A comprehensive YARA ruleset for detecting malware, security vulnerabilities, and suspicious patterns in WordPress installations, plugins, and themes.
- Overview
- Rule Files & Coverage
- Security Rules by Category
- Contents
- Installation
- Usage
- Scanning Strategies
- Rule Statistics
- Contributing
This repository contains 100+ YARA rules designed to detect:
β OWASP Top 10 Vulnerabilities β Authentication & Authorization Bypasses β Obfuscated Malware & Webshells β Supply Chain Attacks β OAuth/OIDC/SAML Security Issues β SQL Injection & RCE β File Upload & Path Traversal β API Security Issues β Credential Exposure
| File | Rules | Coverage |
|---|---|---|
rules/wordpress-threats.yar |
12 | Webshells, RCE, malware patterns |
rules/wordpress-owasp.yar |
10 | OWASP Top 10 vulnerabilities |
rules/wordpress-advance.yar |
9 | Advanced WordPress security |
rules/owasp.yar |
35+ | Comprehensive OWASP coverage |
rules/api-jwt.yar |
5 | JWT & API authentication |
rules/oauth-oidc.yar |
20+ | OAuth/OIDC vulnerabilities |
rules/saml.yar |
7 | SAML security issues |
rules/laravel-threats.yar |
5 | Laravel-specific threats |
rules/supply-chain-wordpress.yar |
8 | Supply chain attacks |
rules/user-sync-ad.yar |
10 | LDAP/AD security |
| Total | ~100+ | Production Ready |
wordpress_sql_injection_unsanitized_input- SELECT with unfiltered $_GET/$_POSTPHP_Possible_SQL_Injection_String_Interpolation- Variable interpolation in SQLWP_SQL_Concat_From_Input- Direct string concatenation in queriesWP_WPDB_Unprepared- $wpdb->query() without prepared statements
wordpress_rce_unserialize- unserialize() on user inputwp_shell_exec_calls_or_obfuscation- system(), exec(), shell_exec() functionsWP_Shell_Patterns- Common webshell PHP patternsWP_Malicious_Eval_Base64- eval(base64_decode(...))api_jwt_algorithm_none_or_weak_validation- JWT with alg:noneLaravel_Obfuscated_PHP- Obfuscated PHP code in Laravel
wordpress_xss_unescaped_output- Unescaped user input in outputwp_open_redirect_header_location- header('Location: ...') with user inputmeta_refresh_redirect- Meta refresh redirects with user input
wordpress_csrf_missing_nonce_check- State-changing actions without noncewordpress_csrf_missing_nonce_verification- Missing wp_verify_nonce()wp_state_missing_or_not_validated- OAuth state not validated
wordpress_auth_bypass_static_key- Hardcoded encryption keyswordpress_missing_capability_check- Missing current_user_can() checkswp_auth_bypass_user_lookup_from_input- User lookup from unsanitized inputwp_missing_rate_limiting- No rate limiting on loginphp_plaintext_password_storage- Plaintext password comparison
wordpress_idor_raw_access- Insecure Direct Object Referencesmicroservice_trust_header_abuse- Trusting spoofable headersAD_Admin_Role_Mapping- Unchecked AD group to admin mapping
WP_DB_Credentials_In_Config- Hardcoded database credentialswp_insecure_tls_disabled- SSL/TLS verification disabledwp_insecure_cookie_settings- Missing Secure/HttpOnly/SameSiteOAuth_Client_Secret_Exposure- Hardcoded OAuth secretsOAuth_Token_Leakage_In_URL- Tokens in URLs/logswp_insecure_ip_and_http_usage- Insecure HTTP + spoofable IP headers
SAML_XML_Signature_Wrapping- XML Signature Wrapping attacksLDAP_Injection_Filter- LDAP injection in filters
wp_dependency_files_present- Detect composer.json/package.json (review with SCA)
OAuth_Token_Logged_Or_Dumped- Tokens in debug outputwp_debug_endpoints_exposed- Debug endpoints exposed
wordpress_auth_bypass_static_key- Hardcoded secretswordpress_missing_capability_check- Missing permission checkswp_auth_bypass_user_lookup_from_input- Auth bypass via user inputphp_plaintext_password_storage- Plaintext password storagewp_missing_rate_limiting- Missing login rate limitingAD_Admin_Role_Mapping- Unsafe AD group mappingIdP_Attribute_Trust- Trusting IdP attributes blindlyOIDC_Missing_IDToken_Verification- OIDC token not validated
