Plecost: WordPress Vulnerabilities Finder

There are a huge number of WordPress around the world. Most of them
are exposed to be attacked and be converted into a virus, malware or
illegal porn provider, without the knowledge of the blog owner.

This project try to help sysadmins and blog’s owners to make a bit secure their WordPress.

Plecost is a vulnerability fingerprinting and vulnerability finder for WordPress blog engine. 

What’s new?

This Plecost 3 version, add a lot of new features and fixes, like:

  • Fixed a lot of bugs.
  • New engine: without threads or any dependencies, but run more
    faster. We’ll used python 3 asyncio and non-blocking connections. Also
    consume less memory. Incredible, right? 🙂
  • Changed CVE update system and storage: Now Plecost get
    vulnerabilities directly from NIST and create a local SQLite data base
    with filtered information for WordPress and theirs plugins.
  • WordPress vulnerabilities: Now Plecost also manage WordPress Vulnerabilities (not only for the Plugins).
  • Add local vulnerability database are queryable. You can consult the
    vulnerabilities for a concrete wordpress or plugins without, using the
    local database.

Installation

Install Plecost is so easy:

$ python3 -m pip install plecost

Remember that Plecost3 only runs in Python 3.

Quick start

Scan a web site si so simple:

$ plecost http://SITE.com

A bit complex scan: increasing verbosity exporting results in JSON format and XML:

JSON

$ plecost -v http://SITE.com -o results.json

XML

$ plecost -v http://SITE.com -o results.xml

Example :

 Download and read more at:

Ehacking Staff
With more than 50 global partners, we are proud to count the world’s leading cybersecurity training provider. EH Academy is the brainchild of Ehacking, which has been involved in the field of training since the past Five years and continues to help in creating professional IT experts.

Most Popular

How to Become an Expert in Ethical Hacking

This article is mainly addressing the audience who wants to pursue their career in Cybersecurity as a professional that provides ethical hacking services, whether...

5 Cybersecurity Tips to Keep in Mind When Working From Home

  Due to the ongoing global health crisis, more and more people are being forced to work from their homes. In fact, Forbes estimates that about...

The Complete OSINT Tutorial to Find Personal Information About Anyone

This article mainly focuses on how to discover a person's digital footprint and gather personal data by using open-source intelligence (OSINT). So, in its...

How to find the password of hacked email addresses using OSINT

Open-source intelligence or OSINT is a potent technique, and it can give a lot of valuable information, if implemented correctly with the right strategy...