Title: WPScan &#8211; WordPress 安全性掃描程式
Author: ethicalhack3r
Published: <strong>2019 年 3 月 2 日</strong>
Last modified: 2026 年 1 月 12 日

---

搜尋外掛

![](https://ps.w.org/wpscan/assets/banner-772x250.png?rev=2678579)

![](https://ps.w.org/wpscan/assets/icon.svg?rev=2678582)

# WPScan – WordPress 安全性掃描程式

 由 [ethicalhack3r](https://profiles.wordpress.org/ethicalhack3r/) 開發

[下載](https://downloads.wordpress.org/plugin/wpscan.1.16.zip)

 * [詳細資料](https://tw.wordpress.org/plugins/wpscan/#description)
 * [使用者評論](https://tw.wordpress.org/plugins/wpscan/#reviews)
 *  [安裝方式](https://tw.wordpress.org/plugins/wpscan/#installation)
 * [開發資訊](https://tw.wordpress.org/plugins/wpscan/#developers)

 [技術支援](https://wordpress.org/support/plugin/wpscan/)

## 外掛說明

**注意事項：**這個外掛已不再主動支援非企業使用者。我們**建議使用 [Jetpack Protect](https://tw.wordpress.org/plugins/jetpack-protect/)**，
這是一款使用 WPScan 巨量資料的免費 WordPress 安全性外掛。Jetpack Protect 能掃描網站
並對漏洞提出警示，讓網站能夠遠離安全性威脅及惡意程式碼。

The WPScan WordPress security plugin is unique in that it uses its own manually 
curated [WPScan WordPress Vulnerability Database](https://wpscan.com/). The vulnerability
database has been around since 2014 and is updated on a daily basis by dedicated
WordPress security specialists and the community at large. The database includes
more than 21,000 known security vulnerabilities. The plugin uses this database to
scan for [WordPress vulnerabilities](https://wpscan.com/wordpresses), [plugin vulnerabilities](https://wpscan.com/plugins)
and [theme vulnerabilities](https://wpscan.com/themes), and has the options to schedule
automated daily scans and to send email notifications.

WPScan has a Free API plan that should be suitable for most WordPress websites, 
however, also has paid plans for users who may need more API calls. To use the WPScan
WordPress Security Plugin you will need to use a free API token by [registering here](https://wpscan.com/).

**The Free plan allows 25 API requests per day. View the different available [API plans](https://wpscan.com/api).**

#### How many API requests do you need?

 * Our WordPress scanner makes one API request for the WordPress version, one request
   per installed plugin and one request per installed theme.
 * On average, a WordPress website has 22 installed plugins.
 * The Free plan should cover around 50% of all WordPress websites.

#### Security Checks

The WPScan WordPress Security Plugin will also check for other security issues, 
which do not require an API token, such as:

 * Check for debug.log files
 * Check for wp-config.php backup files
 * Check if XML-RPC is enabled
 * Check for code repository files
 * Check if default secret keys are used
 * Check for exported database files
 * Weak passwords
 * HTTPS enabled

#### What does the plugin do?

 * Scans for known WordPress vulnerabilities, plugin vulnerabilities and theme vulnerabilities;
 * Does additional security checks;
 * Shows an icon on the Admin Toolbar with the total number of security vulnerabilities
   found;
 * Notifies you by mail when new security vulnerabilities are found.

#### Further Reading

 * [WPScan WordPress Vulnerability Database](https://wpscan.com/)
 * [WPScan WordPress Security Scanner](https://wpscan.com/wordpress-security-scanner)
 * [WPScan Twitter](https://twitter.com/_wpscan_)

## 螢幕擷圖

[⌊List of vulnerabilities and icon at Admin Bar.⌉⌊List of vulnerabilities and icon
at Admin Bar.⌉[

List of vulnerabilities and icon at Admin Bar.

[⌊Notification settings.⌉⌊Notification settings.⌉[

Notification settings.

[⌊Site health page.⌉⌊Site health page.⌉[

Site health page.

## 安裝方式

 1. Upload `wpscan.zip` content to the `/wp-content/plugins/` directory
 2. Activate the plugin through the ‘Plugins’ menu in WordPress
 3. [Register](https://wpscan.com/register) for a free API token
 4. Save the API token to the WPScan settings page or within the wp-config.php file

## 常見問題集

### How many API calls are made?

There is one API call made for the WordPress version, one call for each installed
plugin and one for each theme. By default there is one scan per day. The number 
of daily scans can be configured when configuring notifications.

