العودة إلى المشاريع
Security Tool Security Scanning Tool

Ultimate WP Security Scanner

Free, open-source desktop scanner that automates WordPress security assessments - plugin/theme fingerprinting, vulnerability findings, and WAF/origin detection in one dashboard.

Ultimate WP Security Scanner

نظرة عامة

Ultimate WP Security Scanner is a desktop application built to speed up authorized WordPress security testing. Instead of running multiple separate tools, a tester enters a target and the scanner runs a full assessment in the background - fingerprinting installed plugins and themes with version detection, surfacing findings by severity (Critical, High, Medium, Low, Info), attempting WAF evasion and real-origin IP discovery, and mapping WordPress core version, users, and themes. Findings are organized into a live dashboard, a detailed findings table with CWE references and remediation notes, an event log, and exportable reports - all running multi-threaded for speed. Released free and open-source so other researchers testing their own sites don't have to piece together several tools by hand.

أبرز المميزات

Multi-threaded scanning engine (configurable thread count)
Live dashboard with severity breakdown (Critical/High/Medium/Low/Info)
Findings table with module, confidence level, and CWE classification
Plugin and theme fingerprinting with version detection
WordPress core version and user enumeration
WAF evasion and real origin-IP discovery modes
Stealth and aggressive scanning modes
Event log for full scan traceability
Exportable scan reports
Free and open-source

الأثر

Cut down the time it takes to run a full WordPress security assessment by consolidating plugin/theme fingerprinting, vulnerability findings, and origin/WAF detection into one tool — instead of manually running several separate scanners in sequence. Released free and open-source so other researchers testing their own sites can run a full assessment without extra cost or tooling overhead.

التحديات

Building a scanner fast enough for real engagements meant getting multi-threading right without overwhelming the target or triggering false positives, correctly fingerprinting dozens of plugins/themes purely from passive signals, and reliably unmasking the real origin IP behind a WAF without crossing into unauthorized/aggressive techniques by default.

الحل

Built a desktop scanning tool with a configurable multi-threaded engine, modular scan modes (Aggressive, Evade WAF, Stealth, Find Origin), and a live-updating dashboard. Findings are automatically classified by severity and mapped to CWE identifiers, with remediation guidance generated per finding, and everything is logged for auditability.

النتائج

A working, free and open-source scanner used by other developers to test their own WordPress sites - detecting installed plugins/themes with versions, WordPress core version, findings across all severity levels, and origin IPs behind WAFs, all from a single responsive interface.

المعرض

التفاصيل

المدة
3 months
الجدول الزمني
Jun 2026 – Aug 2026
الفئة
Security Tool

التقنيات

PythonPyQtMulti-threadingREST API

الوسوم

#security#wordpress#scanner#pentesting#open-source#cli-tool