A WordPress honeypot that detects probes for plugins, themes, and common files used to fingerprint WordPress installations.
Wordpot is a WordPress honeypot that simulates a WordPress installation to detect and log probes for plugins, themes, TimThumb, and other common files used by attackers to fingerprint sites. It helps security professionals identify reconnaissance activities and potential threats targeting WordPress environments.
Security researchers, penetration testers, and system administrators who need to monitor and analyze attacks on WordPress installations.
It provides a lightweight, customizable solution for detecting WordPress-specific reconnaissance, with support for real themes and an extensible plugin system to mimic vulnerabilities.
A Wordpress Honeypot
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Allows easy setup via command-line arguments or a config file to specify host, port, blog title, and fake installed plugins and themes, as shown in the usage example.
Supports using actual WordPress themes by placing them in the static/wp-content/themes/ directory and rendering with Jinja2 templates, enhancing deception realism.
Offers a beta plugin system to mimic specific vulnerabilities or extend functionality, with a dedicated wiki for guidance on writing custom plugins.
Specifically designed to detect probes for WordPress plugins, themes, and TimThumb, making it effective for targeted reconnaissance in WordPress environments.
The plugin system is marked as beta, indicating potential instability and limited documentation, which may deter users needing reliable, production-ready extensions.
Requires users to manually edit Jinja2 templates and place theme folders, adding complexity compared to automated or pre-configured solutions.
With a copyright from 2012 and no mention of recent updates, it may not be actively maintained or compatible with the latest WordPress versions and security threats.