ButlerBlog

chad butler's weblog

  • About
  • Blog
  • WordPress Plugins
  • Contact
Home / Reviews / Plugin Review: Timthumb Vulnerability Scanner

Plugin Review: Timthumb Vulnerability Scanner

By Chad Butler 2 Comments

Well, if you are an active WordPress user (or designer, or developer), you are likely aware of the Timthumb vulnerability that has recently been wreaking havoc on WordPress blog owners.  (If you’re not aware, then read on, as you are actually far more likely to be effected than someone who has been paying attention to WordPress security.) 

This vulnerability is one of the base64 encoded hacks (similar to one that was going around a couple years ago).  Here is some information on the attack

  • Technical details and scripts of the WordPress TimThumb.php hack
  • WordPress discussion of the exploit
  • Matt Mullenweg comments on the the TimThumb saga

So, have you been hacked by the TimThumb exploit?  Are you vulnerable?  Now there is a quick and easy plugin to scan for this vulnerability.

The TimThumb Scanner is a plugin that is quick to install, quick to scan, and will tell you if you are vulnerable to attack via the exploit.

Install via Add New in your WordPress Plugin Admin Panel.  Search for “TimThumb” and it is currently the first result in the list.  Select Install Now to download and install the plugin.

Once installed, using the plugin is easy.  Go to the Tools menu and select Timthumb Sanner in the submenu.  Once there, click the “Scan” button.  It’s pretty simple – which in this case is a good thing.  It does one thing, and apparently does it well.  There are more details on the plugin page listed below.

The one downside that it only scans for a vulnerability.  It does not fix it for you.  But Peter Butler has provided some insight into how to clean up your site should you find that your site has been compromised.

Authors: Peter Butler, Jacob Gillespie

Plugin Page

Where to get it: WordPress.org Plugin Repository

 

 

 

 

 

 

 

 

Enjoyed this article?

Don't miss a single post. Subscribe to our RSS feed!

  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on X (Opens in new window) X
  • Click to email a link to a friend (Opens in new window) Email
  • Click to print (Opens in new window) Print
  • More
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Pinterest (Opens in new window) Pinterest

Filed Under: Reviews, WordPress Tagged With: other-plugins, plugins, Reviews, tools, WordPress

About Chad Butler

Chad Butler is a freelance writer and web developer. He has developed several popular WordPress plugins and has written for forbes.com, sfomag.com, and investopedia.com. He also runs a small organic farm in east Georgia.

Join Us!

I will never share your information. No spam. No junk. No kidding. Unsubscribe anytime.

Recent Posts:

  • The High Price of Free Plugins
  • YouTube Success: Key Tips for Enhancing Video Optimization and Visibility
  • Mobile App vs. Mobile Website Ideal Choice for your Business
  • Top Strategies to Boost Your Brand’s Visibility and Impact
  • Advanced Blogging Strategies: Using Analytics, A/B Testing, and Conversion Optimization Techniques to Grow Your Audience
  • Unlock Real-Time Process Insights to Save Time and Money
  • How Writers Can Attract More Audience Attention
  • Dress for Success – Even at Home
  • Mastering the Art of Crafting SMART Marketing Goals
  • Rediscover Your Brand Story: 7 Tips for Refreshing Your Company Identity

Archives

  • About
  • Blog
  • Archive
  • Contact

Site powered by WordPress, running on the Genesis Framework from StudioPress.

Unless otherwise noted, content on this site is © 2006-2025 ButlerBlog and may not be reproduced without express written permission from the author.

Some content may include affiliate links for which this site receives a small commission.