Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

mohamad186466/WordPress

https://github.com/mohamad186466/WordPress · scanned 2026-09-02 22:18 UTC (1 week, 2 days ago)

163 raw signals (0 security + 163 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 1 week, 2 days ago · v1 · 163 actionable findings from 1 signal source. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: excluding tests × Reset all
Scan summary Repository scanned at 89.3/100 with 90.0% coverage. It contains 7211 nodes across 4 cross-layer flows, written primarily in mixed languages. Engine surfaced 163 findings — concentrated in dependencies (57), frontend (41), security (33). Risk profile is high: 0 critical, 42 high, 45 medium. Recommended next step: open the dependencies layer findings first — that's where the highest-impact wins live.

Showing 143 of 163 actionable findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

high System graph security security conf 1.00 Insecure pattern 'eval_used' in wp-includes/js/jquery/jquery.schedule.js:30
Found a known-risky pattern (eval_used). Review and replace if possible.
wp-includes/js/jquery/jquery.schedule.js:30 Eval used
high System graph security security conf 1.00 Insecure pattern 'eval_used' in wp-includes/js/tinymce/tiny_mce_popup.js:192
Found a known-risky pattern (eval_used). Review and replace if possible.
wp-includes/js/tinymce/tiny_mce_popup.js:192 Eval used
high System graph security security conf 1.00 Insecure pattern 'eval_used' in wp-includes/js/tw-sack.js:119
Found a known-risky pattern (eval_used). Review and replace if possible.
wp-includes/js/tw-sack.js:119 Eval used
high System graph security security conf 1.00 Insecure pattern 'new_function_used' in wp-includes/js/colorpicker.js:413
Found a known-risky pattern (new_function_used). Review and replace if possible.
wp-includes/js/colorpicker.js:413 New function used
high System graph security security conf 1.00 Insecure pattern 'new_function_used' in wp-includes/js/colorpicker.min.js:2
Found a known-risky pattern (new_function_used). Review and replace if possible.
wp-includes/js/colorpicker.min.js:2 New function used
high System graph security security conf 1.00 Insecure pattern 'new_function_used' in wp-includes/js/underscore.js:951
Found a known-risky pattern (new_function_used). Review and replace if possible.
wp-includes/js/underscore.js:951 New function used
high System graph security security conf 1.00 Insecure pattern 'new_function_used' in wp-includes/js/underscore.min.js:2
Found a known-risky pattern (new_function_used). Review and replace if possible.
wp-includes/js/underscore.min.js:2 New function used
high System graph dependencies dependencies conf 0.90 Vulnerable dependency @babel/plugin-transform-modules-systemjs 7.28.5: GHSA-fv7c-fp4j-7gwp
OSV.dev reports `@babel/plugin-transform-modules-systemjs` at version `7.28.5` (resolved in `wp-content/themes/twentytwenty/package-lock.json`) is affected by GHSA-fv7c-fp4j-7gwp (aka CVE-2026-44728). Note: `@babel/plugin-transform-modules-systemjs` is a transitive dependency — pulled in by another…
wp-content/themes/twentytwenty/package-lock.json ScaOsvGhsa fv7c fp4j 7gwp
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp
OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. …
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 3jxr 9vmj r5cp
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.12: GHSA-mh99-v99m-4gvg
OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. …
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa mh99 v99m 4gvg
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.12: GHSA-rgw5-rvv9-x895
OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-rgw5-rvv9-x895 (aka CVE-2026-69152). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. …
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa rgw5 rvv9 x895
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 2.0.2: GHSA-3jxr-9vmj-r5cp
OSV.dev reports `brace-expansion` at version `2.0.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. b…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 3jxr 9vmj r5cp
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 2.0.2: GHSA-mh99-v99m-4gvg
OSV.dev reports `brace-expansion` at version `2.0.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. b…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa mh99 v99m 4gvg
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 2.0.2: GHSA-rgw5-rvv9-x895
OSV.dev reports `brace-expansion` at version `2.0.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-rgw5-rvv9-x895 (aka CVE-2026-69152). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. b…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa rgw5 rvv9 x895
high System graph dependencies dependencies conf 0.90 Vulnerable dependency browserslist 4.28.0: GHSA-73wf-gq98-2v4g
OSV.dev reports `browserslist` at version `4.28.0` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-73wf-gq98-2v4g (aka CVE-2026-73088). Note: `browserslist` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Browse…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 73wf gq98 2v4g
high System graph dependencies dependencies conf 0.90 Vulnerable dependency browserslist 4.28.0: GHSA-c83g-rgw3-j3cx
OSV.dev reports `browserslist` at version `4.28.0` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-c83g-rgw3-j3cx (aka CVE-2026-73089). Note: `browserslist` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Browse…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa c83g rgw3 j3cx
high System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.0: GHSA-52cp-r559-cp3m
OSV.dev reports `js-yaml` at version `4.1.0` (resolved in `wp-content/themes/twentytwenty/package-lock.json`) is affected by GHSA-52cp-r559-cp3m (aka CVE-2026-59869). Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. js-yaml: YAML merge…
