-
Writing Good Submissions
We receive a non‑negligible amount of submissions every day. We model the risk they represent for site owners, figure out what kind of privilege is required to successfully exploit the issue, and forward the information to plugin and theme authors to get it fixed. This is can get pretty time-consuming, especially when we need to scavenge…
-
WPScan Acquired by Automattic
We are very excited to let you know that WPScan will be joining Automattic! WPScan has been working on improving the WordPress security ecosystem for over 10 years. During that time we released our wildly popular WordPress security scanner. We then developed and released the WordPress vulnerability database, where we triage and record hundreds of WordPress…
-
What is Attack Surface Mapping?
Bit Discovery have been using the WPScan WordPress security scanner and the WPScan Enterprise API for some time to add WordPress scanning functionality to their offering. We thought that it would be a good idea to introduce our readers to what Attack Surface Mapping is, and how organisations can benefit from it. To do this,…