Filed Under (News, WordPress) by DK on 14 July 2007

Philipp Heinze of the BlogSecurity team, released a simple plugin to activate wp-scanner when testing your blog.

We know its been a pain having to edit your template every time you want to run wp-scanner. The BlogSecurity team have released the wp-scanner plugin to address this challenge.

The installation instructions are as follows:

  • Download the wp-scanner plugin here
  • Unzip the plugin in your wp-content/plugin directory
  • Enable the plugin from your wp-admin plugin menu
  • Launch wp-scanner and run your test
  • When done, please disable the plugin to prevent others scanning your blog.

We hope this makes the process a little simpler.

If the you are unable to get the scan working, please manually add the <– wp-scanner –> html comment into your theme’s index.php file.

Read and Contribute to BlogSec News!

Comments

BlogSecurity » WordPress Scanner on 14 July, 2007 at 2:37 pm #

[…] To run wp-scanner, please download the wp-scanner activator plugin. Once downloaded, simply activate it launch the wp-scanner and then de-activate it once your done. More detailed installation instructions are available here. […]


wp-scanner Plugin | funnydingo.de on 14 July, 2007 at 5:15 pm #

[…] hat BlogSecurity ein WordPress Plugin für den wp-scanner veröffentlicht. Seit einiger Zeit prüft der wp-scanner, ob sich im Quelltext […]


Geof F. Morris on 14 July, 2007 at 7:12 pm #

Glad y’all got this put together. Sorry that I didn’t get around to doing it myself. :)


David Kierznowski on 15 July, 2007 at 1:01 am #

Geof, no problems :)


[…] neues Plugin von Philipp Heinze sorgt für diesen HTML-Kommentar, so dass man nicht mehr von Hand die […]


Michael on 9 August, 2007 at 6:29 pm #

Your instructions list above says “Launch wp-scanner and run your test” Those words are linked to a 404 and so I have no clue as to how I “launch” wp-scanner.
I have examined every possible part of the dashboard, and there is no mention of wp-scanner, except in the list of Plugins, naturally. And yes, I have activated it :)

Any ideas, suggestions, etc., most welcome….
I’m using WordPress 2.2.1


David Kierznowski on 9 August, 2007 at 10:27 pm #

Michael, launch link has been fixed. If you have enabled the plugin, then try launch the scanner again. Thanks for pointing this out.


[…] Gleich testen mit dem WordPress-Sicherheitscheck. […]


The Doctor What on 12 August, 2007 at 4:32 am #

How about adding a link to the wp-scanner tool in the plugin description?

http://blogsecurity.net/wordpress/tools/wp-scanner/

Ciao!


dk on 15 August, 2007 at 6:28 pm #

Doctor, that is a great idea, we will look at this for the next release.


Dodgypress on 28 August, 2007 at 9:50 am #

Am really glad that, there is now a focus on Security. To an outsider, and a very new user of the WP Platform, its an Excellent sign of Maturity.

Keep Up the Great Work!!!

I would be more then willing to donate some dollars every now and then to help with the update/further development of such a product.

Don


not working on 7 September, 2007 at 8:17 am #

Hi,

wp-scanner is not able to pull the complete list of plugins out from my wordpress.

My website was hacked and I am almost sure it was because of a bad plugin.

Could you help? I didnt want to provide my website here … for obvious reasons.


David Kierznowski on 7 September, 2007 at 11:41 am #

@not working: if you contact us via the contact form we may be able to help you identify the hole.


Ken on 17 September, 2007 at 5:42 am #

Is the scan supposed to list all the plugins that are active? Because it only lists a few of my plugins.


Cobolian » Sécurité WordPress on 31 October, 2007 at 10:41 am #

[…] plug des plus intéressant : wp-scanner plugin permet de vérifier la sécurité de son install […]


Jonathan Dingman on 4 November, 2007 at 5:17 am #

Wow, you guys have done a killer job with this. This is exactly something I have been looking for lately.

Great work!


Tyger on 7 November, 2007 at 6:31 am #

I don’t know if I’m retarded or what. Plugin is installed and activated. No go. So I manually edited my themes index.php file trying each of the variations I found here , and . Mostly it just says blog not authorized, but I did get a couple server timeouts. Any ideas?


PIF on 23 November, 2007 at 1:36 am #

Same as Tyger mostly. Except nothing happens. Unless you count the code showing as is in the body of the page. Using WP 231.


PIF on 23 November, 2007 at 1:39 am #

I might add that the WP Upgrade Preflight Check plugin shows wp_scanner to have no problems.

It would be nice if wp_scanner would show up in the menu bar under options or something…


DK on 23 November, 2007 at 4:14 am #

All the plugin does is add the into the index page. wp-scanner will check the index page for this comment.

We have had some cases where the plugin only adds the html comment into single posts. Hopefully, giving you insight into how it works will help you get on the right foot.


Guro on 11 February, 2008 at 5:44 pm #

Hi guys. I have experienced the same problem as Tyger and Pif. After I have deleted the cached pages from wp-cache everything was fine with me.


[…] knowing the vulnerabilities on your own wordpress blog . I’ve found something interesting here , called wp-scanner . It works this simple […]


[…] the wp-scanner activator plugin. برای اطلاعات بیشتر در مورد نصب نیز اینجا کلیک کنید اینجام می تونید این برنامه رو اجرا کنید. از […]


lubos on 6 May, 2008 at 2:26 pm #

I confirm Tyger/Pif/Guro’s problems. Deleting the cache helped. This occured _only_ after upgrade to 2.5.1… now it works…


Daniel on 13 May, 2008 at 2:29 pm #

I don’t have this plugin and I get the same yger/Pif/Guro’s problem. Also using 2.5.1


Daniel on 13 May, 2008 at 2:36 pm #

Nevermind, I’m blocking by ip address, forgot about that :-)


Comment
Name:
Email:
Website:
Message: