A fast, concurrent scanner to detect potential dependency confusion vulnerabilities in WordPress websites by identifying unclaimed plugin slugs in the official WordPress.org repository.
This tool is intended for security researchers, bug bounty hunters, and WordPress administrators for ethical and authorized security assessments only.
When a WordPress site uses a custom or premium plugin that is not listed in the official WordPress.org plugin repository, a vulnerability can arise. If the plugin's unique name (its "slug") is available, an attacker could register a plugin with the same slug on WordPress.org.
Depending on the site's configuration and update mechanisms, it might automatically "update" to the attacker's malicious version from the official repository, leading to a full site compromise. This tool helps identify such unclaimed plugin slugs.
- Concurrent Scanning: Uses multithreading to scan multiple sites and check plugins quickly.
- Efficient Logic: Gathers all unique plugins first, then checks each plugin's status only once, even if found on multiple sites.
- Multiple Target Inputs: Scan single URLs, multiple URLs, or provide a list of targets from a file.
- Flexible Output: Clear, color-coded console output and the option to save results to a structured JSON file.
- Verbose Mode: Option to view all discovered plugins and their claim status (claimed, unclaimed, or error).
- Robust Scraping: Uses both Regex and BeautifulSoup for better plugin detection from HTML source.
-
Clone the repository:
git clone https://github.com/your-username/wp-unclaimed-plugin-scanner.git cd wp-unclaimed-plugin-scanner -
Install dependencies: It's recommended to use a virtual environment.
python3 -m venv venv source venv/bin/activate pip install -r requirements.txt
python3 scanner.py [targets...] [options]1. Scan a single target:
python3 scanner.py https://example.com2. Scan multiple targets from the command line:
python3 scanner.py https://site1.com https://site2.blog3. Scan targets from a file:
Create a file targets.txt with one URL per line:
https://wordpress-site.org
https://another-blog.com
https://test-site.net
Then run the scanner:
python3 scanner.py -f targets.txt4. Increase concurrency and save vulnerable findings to a JSON file:
python3 scanner.py -f targets.txt -t 20 -o vulnerable.json5. Run in verbose mode to see all discovered plugins:
python3 scanner.py https://example.com -v| Flag | Description |
|---|---|
targets (positional) |
One or more target URLs to scan. |
-f, --file |
Path to a file containing a list of URLs, one per line. |
-t, --threads |
Number of concurrent threads to use. (Default: 10) |
-o, --output |
File to save vulnerable results in JSON format. |
-v, --verbose |
Show all plugins found and their status (claimed/unclaimed). |
[!!!] VULNERABILITIES FOUND [!!!]
--------------------------------------------------
Vulnerable Site: https://example.com/
-> Unclaimed Plugin: my-custom-plugin
Claim URL: https://wordpress.org/plugins/my-custom-plugin/
--------------------------------------------------
[
{
"site": "https://example.com/",
"unclaimed_plugins": [
"my-custom-plugin"
]
}
]