Scan WordPress for Known CVEs
Fingerprint a WordPress site's core, plugins and themes while scanning for known CVEs next to the component and version they hit.
13 workflows that turn a reachable surface into confirmed findings: reflected XSS, open redirects, OpenAPI IDOR/BOLA, WordPress issues, SSRF, takeover checks, and unauthenticated database exposure. Use them when you already have hosts or specs and need a repeatable check.
Between them they run httpx, nuclei, gau, qsreplace and rustscan.
Fingerprint a WordPress site's core, plugins and themes while scanning for known CVEs next to the component and version they hit.
Compare QuicDraw baseline GET vs concurrent HTTP/3 race traffic, then correlate race evidence you can retest.
Decide allow, alert, or block on coding-agent file, shell, and network actions with AgentsLeak rules and a GolemHalt Cedar/YARA corpus.
Read a target's OpenAPI spec, enumerate every GET that takes an object id, and probe each with altered ids and stripped auth.
Seed a Chrome MV3 zip into ThreatXtension, then correlate permission and threat findings you can retest.
Crawl a target and mine its archived URLs, then test every parameter that takes a URL for server-side request forgery using out-of-band detection.
Collect a domain's archived URLs, keep parameters that reflect input, and fuzz each one for reflected and DOM cross-site scripting.
Turn an ASN into its live hosts, then scan the raw ports and the web surface for CVEs, misconfigurations, and exposures. Findings land in one report.
Port-scan a range for eight database engines and check every open service for unauthenticated access, from MongoDB and Redis to PostgreSQL.
Inventory HoneyMCP ghost tools and MCParasite channels, then correlate MCP trust-boundary findings you can retest.
Probe embedded web chat agents for injection, prompt leak, jailbreak, and role confusion with WebAgentAudit.
Find dangling CNAMEs an attacker could claim on your subdomains, with the service behind each record named so you know who to ask.
Mine a domain's archived URLs for redirect parameters, then confirm which ones send a browser to an attacker-controlled host.