Developer releases open-source WordPress scanner covering 109 security checks in 60 seconds
A developer named Damian Hunziker has released wpsec109, a free open-source Python-based tool that audits WordPress sites across 109 security hardening points in approximately 60 seconds. The scanner covers 22 categories including directory listing exposure, PHP execution in upload folders, sensitive file leaks, security headers, and user enumeration vulnerabilities. It runs locally without sending data to third-party servers and does not require API keys for basic scans, though optional WPScan API integration enables CVE cross-referencing for plugins and themes. Each flagged issue comes with an actionable remediation suggestion, such as specific .htaccess rules or file permission changes. The tool is publicly available on GitHub and was built to fill a gap in client-side auditing tools that are both privacy-respecting and provide practical fix guidance.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in