In-House Tools Used

icon picker
WPScan

Description

WPScan is recommended for auditing your WordPress installation security.
By using WPScan you can check if your WordPress setup is vulnerable to certain types of attacks, or if it's exposing too much information in your core, plugin or theme files.

Installation

In macOSX via Homebrew
brew install wpscanteam/tap/wpscan
From RubyGems
On MacOSX, if a Gem::FilePermissionError is raised due to the Apple's System Integrity Protection (SIP), either install RVM and install wpscan again, or run sudo gem install -n /usr/local/bin wpscan

Usage

Enumerating usernames
Enumerating a range of usernames
** replace u1-100 with a range of your choice.
image.png


Want to print your doc?
This is not the way.
Try clicking the ⋯ next to your doc name or using a keyboard shortcut (
CtrlP
) instead.