https://github.com/wordpress/wordpress
· scanned 2026-06-04 23:22 UTC (9 hours, 28 minutes ago)
· 10 languages
417 findings (87 legacy + 330 scanner) 11/13 scanners ran Scanner says 73 (lower by 22)
Last scanned 9 hours, 27 minutes ago · v2 · 252 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
0.0 | 0.20 | 0.00 |
documentation_score |
60.0 | 0.15 | 9.00 |
practices_score |
30.0 | 0.15 | 4.50 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 51.5 |
Showing 196 of 252 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
wp-includes/js/tw-sack.js:119
qualitylegacy
wp-includes/js/codemirror/fakejshint.js:14
qualitylegacy
wp-includes/html-api/html5-named-character-references.php:896
dependencylegacy
wp-admin/js/auth-app.js:84
secrets
wp-admin/js/auth-app.min.js:2
secrets
wp-includes/SimplePie/src/Cache/Memcache.php:66
qualitylegacy
wp-includes/SimplePie/src/Author.php:64
qualitylegacy
wp-admin/includes/import.php:140
qualitylegacy
wp-includes/js/tw-sack.js:136
path_traversallegacy
wp-includes/js/wp-sanitize.js:30
xxelegacy
wp-includes/js/jquery/suggest.js:212
qualitylegacy
wp-admin/js/tags-suggest.js:14
qualitylegacy
wp-admin/js/tags-box.js:65
qualitylegacy
wp-includes/js/shortcode.js:30
qualitylegacy
wp-includes/js/jquery/ui/effect-fold.js:43
qualitylegacy
wp-content/themes/twentytwentyone/assets/js/customize-helpers.js:33
qualitylegacy
wp-includes/js/jquery/jquery.form.min.js:1
owaspeval_used
wp-includes/js/jquery/jquery.schedule.js:30
owaspeval_used
wp-includes/js/tinymce/tiny_mce_popup.js:192
owaspeval_used
wp-includes/js/tw-sack.js:119
owaspeval_used
wp-includes/widgets/class-wp-widget-media-video.php:261
securitylegacy
wp-includes/blocks/navigation-submenu.php:194
securitylegacy
wp-includes/js/wp-embed.js:82
open_redirectlegacy
wp-admin/js/privacy-tools.js:91
open_redirectlegacy
wp-includes/js/wp-embed.js:99
qualitylegacy
wp-content/themes/twentyeleven/inc/block-patterns.php:125
qualitylegacy
wp-includes:1
qualitylegacy
wp-admin:1
qualitylegacy
wp-includes/js/mediaelement/mediaelement-and-player.min.js:12
owaspcors_wildcard
wp-includes/js/mediaelement/mediaelement.min.js:12
owaspcors_wildcard
wp-includes/js/plupload/moxie.min.js:1
owaspcors_wildcard
wp-includes/js/tinymce/tinymce.min.js:2
owaspcors_wildcard
wp-includes/js/tinymce/wp-tinymce.js:3
owaspcors_wildcard
wp-admin/js/media-gallery.js:23
qualitylegacy
wp-admin/js/link.js:82
qualitylegacy
wp-admin/js/application-passwords.js:50
qualitylegacy
wp-content/themes/twentyfourteen/content-link.php:1
qualitylegacy
wp-content/themes/twentyfourteen/content-image.php:1
qualitylegacy
wp-content/themes/twentyfourteen/content-gallery.php:1
qualitylegacy
wp-content/themes/twentyfourteen/content-audio.php:1
qualitylegacy
wp-content/themes/twentyfourteen/category.php:19
qualitylegacy
wp-content/themes/twentyfourteen/author.php:19
qualitylegacy
wp-content/themes/twentyfifteen/search.php:19
qualitylegacy
wp-content/themes/twentyfifteen/index.php:11
qualitylegacy
wp-content/themes/twentyfifteen/inc/customizer.php:464
qualitylegacy
wp-content/themes/twentyfifteen/image.php:32
qualitylegacy
wp-content/themes/twentyfifteen/content.php:24
qualitylegacy
wp-content/themes/twentyfifteen/content.php:16
qualitylegacy
wp-content/themes/twentyeleven/tag.php:18
qualitylegacy
wp-content/themes/twentyeleven/tag.php:16
qualitylegacy
wp-content/themes/twentyeleven/sidebar-page.php:1
qualitylegacy
wp-content/themes/twentyeleven/search.php:10
qualitylegacy
wp-content/themes/twentyeleven/index.php:12
qualitylegacy
wp-content/themes/twentyeleven/content.php:31
qualitylegacy
wp-content/themes/twentyeleven/content.php:18
qualitylegacy
wp-content/themes/twentyeleven/content-status.php:8
qualitylegacy
wp-content/themes/twentyeleven/content-single.php:11
qualitylegacy
wp-content/themes/twentyeleven/content-quote.php:25
qualitylegacy
wp-content/themes/twentyeleven/content-quote.php:12
qualitylegacy
wp-content/themes/twentyeleven/content-link.php:8
qualitylegacy
wp-content/themes/twentyeleven/category.php:18
qualitylegacy
wp-content/themes/twentyeleven/author.php:40
qualitylegacy
wp-content/themes/twentytwenty/assets/js/skip-link-focus-fix.js:1
qualitylegacy
wp-content/themes/twentysixteen/js/skip-link-focus-fix.js:1
qualitylegacy
wp-content/themes/twentyseventeen/assets/js/skip-link-focus-fix.js:2
qualitylegacy
wp-content/themes/twentynineteen/js/skip-link-focus-fix.js:1
qualitylegacy
wp-content/themes/twentytwenty/assets/js/skip-link-focus-fix.js:1
qualitylegacy
wp-content/themes/twentysixteen/js/skip-link-focus-fix.js:1
qualitylegacy
wp-content/themes/twentyseventeen/assets/js/skip-link-focus-fix.js:1
qualitylegacy
wp-content/themes/twentynineteen/js/skip-link-focus-fix.js:1
qualitylegacy
wp-content/themes/twentyfifteen/js/skip-link-focus-fix.js:1
qualitylegacy
wp-includes/js/tinymce/tiny_mce_popup.js:237
owaspdocument_write
wp-includes/js/tinymce/tinymce.min.js:2
owaspdocument_write
wp-includes/js/tinymce/wp-tinymce.js:3
owaspdocument_write
wp-admin/includes/credits.php:35
qualitylegacy
wp-admin/includes/class-wp-importer.php:151
qualitylegacy
wp-activate.php:159
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/6d531520-742c-4cc2-8f61-486e8f74ff8a/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/6d531520-742c-4cc2-8f61-486e8f74ff8a/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.