WordPress Exploit Scanner 0.1 has been released, in response to a comment on a recent thread about old versions of WordPress sites being hacked. You may have spotted this in your WordPress dashboard. Problem is, it only works for v2.5.1+, so it will only be useful in keeping you safe going forward. I just installed it on a basic WordPress site with K2, and got the following results:
Suspect Plugins
These plugin files look suspect. Please verify they are files you uploaded.
- ../themes/k2/app/includes/k2-sbm-loader.php
No suspicious posts or comments found
Hooray! No suspicious text found in your posts or comments tables!
For a brand new plugin that’s not bad, but throwing a false negative on such a popular theme is something that will need to be addressed. I’ll be keeping an eye on this one.