Plugin / Bang Vulnerability Scanner

Bang Communications

Description

Description

This plugin adds an admin page under the Tools section that reports on any known vulnerabilities in your version of WordPress and any installed themes or plugins.

This information is only visible to administrators (or more precisely, those with the manage_options capability). Subscribers, authors and editors cannot see the data.

Source

The information this plugin uses comes from the WPScan Vulnerability Database: https://wpvulndb.com/. It uses a cache and internal throttling to ensure its use of the API is not excessive or abusive.

Note

Using this plugin does not guarantee that your site has no vulnerabilities. It also does not absolve you from responsibilities as a site owner to secure your site in other ways, such as SSL or host security. This plugin is only a tool; using it responsibly is up to you.

WP-CLI

This plugin registers a WP-CLI command, that allows you to scan from the command line. The response codes are compatible with Nagios (1 for critical error, 2 for warning, 3 for unknown).

  • wp vuln scan, to report all known vulnerabilities.
  • wp vuln plugins, to report only vulnerabilities in plugins.
  • wp vuln themes, to report only vulnerabilities in themes.
  • wp vuln wp, to report only vulnerabilities in WordPress core.
  • wp vuln details, to show a more detailed output on known vulnerabilities.
  • wp vuln clear, to clear the internal cache of vulnerability data. This will result in making extra requests to the API, and is probably not needed.

Ratings

0
0 reviews

Rating breakdown

Details Information

Version

1.0

First Released

17 Apr, 2018

Total Downloads

340

Wordpress Version

3.0.0 or higher

Tested up to:

4.9.12

Require PHP Version:

5.2 or higher

Tags

Contributors

Languages

The plugin hasn't been transalated in any language other than English.

DIRECTORY DISCLAIMER

The information provided in this THEME/PLUGIN DIRECTORY is made available for information purposes only, and intended to serve as a resource to enable visitors to select a relevant theme or plugin. wpSocket gives no warranty of any kind, express or implied with regard to the information, including without limitation any warranty that the particular theme or plugin that you select is qualified on your situation.

The information in the individual theme or plugin displayed in the Directory is provided by the owners and contributors themselves. wpSocket gives no warranty as to the accuracy of the information and will not be liable to you for any loss or damage suffered by you as a consequence of your reliance on the information.

Links to respective sites are offered to assist in accessing additional information. The links may be outdated or broken. Connect to outside sites at your own risk. The Theme/Plugin Directory does not endorse the content or accuracy of any listing or external website.

While information is made available, no guarantee is given that the details provided are correct, complete or up-to-date.

wpSocket is not related to the theme or plugin, and also not responsible and expressly disclaims all liability for, damages of any kind, arising out of the use, reference to, or reliance on, any information or business listed throughout our site.

Keep Leading Your Followers!
Share it for them.