{"id":28923,"date":"2014-04-14T18:45:10","date_gmt":"2014-04-14T18:45:10","guid":{"rendered":"https:\/\/wordpress.org\/plugins-wp\/anti-wpscan\/"},"modified":"2014-04-17T19:27:21","modified_gmt":"2014-04-17T19:27:21","slug":"anti-wpscan","status":"closed","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/anti-wpscan\/","author":13774457,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1","stable_tag":"1.1","tested":"3.9.40","requires":"3.8","requires_php":"","requires_plugins":"","header_name":"anti-wpscan","header_author":"BlackFault","header_description":"","assets_banners_color":"","last_updated":"2014-04-17 19:27:21","external_support_url":"","external_repository_url":"","donate_link":"http:\/\/www.blackfault.com","header_plugin_uri":"http:\/\/www.blackfault.com\/projects\/anti-wpscan","header_author_uri":"http:\/\/www.blackfault.com","rating":1,"author_block_rating":0,"active_installs":10,"downloads":1634,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":[],"upgrade_notice":{"":"<p>N\/A<\/p>"},"ratings":{"1":"1","2":0,"3":0,"4":0,"5":0},"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0","1.1"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[600],"plugin_category":[54],"plugin_contributors":[89951],"plugin_business_model":[],"class_list":["post-28923","plugin","type-plugin","status-closed","hentry","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-blackfault","plugin_committers-blackfault"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/anti-wpscan.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>1.1 is a beta.<\/p>\n\n<p>Tools such as wp-scan allow security professionals and malicous \u201chackers\u201d to scan your blog for security holes. It detects the version of Wordpress, and version of all your plugins and cross-checks with a vulnerability database to see if there are any security threats with those versions. The users of wp-scan can then exploit any vulnerabilities found to gain unauthorized access to your Wordpress blog.<\/p>\n\n<p>Anti-wpscan prevents this tool from obtaining these version numbers, greatly increasing security and prevent wp-scan bots from getting your version numbers.<\/p>\n\n<p>Note. All un-even minor version numbers are considered beta. 1.1 is a beta. 1.2 would be production ready.<\/p>\n\n<p>Features:<\/p>\n\n<ul>\n<li>Block Wordpress version detection.<\/li>\n<li>Block passive Wordpress version detection (not just the version in your meta tags).<\/li>\n<li>Block plugin version detection.<\/li>\n<li>Block all plugin change_log files.<\/li>\n<li>Block directory browsing for improperly setup web hosting.<\/li>\n<li>Block access to css files from clients without a referring url.<\/li>\n<li>Block access to important files in wp-include.<\/li>\n<li>Strip all comments from final putput. Prevents plugins from putting comments in your blog with version information.<\/li>\n<\/ul>\n\n<p>Requirements:<\/p>\n\n<ul>\n<li>Must be using an updated version of Wordpress.<\/li>\n<li>Must be using custom permalinks (this generates a .htaccess file which anti-wspcan uses).<\/li>\n<\/ul>\n\n<p>Check out my security blog at <a href=\"http:\/\/www.blackfault.com\">Blackfault.com<\/a> for more information.<\/p>\n\n<h3>Support<\/h3>\n\n<p><a href=\"http:\/\/www.blackfault.com\/projects\/anti-wpscan\">Get support here.<\/a><\/p>\n\n<h3>UnInstall<\/h3>\n\n<p>To un-install, open .htaccess and remove everything between #RULES ADDED BY anti-wpscan and #END ANTI-WPSCAN RULES.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload and unzip to your plugins folder.<\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt>Will this block all wp-scan detection?<\/dt>\n<dd><p>This will block version detection on most Wordpress blogs. Some plugins such as google-xml-generator(Google XML Sitemaps) outputs the Wordpress version and can not be blocked without changing the code of that plugin. We contact plugin authors as we find plugins that do this.<\/p><\/dd>\n<dt>Will this prevent me from getting hacked?<\/dt>\n<dd><p>While this plugin will detect the ability to scan your Wordpress blog with wp-scan, it will not prevent hackers from continuing to try. This plugin will prevent the detection of possible vulnerabilities on your blog.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0<\/h4>\n\n<ul>\n<li>Initial release. Allow for blocking of all plugin versions and blocks getting the version of Wordpress being used.<\/li>\n<\/ul>\n\n<h4>1.1<\/h4>\n\n<ul>\n<li>wp-scan now puts the primary domain in as the referer. Removed referer requirement from mod_rewrite rules. Hard blocks on all .txt and readme.html files.<\/li>\n<li>Added output buffer modification to remove ALL COMMENTS in html. Plugin authors like to put their plugin version information in there and we are stripping that.<\/li>\n<\/ul>","raw_excerpt":"The anti-wpscan plugin prevents the security tool wpscan from scanning your Wordpress blog and enhances other aspects of security.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/28923","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=28923"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/blackfault"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=28923"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=28923"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=28923"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=28923"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=28923"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=28923"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}