80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒
-
Updated
Aug 30, 2026 - Python
80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒
A fast WordPress plugin enumeration tool
The useful exploit finder
EngineScript is a super fast WordPress server built on Ubuntu and optimized for Cloudflare and Digital Ocean
Extension for MainWP Dashboard. Checks the child websites plugins for vulnerability using the WordFence intelligence api.
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.
Useful plugins for Wordpress
WP-CLI commands and WordPress Abilities API integration for Wordfence Security - manage scans, issues, firewall, and license from CLI and REST API
Checks active plugins against Wordfence Intelligence V3 vulnerability feed
Fetch WordPress vulnerability information from Wordfence vulnerability data feed.
List of the URLs to block on standard WordPress installation to immediately block attack attempts
This WordPress plugin customizes Wordfence CAPTCHA validation for custom login & registration pages to reduce spam registrations and fix the "Registration Attempt Blocked" issue on custom pages.
This powerful plugin offers advanced security features including automatic IP blocking, an advanced rule builder, traffic analysis, and seamless integration with services like Cloudflare, AbuseIPDB, Whatismybrowser.com, and now IPData.
Download the WordFence license activator for free to unlock premium features. It has been scanned by VirusTotal which ensures that you are downloading only clean, safe and trusted files.
Find the WordPress plugin code an attacker can reach, and check whether anything is guarding it
Ensure required WordfFence files exist in shared directory
Email 2FA for WordPress login - a 6-digit one-time code by email, no app or SMS. Works with Wordfence, custom login pages, and multisite.
Developer reference: how major WordPress 2FA plugins store secrets, detect users, and validate codes. Includes Sudo bridge examples for WP 2FA, Wordfence, and AIOS.
Add a description, image, and links to the wordfence topic page so that developers can more easily learn about it.
To associate your repository with the wordfence topic, visit your repo's landing page and select "manage topics."