适用环境:Windows CMD(非 PowerShell)、自带 curl(Win10 1803+ 已内置) 文档约定:域名统一用
https://www.example.com占位,本地路径统一用C:\website\占位,使用时全局替换即可。 用途:上线检查、迁移核对、性能与安全巡检、代码扫描。
一、环境准备(每次开窗口先做)
REM 切到 UTF-8 代码页,避免中文输出乱码(curl 返回头/页面含中文时尤其重要)
chcp 65001
REM 可选:切换到工作盘(按实际盘符)
C:
cd \website
二、curl 常用占位变量(-w 参数里可用)
-w(write-out)用于在请求结束后输出自定义字段,是做"只看结果、不看正文"检测的核心。
| 变量 | 含义 |
|---|---|
%{http_code} |
HTTP 状态码(200/301/403/404/500…) |
%{time_total} |
总耗时(秒) |
%{time_namelookup} |
DNS 解析耗时 |
%{time_connect} |
TCP 建连耗时 |
%{time_appconnect} |
TLS 握手耗时 |
%{time_starttransfer} |
首字节时间 TTFB |
%{size_download} |
下载字节数 |
%{size_header} |
响应头字节数 |
%{remote_ip} |
实际连到的服务器 IP |
%{remote_port} |
实际连接端口 |
%{url_effective} |
跳转后的最终 URL(配合 -L 看真实落地页) |
%{num_redirects} |
经过的跳转次数 |
%{ssl_verify_result} |
证书校验结果(0 = 通过) |
%{content_type} |
响应的 MIME 类型 |
注意:CMD 里 % 要写两个 %% 吗?——不需要。在命令行直接敲写一个 %{http_code} 即可;只有写在 .bat 批处理文件里 时才要把 % 转义成 %%。本文示例默认按命令行写法。
三、HTTP 状态码检测(最常用)
REM 只看状态码,不输出正文(-s 静默 -o /dev/null 丢弃正文 -w 输出码)
curl -s -o /dev/null -w "%{http_code}\n" https://www.example.com/
REM 状态码 + 总耗时(上线巡检标配)
curl -s -o /dev/null -w "%{http_code} 耗时:%{time_total}s IP:%{remote_ip}\n" -m 15 https://www.example.com/
REM 状态码 + 完整性能分段
curl -s -o /dev/null -w "码:%{http_code} DNS:%{time_namelookup}s 建连:%{time_connect}s TLS:%{time_appconnect}s TTFB:%{time_starttransfer}s 总:%{time_total}s\n" -m 15 https://www.example.com/
REM -m 15 :最多等 15 秒,防止卡住(生产环境必加)
REM -L :跟随跳转(默认不跳,看不到最终码)
curl -s -L -o /dev/null -w "%{http_code} 跳转%{num_redirects}次 最终:%{url_effective}\n" https://www.example.com/
批量检测一组 URL(写进 .bat)
@echo off
chcp 65001
for %%U in (
"https://www.example.com/"
"https://www.example.com/about/"
"https://www.example.com/contact/"
"https://www.example.com/sitemap.xml"
"https://www.example.com/robots.txt"
) do (
for /f "delims=" %%R in ('curl -s -o /dev/null -w "%%{http_code}" -m 15 %%U') do echo %%R %%U
)
pause
批处理文件里
%{http_code}必须写成%%{http_code}。
四、重定向 / 301 迁移检查
REM 旧分类链接是否 301(不跟跳转,看的就是原始码)
curl -s -o /dev/null -w "%{http_code}\n" https://www.example.com/category/old-slug/
REM 看跳去哪(Location 头,不跟随)
curl -s -I https://www.example.com/category/old-slug/ | findstr /i "Location HTTP/"
REM 完整跳转链:每一跳的码和目的地
curl -s -I https://www.example.com/old-path/ > C:\website\jump.txt
REM 最终落地页是不是 HTTPS / 带 www
curl -s -L -o /dev/null -w "最终码:%{http_code} 最终URL:%{url_effective}\n" http://example.com/
五、响应头 / 服务器信息检查
REM 只拉响应头(HEAD 请求)
curl -s -I https://www.example.com/
REM 完整请求头+响应头(-v 详细模式,排障用)
curl -s -v -o NUL https://www.example.com/ 2>&1 | findstr /i "HTTP/ server: location: set-cookie x-powered"
REM 重点安全响应头是否齐全
curl -s -I https://www.example.com/ | findstr /i "Strict-Transport-Security X-Frame-Options X-Content-Type-Options Content-Security-Policy Referrer-Policy"
REM 上面无输出 = 这些头缺失,需补
REM 服务器用的什么程序(应不应该暴露)
curl -s -I https://www.example.com/ | findstr /i "server: x-powered-by"
REM 缓存策略
curl -s -I https://www.example.com/ | findstr /i "cache-control expires etag last-modified"
六、HTTPS / 证书检查
REM 证书是否有效(不加 -k,证书有问题会直接报错)
curl -s -o /dev/null -w "证书校验:%{ssl_verify_result} (0=通过)\n" https://www.example.com/
