Going to do this in two parts:
-
A generic scan that checks for default wordpress file backups.
-
A custom scan that is based on the current theme, the user will have to provide a theme archive - this is then used as a sitemap to test for theme specific backup files.