI Security
GitHubrodhnin/argus-wp-watcher

argus-wp-watcher

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

View Repository
181155 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share
Argus β€” WordPress Security Scanner

Version Python License Docker LangChain Ethical


Ethical WordPress vulnerability scanner β€” real-time CVE correlation, OWASP mapping, AI-powered analysis, and consent-based testing.


Quick Start Β Β·Β  Documentation Β Β·Β  Docker Β Β·Β  AI Features Β Β·Β  Star on GitHub


Argus β€” Eyes on the site. Proof in the log.

In Action

Argus scan β€” real output against WordPress 6.0.3
Live scan Β· WordPress 6.0.3 Β· 49 CVEs detected Β· 18 findings Β· 47s

Argus HTML report β€” scan overview
Scan overview Β· severity breakdown
Argus HTML report β€” security findings
Findings Β· CVE/OWASP badges Β· filter bar

🎯 What is Argus?

Argus is a production-ready WordPress security scanner that puts ethics first. Built for penetration testers, security researchers, and WordPress administrators, it combines traditional vulnerability scanning with cutting-edge AI analysis to deliver actionable insights.

Why Argus?

  • πŸ”’ Ethical by Design: Consent token system prevents unauthorized scanning
  • πŸ” Real CVE Data: Live correlation with WPVulnerability.net + CVSS scores from NVD (both free, no key)
  • πŸ—‚οΈ OWASP Mapping: Every finding mapped to OWASP Top 10 2021
  • πŸ“ˆ Scan Diffing: --diff last compares scans to track remediation progress
  • πŸ€– AI-Powered: GPT-4, Claude, or local Ollama β€” with streaming, agent mode, and multi-LLM compare
  • πŸ“Š Professional Reports: Rich HTML with CVE/CWE/OWASP/CVSS badges + machine-readable JSON
  • πŸš€ Fast & Efficient: Concurrent scanning with intelligent rate limiting
  • πŸ’Ύ Persistent Tracking: SQLite database for scan history
  • 🐳 Docker Ready: Containerized scanning + vulnerable test lab included

What It Scans

Check CategorySafe ModeAggressiveDetails
WordPress Detectionβœ…βœ…Version fingerprinting via meta tags, readme, RSS, assets
Plugins & Themes100 plugins447 pluginsVersion detection (4 methods) + real-time CVE/CVSS correlation
Sensitive Files74 paths437 pathswp-config backups, .env, SQL dumps, .git, debug logs, PHP tools
User Enumeration3 methods6 methodsAuthor IDOR, REST API, HTML parsing + oEmbed, login error, XML-RPC
Security Headersβœ…βœ…HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy
Misconfigurationsβœ…βœ…XML-RPC, debug mode, directory listing, file editor
Login SecurityβŒβœ…2FA, CAPTCHA, brute-force protection, open registration, password policy
Web CrawlβŒβœ…robots.txt, sitemap.xml, HTML comments, link discovery (depth 1)

✨ Features

πŸ›‘οΈ Core Security Scanning

# One command, comprehensive analysis
python -m argus --target https://example.com --html
  • Multi-Method Fingerprinting: Detects WordPress 4.x-6.x with zero false positives
  • Real-Time CVE Correlation: Checks every detected plugin, theme, and core version against WPVulnerability.net (free, no API key)
  • CVSS Scoring: Fetches scores from NVD for each CVE (critical β‰₯9.0, high β‰₯7.0, medium β‰₯4.0)
  • Latest Version Detection: WordPress.org API shows the current stable version alongside detected version
  • OWASP Top 10 2021: Every finding mapped to its OWASP category (A01–A10)
  • Concurrent Scanning: Thread pool + rate limiting for fast, respectful scans
  • Smart Detection: Early abort for non-WordPress sites (99% faster rejection)
  • Evidence Collection: HTTP responses, headers, and file contents preserved

πŸ“ˆ Scan Diff Reports (v0.2.0)

Track remediation progress between scans:

# Compare this scan against the previous one
python -m argus --target https://example.com --html --diff last

# Or reference a specific scan ID
python -m argus --target https://example.com --html --diff 42

The diff section shows:

  • New findings (appeared since last scan) β€” in red
  • Fixed findings (remediated since last scan) β€” in green with strikethrough
  • Persisting findings (present in both scans) β€” collapsed by default
  • Mode mismatch warning when comparing safe vs aggressive scans

πŸ€– AI-Powered Analysis

Choose your AI provider based on your needs:

ProviderBest ForSpeedCost/scanPrivacy
OpenAI gpt-4o-mini (default)Best value⚑ ~40sπŸ’° ~$0.006πŸ”’ Standard
OpenAI gpt-4oProduction quality⚑ ~40sπŸ’° ~$0.05πŸ”’ Standard
Anthropic claude-3-5-haikuPrivacy-focused⚑ ~55sπŸ’° ~$0.02πŸ”’ Enhanced
Ollama (Local)Complete privacy🐒 ~28minπŸ’° FreeπŸ” 100% Offline

Analysis Modes:

  • Technical: Step-by-step remediation with WP-CLI commands and configuration snippets
  • Executive: Plain-language summaries for stakeholders and management
  • Agent (--ai-agent): Enriched with live NVD CVE data and WPVulnerability.net lookups (free APIs)
  • Compare (--ai-compare): Side-by-side analysis from multiple providers in parallel
  • Stream (--ai-stream): Real-time token output as the AI generates
  • Budget (--ai-budget): Cost cap enforcement with configurable abort threshold

πŸ“Š Professional Reporting

JSON Reports (Machine-Readable)

Download Tool