Recent

WPScan 1.1 released

I am pleased to announce, after 5 months of work, that WPScan version 1.1 has been released!

With 780 more lines of code the most notable changes are:

Detection for 750 more plugins.
Detection for 107 new plugin vulnerabilities.
Detection for 447 possible timthumb file locations.
Advanced version fingerprinting implemented.
Full Path Disclosure (FPD) checks.
Auto updates.
Progress indicators.
Improved custom 404 checking.
Improved plugin detection.
Improved error_log checking.
Lots of bugs fixed.
Lots of small tweaks.

A full list of changes can be found here:
http://code.google.com/p/wpscan/source/browse/trunk/CHANGELOG

We have done away with file downloads and instead we’re using Subversion (SVN) for distributing WPScan, you can checkout WPScan 1.1 by issuing the following command:

svn checkout http://wpscan.googlecode.com/svn/trunk/ ./wpscan-1.1

WPScan can also be found pre-installed in Backtrack5 R1 in the ‘/pentest/web/wpscan’ directory and will soon be available in SamuraiWTF.

Thanks to everyone who reported bugs or requested features. A special thanks to Alip, @gbrindisi and michee08.

If you find any pesky bugs or want to request a feature in version 1.1, please do so here:
http://code.google.com/p/wpscan/

Posted on 25 November, 2011 by ethicalhack3r

7 Responses to “WPScan 1.1 released”


  1. michee08


    Congratz and Your welcome!:)


    Comment posted on November 25, 2011 at 12:36:35 GMT

  2. WordPress Security Scanner/WPScan 1.1 released « Security List Network™


    [...] MORE IN here WPScan – WordPress Security Scanner Copyright (C) 2011 Ryan Dewhurst AKA ethicalhack3r. Code [...]


    Comment posted on November 25, 2011 at 13:12:01 GMT

  3. Fabrizio


    Nice product :)


    Comment posted on November 25, 2011 at 18:29:22 GMT

  4. Miguel Lopes


    [...] http://www.ethicalhack3r.co.uk [...]


    Comment posted on November 26, 2011 at 15:15:38 GMT

  5. Web Hacking 2011 (Blog Attacks) | Villacorp


    [...] http://www.h-online.com/security/news/item/New-project-scans-for-WordPress-holes-1261912.html http://www.ethicalhack3r.co.uk/security/wpscan-1-1-released/ Nueva y poderosa herramienta para identificar vulnerabilidades en forma remota. Útil para [...]


    Comment posted on December 16, 2011 at 07:38:02 GMT

  6. NNick


    Nice Tool and Great site…


    Comment posted on January 14, 2012 at 15:30:50 GMT

  7. Ashish


    Information about security tools and hacking tools http://www.securitytube-tools.net :D


    Comment posted on February 10, 2012 at 13:26:36 GMT

Leave a Reply