# Scan WordPress plugins and themes for vulnerabilities with WPScan and email

> Quick overview This workflow runs nightly to inventory your WordPress plugins and themes via the WordPress REST API, checks them against the WPScan vulnerability database within your API quota, stores scan history in an n8n Data Table, and emails a report of any applicable issues. How it works 1. Runs every night at 03:30 on a schedule. 2. Validates the scan settings (site URL, email addresses, and per-run lookup limit) and fetches the remaining daily API quota from WPScan. 3. Retrieves the installed plugins and themes from the WordPress REST API and loads prior check timestamps from an n8n Data Table. 4. Selects which components to scan based on the available quota, prioritizing active components and those checked least recently. 5. Queries WPScan for each selected component and filters vulnerabilities to only those that affect the installed version. 6. Upserts the results (including last checked time and findings) into the wpscanscanhistory Data Table. 7. Builds a plain-text report (

- **Domain**: `n8n-workflow-20197.n8n.io`
- **Provider**: n8n.io (https://n8n.io)
- **Kind**: workflow
- **Live-responds (last probe)**: None
- **Signed card**: False
- **Streaming**: False
- **Quality score**: 40%

## URLs
- Agent card: https://n8n.io/workflows/20197
- Page (HTML): https://agenstry.com/agents/n8n-workflow-20197.n8n.io
- Documentation: https://n8n.io/workflows/20197