REM 故意忽略证书错误看内容(临时排障,-k)
curl -sk -o /dev/null -w "%{http_code}\n" https://www.example.com/
REM HTTP 自动跳转 HTTPS 是否生效
curl -s -I http://www.example.com/ | findstr /i "HTTP/ location:"
REM TLS 版本探测(强制 TLS1.2 / TLS1.3)
curl -s -o /dev/null -w "TLS1.2: %{http_code}\n" --tls-max 1.2 https://www.example.com/
七、内容抓取与关键字校验
REM 保存整页到本地文件再查(大页面避免管道问题)
curl -s https://www.example.com/article/post.html > C:\website\t.html
REM 首页 title 是否正确
curl -s https://www.example.com/ | findstr /i "<title>"
REM 站内是否还有残留 http:// 链接(无输出 = 通过)
curl -s https://www.example.com/ | findstr /i "http://www.example.com"
REM 是否还有旧的跳转参数 /go?url= 残留
curl -s https://www.example.com/article/post.html | findstr /i "go?url="
REM sitemap 归属(确认是哪款 SEO 插件生成)
curl -s https://www.example.com/sitemap.xml | findstr /i "All in One"
REM 百度 sitemap 必须 200(页脚/百度站长在用)
curl -s -o /dev/null -w "%{http_code}\n" https://www.example.com/sitemap_baidu.xml
REM robots.txt 内容
curl -s https://www.example.com/robots.txt
findstr 常用开关(内容过滤)
| 开关 | 含义 |
|---|---|
/i |
不区分大小写 |
/n |
显示行号 |
/c:"字符串" |
按整串匹配(含空格必须加这个) |
/s |
递归子目录 |
/v |
反向,显示不含该串的行 |
> 文件 |
结果写入文件(覆盖) |
>> 文件 |
追加 |
REM 无输出 = 通过 的典型用法(迁移后检查残留)
curl -s https://www.example.com/ | findstr /i "http://"
八、带 Header / Cookie / 模拟请求
REM 模拟空 UA(部分 WAF 对空 UA 返回 403,用来测防护策略)
curl -s -o /dev/null -w "%{http_code}\n" -H "User-Agent:" https://www.example.com/
REM 模拟手机 UA
curl -s -o /dev/null -w "%{http_code}\n" -A "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15" https://www.example.com/
REM 模拟 Google 爬虫
curl -s -o /dev/null -w "%{http_code}\n" -A "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" https://www.example.com/
REM 带 Cookie 测登录后页面
curl -s -o /dev/null -w "%{http_code}\n" -H "Cookie: key1=val1; key2=val2" https://www.example.com/member/
REM 伪装 Referer 测防盗链
curl -s -o /dev/null -w "%{http_code}\n" -e "https://www.google.com/" https://www.example.com/download/file.zip
POST / 表单提交
curl -s -X POST -d "name=test&age=18" https://www.example.com/api/submit
REM 上传 JSON
curl -s -X POST -H "Content-Type: application/json" -d "{\"key\":\"value\"}" https://www.example.com/api/
九、性能与压力初测
REM 单次详细耗时
curl -s -o /dev/null -w "DNS:%{time_namelookup} 建连:%{time_connect} TLS:%{time_appconnect} TTFB:%{time_starttransfer} 总:%{time_total} 下载:%{size_download}字节\n" -m 15 https://www.example.com/
REM 连续打 10 次看平均延迟(CMD 循环)
for /L %%i in (1,1,10) do @curl -s -o /dev/null -w "第%%i次 %{http_code} %{time_total}s\n" -m 15 https://www.example.com/
REM 测静态资源(CSS/JS/图片)是否走缓存、gzip
curl -s -I https://www.example.com/wp-content/themes/mytheme/style.css | findstr /i "content-encoding cache-control content-length"
REM 测 CDN 是否生效(看命中节点 IP / 响应头)
curl -s -I https://cdn.example.com/logo.png | findstr /i "server: x-cache age:"
十、本地代码扫描(findstr,迁移/清理废弃代码)
REM 切到主题/项目目录
cd /d C:\website\wp-content\themes\mytheme
REM 查找短标签 <? (PHP 配置若不支持会报错)
findstr /s /i /n /c:"<? " *.php > C:\website\find_short_tag.txt
REM 查找废弃/危险函数
findstr /s /i /n /c:"create_function" /c:"mysql_query" /c:"get_bloginfo" *.php > C:\website\find_deprecated.txt
REM 同时查多个文件类型里的某个关键词(CSS 和 JS 是否引用了同一个类名)
