WordPress Security Scan: WPScan

Posted:

[ Categories: ]

#!/bin/bash

# To update database to the lastest version, run
#
# wpscan --update
#
# Scan installed plugins
#
# wpscan --url http(s)://your-domain.com --enumerate p
#
# Scan vulnerable plugins
# 
# wpscan --url http(s)://your-domain.com --enumerate vp
# 
# Scan installed themes
# 
# wpscan --url http(s)://your-domain.com --enumerate t
# 
# Scan vulnerable themes
# 
# wpscan --url http(s)://your-domain.com --enumerate vt
# 
# Scan user accounts:
# 
# wpscan --url http(s)://your-domain.com --enumerate u
# 
# Scan vulnerable timthumb files:
# 
# wpscan --url http(s)://your-domain.com --enumerate tt

OUTPUT_FILE="/mnt/storage-vol1-1/reports/wpscan-$(date '+%Y.%m.%d').txt"

wpscan --url https://keystreams.io -o "${OUTPUT_FILE}" --enumerate p --enumerate vp --enumerate t --enumerate vt --enumerate u --enumerate tt