### How can I configure the API token in the wp-config.php file?

To configure your API token in the wp-config.php file, use the following PHP code:`
define( 'WPSCAN_API_TOKEN', '$your_api_token' );`

### How do I disable vulnerability scanning altogether?

You can set the following PHP constant in the wp-config.php file to disable scanning;`
define( 'WPSCAN_DISABLE_SCANNING_INTERVAL', true );`.

### Why is the “Summary” section and the “Run All” button not showing?

The cron job did not run, which can be due to:
 – The DISABLE_WP_CRON constant is
set to true in the wp-config.php file, but no system cron has been set (crontab -
e). – A plugin’s caching pages is enabled (see https://wordpress.stackexchange.com/
questions/93570/wp-cron-doesnt-execute-when-time-elapses?answertab=active#tab-top).–
The blog is unable to make a loopback request, see the Tools->Site Health for details.

If the issue can not be solved with the above, putting `define('ALTERNATE_WP_CRON',
true);` in the wp-config.php could help, however, will reduce the SEO of the blog.

## 使用者評論

![](https://secure.gravatar.com/avatar/c0c28c20332632f33a6ed7179d4a867aee84275c3e3807fd1807ea9c6e1542d5?
s=60&d=retro&r=g)

### 󠀁[Garbage now](https://wordpress.org/support/topic/garbage-now/)󠁿

 [tripflex](https://profiles.wordpress.org/tripflex/) 2023 年 8 月 30 日

complete garbage now, used to be amazing now they basically force you to use jetpack.
No replies trying to get enterprise license, another great product (used to be) 
that automattic has killed and used just for leads to jetpack

![](https://secure.gravatar.com/avatar/6dc7e69d6f9d24196c7d6c337d697a67992bf2f96361c72c564864969fd298ba?
s=60&d=retro&r=g)

### 󠀁[Good but lacking info](https://wordpress.org/support/topic/good-but-lacking-info/)󠁿

 [Dan](https://profiles.wordpress.org/dtrim/) 2023 年 3 月 10 日

There’s an issue that keeps appearing but no information about why or what to do
about it.

![](https://secure.gravatar.com/avatar/50ed2d4125b2ec67afa6321fd197c05794fa0442aee62b504d87af847f15f802?
s=60&d=retro&r=g)

### 󠀁[Jetpack Protect is not an alternative](https://wordpress.org/support/topic/jetpack-protect-is-not-an-alternative/)󠁿

 [wpgerd](https://profiles.wordpress.org/wpgerd/) 2023 年 1 月 31 日 3 則留言

In the past this was a very good way to check, if you have vulnerable Plugins/Themes,
but with Jetpack you didn’t get notifications, only if you pay the expensive plans;-(
There are other plugins, which do it better!

![](https://secure.gravatar.com/avatar/987a9a8f0a8d2c188a2865d0e0908faed64d068786dba8834043c15d7b387100?
s=60&d=retro&r=g)

### 󠀁[Don’t waste time creating account…](https://wordpress.org/support/topic/dont-waste-time-creating-account/)󠁿

 [quadeg](https://profiles.wordpress.org/quadeg/) 2022 年 9 月 7 日

…if you dont’t intend to pay for a sub, the plugin lies saying that you need a free
api to use it. Maybe the api is free but you need a subscription to access it. The
plugin is useless if you don’t subscribe. Use the tool’s website for a rather useless
partial report.

![](https://secure.gravatar.com/avatar/295394aed1bab38e59adfe9ab0b49af466ef111e036c506e780437880dc8cf0d?
s=60&d=retro&r=g)

### 󠀁[Apparent false flag about http versus https](https://wordpress.org/support/topic/apparent-false-flag-about-http-versus-https/)󠁿

 [Hans Konings](https://profiles.wordpress.org/kamawp/) 2022 年 4 月 25 日

I doubt that I will get me a paid subscription to this otherwise interesting plugin,
because it keeps sending me email alerts with this warning: “Security check Website
HTTPS The website does not seem to be using HTTPS (SSL/TLS) encryption for communications.”
When I check for http:/ in the database or anywhere else on the site, nothing is
found. When I run WPScan manually, it says everything is fine. All my browsers also
indicate that https is functioning. Why does WPSCan insist on sending me these alerts?
I would like to see a log about where WPScan found this error.

![](https://secure.gravatar.com/avatar/fff3164b86eff020927054e670e5afb8563ee5e55dc1646050b2fb71102fe5ba?
s=60&d=retro&r=g)

### 󠀁[Very Useful](https://wordpress.org/support/topic/very-useful-2949/)󠁿

 [Jan](https://profiles.wordpress.org/yotg/) 2022 年 3 月 1 日

Very useful especially if you use many plugins that are not professionally supported.