findstr /s /i /n /c:"small" *.css > C:\website\find_small_css.txt
findstr /s /i /n /c:"small" *.js > C:\website\find_small_js.txt
REM 查硬编码的旧域名(迁移后必须清零)
cd /d C:\website\wp-content\themes\mytheme
findstr /s /i /n /c:"old-domain.com" *.php *.css *.js > C:\website\find_old_domain.txt
REM 查 http:// 硬编码链接
findstr /s /i /n /c:"http://" *.php > C:\website\find_http.txt
扫描大项目时把结果落到文件再打开,避免刷屏;
/s递归、/n带行号,方便直接定位修改。
十一、WordPress / CMS 专项检查清单
迁移或改版后逐项跑一遍:
chcp 65001
set SITE=https://www.example.com
REM 1) 首页 / 关键页面状态码
curl -s -o /dev/null -w "首页: %{http_code}\n" %SITE%/
curl -s -o /dev/null -w "文章: %{http_code}\n" %SITE%/article/post.html
curl -s -o /dev/null -w "页面: %{http_code}\n" %SITE%/about/
REM 2) 必备文件
curl -s -o /dev/null -w "robots.txt: %{http_code}\n" %SITE%/robots.txt
curl -s -o /dev/null -w "sitemap.xml: %{http_code}\n" %SITE%/sitemap.xml
curl -s -o /dev/null -w "sitemap_baidu.xml: %{http_code}\n" %SITE%/sitemap_baidu.xml
REM 3) 旧链接 301
curl -s -o /dev/null -w "旧分类: %{http_code}\n" %SITE%/category/old-slug/
curl -s -o /dev/null -w "旧附件页: %{http_code}\n" %SITE%/?p=123
REM 4) 首页 title 与 SEO 插件
curl -s %SITE%/ | findstr /i "<title>"
REM 5) 无残留 http / 旧域名
curl -s %SITE%/ | findstr /i "http://www.example.com"
REM 6) 后台 / 登录页可访问但不应暴露版本号
curl -s -I %SITE%/wp-admin/ | findstr /i "HTTP/ location:"
curl -s %SITE%/readme.html | findstr /i "<title>"
十二、其他常用一招
REM 下载文件(验证可下载 + 看大小)
curl -s -L -o C:\website\download.zip https://www.example.com/file.zip
REM 下载同时打印进度信息
curl -L -o C:\website\file.zip https://www.example.com/file.zip
REM 查看某 IP 直连是否绕过 CDN(压测源站)
curl -s -o /dev/null -w "%{http_code} %{time_total}s\n" --resolve www.example.com:443:1.2.3.4 https://www.example.com/
REM 模拟限速下载(避免打满带宽)
curl -s --limit-rate 100K -o C:\website\big.iso https://www.example.com/big.iso
REM 查看 DNS 解析到哪(配合 nslookup 更直观)
nslookup www.example.com
十三、上线 / 巡检一键模板(复制即用)
保存为 check.bat,把域名和路径改成自己的:
@echo off
chcp 65001
set SITE=https://www.example.com
echo ===== 开始巡检 %SITE% =====
echo [1] 首页状态与耗时
curl -s -o /dev/null -w " 码:%{http_code} 总耗时:%{time_total}s TTFB:%{time_starttransfer}s\n" -m 15 %SITE%/
echo [2] 必备文件
curl -s -o /dev/null -w " robots.txt : %{http_code}\n" %SITE%/robots.txt
curl -s -o /dev/null -w " sitemap.xml : %{http_code}\n" %SITE%/sitemap.xml
echo [3] 安全响应头
curl -s -I %SITE%/ | findstr /i "Strict-Transport X-Frame X-Content-Type"
echo [4] HTTPS 跳转
curl -s -I http://www.example.com/ | findstr /i "HTTP/ location:"
echo [5] 残留 http 链接(无输出=通过)
curl -s %SITE%/ | findstr /i "http://www.example.com"
echo ===== 巡检完成 =====
pause
十四、常见坑
- CMD 里
%转义:命令行敲用一个%,写成.bat文件必须写%%(如%%{http_code})。 - 中文乱码:先
chcp 65001,且 curl 输出重定向到文件时编码可能仍是 GBK,用 VS Code 打开切编码。 - Windows 没有
/dev/null:curl -o /dev/null在 Git Bash / WSL 里能用;CMD 里用NUL(如-o NUL)或-o %TEMP%\null。- 实际上 Win10 自带 curl 的
-o NUL即可丢弃正文;本文用/dev/null是为了跨平台习惯,CMD 下请替换为NUL。
- 实际上 Win10 自带 curl 的
-I是 HEAD 请求:有些服务器对 HEAD 和 GET 返回不同结果,必要时用-r 0-0(只取第一个字节)模拟 GET。- findstr 匹配中文:先
chcp 65001仍可能匹配不到 UTF-8 内容,建议把页面>落成本地文件再用编辑器查。 -L才看得到最终码:不跟跳转时/old返回 301 而不是 200,别误以为是故障。- PowerShell ≠ CMD:PowerShell 里
curl是Invoke-WebRequest别名,参数不兼容;要在 PowerShell 里用真 curl 得写curl.exe。