Membership level: Free member
Enumerate Wordpress Users (wpscan --url https://wordpress.com/ --enumerate u --random-user-agent --force --max-scan-duration 60)
URL: https://wordpress.com/ [192.0.78.9]
Started: Wed Nov 26 20:55:50 2025

Interesting Finding(s):

Headers
 | Interesting Entries:
 |  - Server: nginx
 |  - X-ac: 20.bur _bur BYPASS
 |  - Alt-Svc: h3=":443"; ma=86400
 |  - Server-Timing: a8c-cdn, dc;desc=bur, cache;desc=BYPASS;dur=2.0
 | Found By: Headers (Passive Detection)
 | Confidence: 100%

robots.txt found: https://wordpress.com/robots.txt
 | Interesting Entries:
 |  - /wp-admin/
 |  - /wp-admin/admin-ajax.php
 |  - /typo/?subdomain=
 |  - /read/
 |  - /*/read/
 |  - /forums/topic-tag/reader/
 |  - /*/forums/topic-tag/reader/
 |  - /support/reader/
 |  - /*/support/reader/
 |  - /reader/
 |  - /*/reader/
 |  - /log-in/
 |  - /log-in$
 |  - /log-in?
 |  - /abuse/?*
 |  - /abuse?*
 |  - /plugins/?s=
 |  - /*/plugins/?s=
 |  - /*?aff=
 |  - /*&aff=
 |  - /*?affiliate=
 |  - /*&affiliate=
 |  - /*?cid=
 |  - /*&cid=
 |  - /*?irclickid=
 |  - /*&irclickid=
 |  - /*/?like_comment=
 |  - /*?retry=
 |  - /*?sid=
 |  - /*?action=
 |  - /wp-login.php
 |  - /wp-signup.php
 |  - /press-this.php
 |  - /remote-login.php
 |  - /activate/
 |  - /cgi-bin/
 |  - /mshots/v1/
 |  - /next/
 |  - /public.api/
 | Found By: Robots Txt (Aggressive Detection)
 | Confidence: 100%


Fingerprinting the version -: |================================================|
 The WordPress version could not be detected.

 The main theme could not be detected.

Enumerating Users (via Passive and Aggressive Methods)

 Brute Forcing Author IDs -: |=================================================|

 No Users Found.

 No WPScan API Token given, as a result vulnerability data has not been output.
 You can get a free API token with 25 daily requests by registering at https://wpscan.com/register

Finished: Wed Nov 26 20:56:25 2025
Requests Done: 1308
Cached Requests: 9
Data Sent: 320.188 KB
Data Received: 20.118 MB
Memory used: 141.75 MB
Elapsed time: 00:00:34
Color Scheme
Target
wordpress.com
Scan method
Enumerate Wordpress Users
Run command
wpscan --url https://wordpress.com/ --enumerate u --random-user-agent --force --max-scan-duration 60
Scan time
34s
Quick report
Order full scan ($19/one time)
Scan date
26 Nov 2025 23:56
Copy scan report
Download report
Remove scan result
$
Some firewalls blocks vulnerability scanners. For get true positive results add wpscan.online IP addresses (208.76.253.232-208.76.253.239 or CIDR 208.76.253.232/29 ) to the whitelist
[scan_method]
Visibility:
Scan method:
Max Scan duration: