About
MCP Server for the WPScan (wpscan.com) API
README
An MCP server (TypeScript) that exposes a few tools for the WPScan (wpscan.com) API v3.
Requirements
- Node.js >= 18
- A WPScan API token
Setup
Node.js
npm install
Set your token:
export WPSCAN_API_TOKEN="..."
Build & run:
npm run build
node dist/index.js
Bun
Install dependencies and compile:
bun install
bun run compile
Set your token:
export WPSCAN_API_TOKEN="..."
Run:
./wpscan-mcp
If, for some reason, compilation does not work:
bun install
bun run build
export WPSCAN_API_TOKEN="..."
bun run dist/index.js
Type generation (optional)
This project can generate TypeScript types directly from the WPScan OpenAPI spec:
# Node.js:
npm run generate-types
# Bun:
bun run generate-types
Notes:
- The OpenAPI spec is fetched from
https://wpscan.com/docs/api/v3/v3.yml/.
MCP tools
wpscan_plugin_lookup- Args:
{ slug: string, version?: string }
- Args:
wpscan_theme_lookup- Args:
{ slug: string, version?: string }
- Args:
wpscan_core_lookup- Args:
{ version: number } - Note: WPScan expects the WordPress version with dots removed (e.g.
6.4.2→642).
- Args:
wpscan_lookup_vuln- Args:
{ wpvdbId: string }(e.g.WPVDB-ID-12345)
- Args:
Usage with an MCP client
This server uses stdio transport.
Example: Claude Desktop config
Add a server entry to your Claude Desktop MCP config (path varies by OS). Example:
{
"mcpServers": {
"wpscan": {
"command": "node",
"args": ["/path/to/wpscan-mcp/dist/index.js"],
"env": {
"WPSCAN_API_TOKEN": "YOUR_TOKEN_HERE"
}
}
}
}
Then restart the client so it picks up the new MCP server.
Example: VSCode
Bun
Create .vscode/mcp.json:
{
"servers": {
"wpscan": {
"type": "stdio",
"command": "${workspaceFolder}/wpscan-mcp",
"args": [],
"env": {
"WPSCAN_API_TOKEN": "YOUR_TOKEN_HERE"
}
}
}
}
Node.js
{
"servers": {
"wpscan": {
"type": "stdio",
"command": "node",
"args": ["${workspaceFolder}/dist/index.js"],
"env": {
"WPSCAN_API_TOKEN": "YOUR_TOKEN_HERE"
}
}
}
}
Tool call examples
- Plugin lookup:
{ "slug": "woocommerce" }
- Theme lookup (specific version):
{ "slug": "astra", "version": "4.6.3" }
- Core lookup (WordPress 6.4.2 → 642):
{ "version": 642 }
- Vulnerability lookup:
{ "wpvdbId": "WPVDB-ID-12345" }
Installing Wpscan
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/sjinks/wpscan-mcp-serverFAQ
Is Wpscan MCP free?
Yes, Wpscan MCP is free — one-click install via Unyly at no cost.
Does Wpscan need an API key?
No, Wpscan runs without API keys or environment variables.
Is Wpscan hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Wpscan in Claude Desktop, Claude Code or Cursor?
Open Wpscan on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
GitHub
PRs, issues, code search, CI status
by GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
by mcpdotdirectAmap Maps Mcp Server
MCP server for using the AMap Maps API
by duxiaohuiSupabase
Database, auth and storage
by SupabaseEverything
Reference / test server with prompts, resources, and tools.
Git
Tools to read, search, and manipulate Git repositories.
Sequential Thinking
Dynamic and reflective problem-solving through thought sequences.
Time
Time and timezone conversion capabilities.
Compare Wpscan with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All development MCPs