 [ 閱讀全部 28 則使用者評論 ](https://wordpress.org/support/plugin/wpscan/reviews/)

## 參與者及開發者

以下人員參與了開源軟體〈WPScan – WordPress 安全性掃描程式〉的開發相關工作。

參與者

 *   [ ethicalhack3r ](https://profiles.wordpress.org/ethicalhack3r/)
 *   [ FireFart ](https://profiles.wordpress.org/xfirefartx/)
 *   [ Erwan Le Rousseau ](https://profiles.wordpress.org/erwanlr/)

〈WPScan – WordPress 安全性掃描程式〉外掛目前已有 11 個本地化語言版本。 感謝[全部譯者](https://translate.wordpress.org/projects/wp-plugins/wpscan/contributors)
為這個外掛做出的貢獻。

[將〈WPScan – WordPress 安全性掃描程式〉外掛本地化為台灣繁體中文版](https://translate.wordpress.org/projects/wp-plugins/wpscan)

### 對開發相關資訊感興趣？

任何人均可[瀏覽程式碼](https://plugins.trac.wordpress.org/browser/wpscan/)、查看
[SVN 存放庫](https://plugins.svn.wordpress.org/wpscan/)，或透過 [RSS](https://plugins.trac.wordpress.org/log/wpscan/?limit=100&mode=stop_on_copy&format=rss)
訂閱[開發記錄](https://plugins.trac.wordpress.org/log/wpscan/)。

## 變更記錄

#### 1.16

 * Allow report to be POST-ed to webhook URL or downloaded as JSON.

#### 1.15.7

 * Fix the way the plugin handles extension versions to be more accurate.

#### 1.15.6

 * Added a notice pointing regular users to Jetpack Protect

#### 1.15.5

 * Update “Tested up to”
 * Some minor text changes
 * Fix API conflict

#### 1.15.4

 * Fix images not loading on some hosted websites
 * Update remediation links

#### 1.15.3

 * Fix fatal error in security checks

#### 1.15.2

 * Improve HTML and PDF report output
 * Disable security checks setting
 * Some refactoring

#### 1.15.1

 * Improved email alert text
 * Improved PDF report download layout

#### 1.15

 * Fix memory_limit when using list_files()
 * Use Action Scheduler
 * Add security check remediation links

#### 1.14.4

 * Use new free API defaults
 * Remove “Not found in database” message

#### 1.14.3

 * Don’t use HTTP_HOST in db exports check

#### 1.14.2

 * Revert DISABLE_WP_CRON check
 * Fix HTTPS check

#### 1.14.1

 * Use the wp_check_password() function to check for weak passwords

#### 1.14

 * Uses the status endpoint to get account data
 * Fixes the account status not being updated unless a scan is performed when the
   API token is updated/set
 * Adds vulnerability found hook
 * New security check: Check for weak user passwords
 * New security check: HTTPS
 * Clear plan info if API Token set to null
 * Fixes automated scanning when plugin deactivated and reactivated
 * Fixes cron job not being created when using the WPSCAN_API_TOKEN constant
 * Change default scanning time to the current time
 * Many other small improvements

#### 1.13.2

 * Fix XML-RPC check false positive

#### 1.13.1

 * Fix potential WP_Error issue in XML-RPC check
 * Add version to client side CSS and JS
 * Work towards PHP WordPress coding standards

#### 1.13

 * Improve the XML-RPC security check
 * No longer run a scan when adding an API token
 * Other small improvements & bug fixes

#### 1.12.3

 * Improve WPScan API error handling
 * Add status URL on WPScan API errors
 * Delete doing_cron transient on plugin activation
 * Replace the xmlrpc_encode_request() PHP function
 * Blur API token setting input box

#### 1.12.2

 * Fix bug: case statement should ‘break’

#### 1.12.1

 * Fix bug: Handle 404 API errors

#### 1.12

 * Code Refactoring
 * Adds Security Check System
 * Check for debug.log files
 * Check for wp-config.php backups
 * Check if XMLRPC is enabled
 * Check if default keys are used in wp-config.php
 * Check for code repo files .svn and .git
 * Create a Vulnerabilities to Ignore meta-box
 * Fixes Theme closed incorrect message and position in report
 * Show message if API is not working
 * Timeout cron jobs
 * Fix 404 error in devtools

