A program that checks wordpress vulnerabilities using the wordfence API.
.gitignore | ||
check_wp_vuln.sh | ||
docker-compose.yml | ||
Dockerfile | ||
README.md |
docker_wordpress_scanner
This is a docker-compose ecosystem that will install a specific target wordpress version in a webserver and then run wpscan against and output the vulnerabilities. It is meant to be used as a quick way to scan a target wordpress version from its base
Usage:
Create a .env file with the following envar
WPSCANDB_API_TOKEN=
this token is used for wpscan db api calls. To use the container:
# PLUGIN
docker run --env-file .env wp_checker --plugin jetpack
# THEME
docker run --env-file .env wp_checker --theme zerif-lite
# VERSION - Example checks version 4.9.4
docker run --env-file .env wp_checker --all 494