[WordPress] 外掛分享: Bang Vulnerability Scanner

首頁外掛目錄 › Bang Vulnerability Scanner
WordPress 外掛 Bang Vulnerability Scanner 的封面圖片
20+
安裝啟用
尚無評分
2891 天前
最後更新
問題解決
WordPress 3.0.0+ PHP 5.2+ v1.0 上架:2018-04-17

內容簡介

這款外掛會在「工具」區塊下新增一個管理頁面,報告您的 WordPress 版本和安裝的佈景主題或外掛是否存在已知的漏洞。

這些資訊僅限於管理員(或更確切地說,擁有 manage_options 權限的用戶)可見,訂閱者、作者和編輯無法查看這些資料。

資料來源

這款外掛使用的資料來源為 WPScan 漏洞資料庫:https://wpvulndb.com/。它使用緩存和內部節流,以確保其對 API 的使用量不過度或過度濫用。

備註

使用此外掛無法保證您的網站不具有漏洞。它也不免除您作為網站擁有者以其他方式保障您的網站安全,例如 SSL 或主機安全的責任。這款外掛只是一個工具,您需負責負責任地使用它。

WP-CLI

這款外掛註冊了 WP-CLI 命令,可讓您在命令列中掃描。回應狀態碼與 Nagios 兼容 (1 表示致命錯誤,2 表示警告,3 表示未知)。

wp vuln scan,報告所有已知漏洞。
wp vuln plugins,報告僅在外掛中發現的漏洞。
wp vuln themes,報告僅在佈景主題中發現的漏洞。
wp vuln wp,報告僅在 WordPress 核心中發現的漏洞。
wp vuln details,顯示有關已知漏洞的更詳細輸出。
wp vuln clear,清除漏洞資料的內部快取。這會導致對 API 進行額外的請求,可能沒有必要。

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.0) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Bang Vulnerability Scanner」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

This plugin adds an admin page under the Tools section that reports on any known vulnerabilities in your version of WordPress and any installed themes or plugins.
This information is only visible to administrators (or more precisely, those with the manage_options capability). Subscribers, authors and editors cannot see the data.
Source
The information this plugin uses comes from the WPScan Vulnerability Database: https://wpvulndb.com/. It uses a cache and internal throttling to ensure its use of the API is not excessive or abusive.
Note
Using this plugin does not guarantee that your site has no vulnerabilities. It also does not absolve you from responsibilities as a site owner to secure your site in other ways, such as SSL or host security. This plugin is only a tool; using it responsibly is up to you.
WP-CLI
This plugin registers a WP-CLI command, that allows you to scan from the command line. The response codes are compatible with Nagios (1 for critical error, 2 for warning, 3 for unknown).

wp vuln scan, to report all known vulnerabilities.
wp vuln plugins, to report only vulnerabilities in plugins.
wp vuln themes, to report only vulnerabilities in themes.
wp vuln wp, to report only vulnerabilities in WordPress core.
wp vuln details, to show a more detailed output on known vulnerabilities.
wp vuln clear, to clear the internal cache of vulnerability data. This will result in making extra requests to the API, and is probably not needed.

延伸相關外掛

文章
Filter
Mastodon