#### 1.11

 * Change references of wpvulndb to wpscan.com

#### 1.10

 * Add WPSCAN_DISABLE_SCANNING_INTERVAL constant to disable automated scanning
 * Add an option in the settings to ignore items
 * Add an option in the settings to set the scan time
 * Show a not found in database message
 * Other minor bug fixes

#### 1.9

 * Add scanning interval option to settings page
 * Some other small improvements

#### 1.8

 * Show severity ratings for Enterprise users
 * Show Plugin Closed label
 * Add PDF report download
 * Add account status meta box
 * Add support for API token constant in wp-config.php file
 * Show vulnerabilities in Site Health
 * Update menu icon to monochrome

#### 1.7

 * Updated text and messages to reduce confusion
 * Removed WPScan_JWT class as no longer required

#### 1.6

 * Use the new slug helper method on all items on the page

#### 1.5

 * Better slug detection before calling the API

#### 1.4

 * Prevent multiple tasks to run simultaneously
 * Check Now Button disabled and Spinner icon displayed when a task is already running
 * Results page automatically reloaded when Task is finished (checked every 10s)

#### 1.3

 * Use the /status API endpoint to determine if the Token is valid. As a result,
   a call is no longer consumed when setting/changing the API token.
 * Trim and remove potential leading ‘v’ in versions when comparing then with the
   fixed_in values.

#### 1.2

 * Add notice about paid licenses

#### 1.1

 * Warn if API Limit was hit

#### 1.0

 * First release.

## 中繼資料

 *  版本 **1.16**
 *  最後更新 **6 個月前**
 *  啟用安裝數 **8,000+**
 *  WordPress 版本需求 ** 3.4 或更新版本 **
 *  已測試相容的 WordPress 版本 **6.9.5**
 *  PHP 版本需求 ** 5.5 或更新版本 **
 *  語言
 * [Dutch](https://nl.wordpress.org/plugins/wpscan/)、[Dutch (Belgium)](https://nl-be.wordpress.org/plugins/wpscan/)、
   [English (UK)](https://en-gb.wordpress.org/plugins/wpscan/)、[English (US)](https://wordpress.org/plugins/wpscan/)、
   [German](https://de.wordpress.org/plugins/wpscan/)、[Japanese](https://ja.wordpress.org/plugins/wpscan/)、
   [Russian](https://ru.wordpress.org/plugins/wpscan/)、[Spanish (Colombia)](https://es-co.wordpress.org/plugins/wpscan/)、
   [Spanish (Spain)](https://es.wordpress.org/plugins/wpscan/)、[Spanish (Venezuela)](https://ve.wordpress.org/plugins/wpscan/)、
   [Swedish](https://sv.wordpress.org/plugins/wpscan/)、及 [Turkish](https://tr.wordpress.org/plugins/wpscan/).
 *  [將這個外掛本地化為你的母語版本](https://translate.wordpress.org/projects/wp-plugins/wpscan)
 * 標籤:
 * [hack](https://tw.wordpress.org/plugins/tags/hack/)[security](https://tw.wordpress.org/plugins/tags/security/)
   [vulnerability](https://tw.wordpress.org/plugins/tags/vulnerability/)[wpscan](https://tw.wordpress.org/plugins/tags/wpscan/)
   [wpvulndb](https://tw.wordpress.org/plugins/tags/wpvulndb/)
 *  [進階檢視](https://tw.wordpress.org/plugins/wpscan/advanced/)

## 評分

 3.8 星，滿分為 5 星

 *  [  18 個 5 星使用者評論     ](https://wordpress.org/support/plugin/wpscan/reviews/?filter=5)
 *  [  0 個 4 星使用者評論     ](https://wordpress.org/support/plugin/wpscan/reviews/?filter=4)
 *  [  3 個 3 星使用者評論     ](https://wordpress.org/support/plugin/wpscan/reviews/?filter=3)
 *  [  0 個 2 星使用者評論     ](https://wordpress.org/support/plugin/wpscan/reviews/?filter=2)
 *  [  7 個 1 星使用者評論     ](https://wordpress.org/support/plugin/wpscan/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/wpscan/reviews/#new-post)

[查看全部使用者評論](https://wordpress.org/support/plugin/wpscan/reviews/)

## 參與者

 *   [ ethicalhack3r ](https://profiles.wordpress.org/ethicalhack3r/)
 *   [ FireFart ](https://profiles.wordpress.org/xfirefartx/)
 *   [ Erwan Le Rousseau ](https://profiles.wordpress.org/erwanlr/)

## 技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

 [檢視技術支援論壇](https://wordpress.org/support/plugin/wpscan/)