discovered 03 Aug 2026
wphunter
→ View on GitHubwphunter is a Python CLI tool designed for scanning WordPress plugins, themes, and core files for known CVE vulnerabilities, as well as detecting gambling spam injections (judol) and looking up public exploits. It operates both offline, using exported lists, and remotely via a URL, providing AI-powered analysis through Claude, including intelligent threat assessments and actionable remediation steps. Notable features include support for multiple vulnerability sources, comprehensive judol detection mechanisms, and version-aware matching to report relevant vulnerabilities based on the installed versions.