wordpress_file_upload_no_validation- File upload without MIME validationwordpress_rfi_lfi_includes- Remote/Local File Inclusionwp_path_traversal_hint- Path traversal with ../ patternswordpress_arbitrary_file_delete- unlink() with user inputwordpress_direct_file_access- Missing ABSPATH guardWP_Insecure_NonAbsolute_Include_Path- Non-absolute include pathsLaravel_Storage_Backdoor- PHP in storage/public folderswp_supply_chain_remote_include- Remote includes in plugins
api_jwt_algorithm_none_or_weak_validation- JWT alg:none bypassapi_jwt_decoded_without_verification- JWT not verifiedJWT_IDTOKEN_NO_SIG_VERIFICATION- ID Token signature not checked
OAuth_Missing_State_Parameter- No CSRF protection via stateOAuth_Missing_State_Validation- State parameter not validatedOAuth_Email_Only_Acceptance- User lookup by email onlyOAuth_Token_Leakage_In_URL- Token in URL/logsOAuth_Missing_PKCE- Missing PKCE protectionOAuth_Open_Redirect_URI- Dynamic redirect_uri from inputOAuth_Token_Stored_Insecurely- Tokens stored without encryptionOAuth_Client_Secret_Exposure- Hardcoded client secretsOAuth_Implicit_Flow_Usage- Insecure implicit flowOAuth_Code_Leak_In_URL- Authorization code exposedOAuth_Missing_Audience_Check- Token audience not validatedOAuth_Insecure_HTTP_Endpoint- HTTP for token endpoint
OIDC_Missing_Nonce- OIDC request missing nonceOIDC_Missing_IDToken_Verification- ID Token not validated
api_endpoint_missing_authentication- REST endpoints without auth
SAML_Missing_Signature_Validation- SAML assertions not verifiedSAML_XML_Signature_Wrapping- XML Signature Wrapping attacksSAML_Missing_Audience_Validation- Missing AudienceRestriction checkSAML_Missing_Issuer_Validation- Issuer not validatedSAML_Unsigned_Assertion_Accepted- Unsigned assertions acceptedSAML_Disabled_Certificate_Validation- Certificate verification disabledSAML_RelayState_OpenRedirect- RelayState open redirect
LDAP_Injection_Filter- LDAP injection in filtersLDAP_Filter_User_Input- LDAP filter from request parametersAD_Auto_User_Creation- Automatic user creation from ADAD_Admin_Role_Mapping- AD groups mapped to adminIdP_Attribute_Trust- Blindly trusting IdP attributesMissing_Email_Domain_Validation- Email domain not validatedAD_Password_Sync- Password synced from ADLDAP_Insecure_Connection- LDAP without TLS
wp_supply_chain_remote_code_execution- Remote code execution in updateswp_supply_chain_obfuscated_payload_dropper- Obfuscated malware deliverywp_supply_chain_external_update_server- Malicious update serverswp_supply_chain_external_zip_install- External ZIP extractionwp_supply_chain_hidden_admin_creation- Silent admin user creationwp_supply_chain_vendor_folder_backdoor- Backdoors in vendor/wp_supply_chain_typosquatted_library- Typosquatted librarieswp_supply_chain_activation_time_execution- Code in plugin activation hookwp_supply_chain_remote_include- Remote file inclusion in plugins
wp_obfuscated_malicious_patterns- Multiple obfuscation indicatorsWP_Malicious_Eval_Base64- eval(base64_decode())WP_Obfuscated_Long_Strings- Long base64 stringsWP_Theme_Backdoor_Hidden_Admin- Hidden admin in themesLaravel_WebShell_Common- Common webshell keywordsLaravel_Backdoor_Indicators- Laravel backdoor patternsPHP_Uninitialized_Array_Used_In_Return- Suspicious array usage
wp_insecure_tls_disabled- SSL verification disabledwp_ssrf_url_param- Server-Side Request Forgerywp_insecure_http_geoapi- HTTP for geo/IP APIswp_insecure_ip_and_http_usage- Spoofable IP headersLDAP_Insecure_Connection- LDAP without TLSOAuth_Insecure_HTTP_Endpoint- Token endpoint over HTTP
