WPScan is recommended for auditing your WordPress installation security.
By using WPScan you can check if your WordPress setup is vulnerable to certain types of attacks, or if it's exposing too much information in your core, plugin or theme files.
Installation
In macOSX via Homebrew
brew install wpscanteam/tap/wpscan
From RubyGems
On MacOSX, if a Gem::FilePermissionError is raised due to the Apple's System Integrity Protection (SIP), either install RVM and install wpscan again, or run sudo gem install -n /usr/local/bin wpscan
Usage
Enumerating usernames
Enumerating a range of usernames
** replace u1-100 with a range of your choice.
Want to print your doc? This is not the way.
Try clicking the ⋯ next to your doc name or using a keyboard shortcut (