WPScan’s Dedicated Team of Security Experts Are Actually Random Unpaid People on the Internet
Last week we discussed an example of WordPress security providers often make marketing claims that don’t match up with what they deliver involving Patchstack, but they are certainly not alone in that. We ran across another example of that involving WPScan and a claimed vulnerability in a plugin used by at least one of our customers.
WPScan markets their service with a claim that they have a “dedicated team of WordPress security experts” and that they are “continually monitoring the web for new vulnerabilities”, but if you look at their blog, they tell a different story. At the end of September, they wrote a post titled “Writing Good Submissions“. In that, they partially gave away what they are really doing, which is getting other people to do their work for them: [Read more]