Geof from gfmorris.wordpress.com gave wp-scanner such an awesome review that I just had to mention it, because he sheds light on exactly what wp-scanner is all about; I promise we didn’t pay him.
These are his words:
I’ve found BlogSecurity’s WordPress Scanner to be invaluable for me; I’ve recently brought a bunch of installs up to current, but I hadn’t considered the vulnerabilities in XSS attacks on templates. But now that I know that those have holes, too, I can patch them up.
Thanks Geof, we glad we could help!
Happy to help highlight what y’all are up to here. I really would love to see a post-upgrade theme check be done by WordPress, building on the checks that y’all are doing here.
Thanks for building the service *and* for requiring the HTML comment to keep black hats from doing your tests. [Not that it’ll stop anyone who’s seriously looking into screwing around with WP users, but it will stop script kiddies. Maybe.]
Geof, no problems champ; thanks for y’all feedback :)
happy to hear that too :)