Penetration Testing

[ad_1]

Investigating penetration testing for client with four different WP sites. Site live with host outside of organization. Not looking for do it yourself suggestions. Looking for any guidance on what kind of companies or consultants do this work and how to define penetration testing for WP sites.

[ad_2]
1 Comment
  1. *> how to define penetration testing for WP sites.*

    Not sure what you mean exactly, but this is the sort of thing that pen testers test for:

    * The version of WordPress installed and any associated vulnerabilities
    * What plugins are installed and any associated vulnerabilities
    * What themes are installed and any associated vulnerabilities
    * Username enumeration
    * Users with weak passwords via password brute forcing
    * Backed up and publicly accessible wp-config.php files
    * Database dumps that may be publicly accessible
    * If error logs are exposed by plugins
    * Media file enumeration
    * Vulnerable Timthumb files
    * If the WordPress readme file is present
    * If WP-Cron is enabled
    * If user registration is enabled
    * Full Path Disclose
    * Upload directory listing

    source: [https://wpscan.com/wordpress-security-scanner])

 

This site will teach you how to build a WordPress website for beginners. We will cover everything from installing WordPress to adding pages, posts, and images to your site. You will learn how to customize your site with themes and plugins, as well as how to market your site online.

Buy WordPress Transfer