An open source web server and web application scanner that tests for misconfigurations, bugs, and missing patches. Not designed to be subtle, it's a pen tester's auditing tool through and through.
An excellent blog post on how Wordpress backdoors work, how they're hidden, and how they're used.