wordpress_dependency_files_present- Dependency files (review with SCA)wp_debug_endpoints_exposed- Debug routes exposedjs_vulnerable_eval- JavaScript eval() usageWP_Unsanitized_SQL_Functions- mysql_query() without prepare
rules/β Directory containing all YARA rule fileswordpress-threats.yarβ Webshells, RCE, obfuscated codewordpress-owasp.yarβ OWASP Top 10 vulnerabilitieswordpress-advance.yarβ Advanced WordPress security checksowasp.yarβ Comprehensive OWASP coverageapi-jwt.yarβ JWT and API securityoauth-oidc.yarβ OAuth/OIDC vulnerabilitiessaml.yarβ SAML security issueslaravel-threats.yarβ Laravel-specific threatssupply-chain-wordpress.yarβ Supply chain attacksuser-sync-ad.yarβ LDAP/AD security
test-payloads/β Test cases and example malicious patternsyara_line_matcher.pyβ Python automation scriptREADME.mdβ This file
sudo apt install yara
# Install Python YARA bindings
pip install yara-pythonbrew install yara
# Install Python YARA bindings
pip install yara-pythonchoco install yara
# Install Python YARA bindings
pip install yara-python# Scan a single file
yara rules/wordpress-threats.yar /path/to/wordpress/plugin.php
# Scan a directory
yara -r rules/wordpress-threats.yar /var/www/html/wp-content/# Scan WordPress plugins with context
python yara_line_matcher.py rules/wordpress-threats.yar /var/www/html/wp-content/plugins --skip-folders node_modules,vendor,.git
# Scan all rule files
python yara_line_matcher.py rules/ /var/www/html/wp-content --skip-folders node_modules,vendor
# Save results to file
python yara_line_matcher.py rules/ /var/www/html > scan_results.txt# Combine all rules
yara -r rules/ /var/www/html/wp-content/# JSON output
yara -j rules/ /var/www/html/wp-content/ > report.json
# Show matches with line numbers
yara -s rules/owasp.yar /var/www/html/wp-content/yara rules/owasp.yar /var/www/html/wp-content/Focus: SQL Injection, RCE, Authentication Bypass
yara rules/wordpress-threats.yar /var/www/html/wp-content/Focus: Webshells, Obfuscated code, Known malware patterns
yara rules/api-jwt.yar rules/oauth-oidc.yar /var/www/html/wp-content/Focus: Token leakage, Missing validation, Secret exposure
yara -r rules/ /var/www/html/Focus: All vulnerabilities + supply chain + SAML/LDAP
name: WordPress Security Scan
on: [push, pull_request]
jobs:
yara-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- name: Install YARA
run: sudo apt install yara
- name: Run Security Scan
run: yara -r rules/ .#!/bin/bash
# .git/hooks/pre-commit
yara -r rules/ . && exit 0 || exit 1| Category | Rules | Severity |
|---|---|---|
| OWASP Top 10 | 35+ | Critical/High |
| Authentication | 8 | High |
| File Operations | 8 | High/Medium |
| API/OAuth | 15+ | High/Critical |
| SAML/LDAP | 15+ | High/Critical |
| Supply Chain | 9 | Critical/High |
| Obfuscation | 7 | High/Medium |
| Database | 6 | High |
| Transport | 6 | High |
| Total | ~100+ | Production Ready |
- False Positives: Some rules may trigger on legitimate code patterns. Review findings manually.
- False Negatives: New/obfuscated malware may not be detected. Use as part of defense-in-depth.
- Regular Updates: Keep rules updated as new threats emerge.
- Context Matters: Always analyze results in context of your codebase.
- Professional Review: Critical findings should be reviewed by security professionals.
Contributions are welcome! To contribute:
- Fork the repository
- Create a new rule file or update existing ones
- Test rules with both legitimate and malicious code
- Submit a pull request with documentation
This project is provided as-is for security research and WordPress vulnerability detection purposes.
For issues, questions, or rule suggestions, please open a GitHub issue.
Last Updated: 2026-05-19 Status: β Production Ready | 100+ Rules | Comprehensive Coverage