wp-content/themes/twentytwenty/package-lock.json ScaOsvGhsa 52cp r559 cp3m
high System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.0: GHSA-5p4m-2wfm-xmqj
OSV.dev reports `js-yaml` at version `4.1.0` (resolved in `wp-content/themes/twentytwenty/package-lock.json`) is affected by GHSA-5p4m-2wfm-xmqj. Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. JS-YAML: Quadratic CPU consumption in !!…
wp-content/themes/twentytwenty/package-lock.json ScaOsvGhsa 5p4m 2wfm xmqj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 3.0.8: GHSA-23c5-xmqv-rm74
OSV.dev reports `minimatch` at version `3.0.8` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-23c5-xmqv-rm74 (aka CVE-2026-27904). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch ReD…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 23c5 xmqv rm74
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 3.0.8: GHSA-3ppc-4f35-3m26
OSV.dev reports `minimatch` at version `3.0.8` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3ppc-4f35-3m26 (aka CVE-2026-26996). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 3ppc 4f35 3m26
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 3.0.8: GHSA-7r86-cg39-jmmj
OSV.dev reports `minimatch` at version `3.0.8` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-7r86-cg39-jmmj (aka CVE-2026-27903). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 7r86 cg39 jmmj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 3.1.2: GHSA-23c5-xmqv-rm74
OSV.dev reports `minimatch` at version `3.1.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-23c5-xmqv-rm74 (aka CVE-2026-27904). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch ReD…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 23c5 xmqv rm74
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 3.1.2: GHSA-3ppc-4f35-3m26
OSV.dev reports `minimatch` at version `3.1.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3ppc-4f35-3m26 (aka CVE-2026-26996). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 3ppc 4f35 3m26
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 3.1.2: GHSA-7r86-cg39-jmmj
OSV.dev reports `minimatch` at version `3.1.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-7r86-cg39-jmmj (aka CVE-2026-27903). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 7r86 cg39 jmmj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 5.1.6: GHSA-23c5-xmqv-rm74
OSV.dev reports `minimatch` at version `5.1.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-23c5-xmqv-rm74 (aka CVE-2026-27904). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch ReD…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 23c5 xmqv rm74
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 5.1.6: GHSA-3ppc-4f35-3m26
OSV.dev reports `minimatch` at version `5.1.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3ppc-4f35-3m26 (aka CVE-2026-26996). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 3ppc 4f35 3m26
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 5.1.6: GHSA-7r86-cg39-jmmj
OSV.dev reports `minimatch` at version `5.1.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-7r86-cg39-jmmj (aka CVE-2026-27903). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 7r86 cg39 jmmj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency nanoid 3.3.11: GHSA-28wg-ghj8-5hjv
OSV.dev reports `nanoid` at version `3.3.11` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-28wg-ghj8-5hjv (aka CVE-2026-67214). Note: `nanoid` is a transitive dependency — pulled in by another package, not declared directly in a manifest. nanoid: non-secure…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 28wg ghj8 5hjv
high System graph dependencies dependencies conf 0.90 Vulnerable dependency nanoid 3.3.11: GHSA-2v37-7h3g-55p8
OSV.dev reports `nanoid` at version `3.3.11` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-2v37-7h3g-55p8 (aka CVE-2026-67213). Note: `nanoid` is a transitive dependency — pulled in by another package, not declared directly in a manifest. nanoid: custom gen…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 2v37 7h3g 55p8
high System graph dependencies dependencies conf 0.90 Vulnerable dependency picomatch 2.3.1: GHSA-c2c7-rcm5-vvqj
OSV.dev reports `picomatch` at version `2.3.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-c2c7-rcm5-vvqj (aka CVE-2026-33671). Note: `picomatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Picomatch has…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa c2c7 rcm5 vvqj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency picomatch 4.0.3: GHSA-c2c7-rcm5-vvqj
OSV.dev reports `picomatch` at version `4.0.3` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-c2c7-rcm5-vvqj (aka CVE-2026-33671). Note: `picomatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Picomatch has…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa c2c7 rcm5 vvqj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q
OSV.dev reports `postcss` at version `8.5.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623). PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments Aliases: CVE-20…
wp-content/themes/twentynineteen/package.json ScaOsvGhsa 6g55 p6wh 862q
high System graph dependencies dependencies conf 0.90 Vulnerable dependency postcss 8.5.6: GHSA-r28c-9q8g-f849
OSV.dev reports `postcss` at version `8.5.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-r28c-9q8g-f849 (aka CVE-2026-73646). PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure Aliases: …
wp-content/themes/twentynineteen/package.json ScaOsvGhsa r28c 9q8g f849
high System graph dependencies dependencies conf 0.90 Vulnerable dependency shell-quote 1.7.3: GHSA-395f-4hp3-45gv
OSV.dev reports `shell-quote` at version `1.7.3` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-395f-4hp3-45gv (aka CVE-2026-13311). Note: `shell-quote` is a transitive dependency — pulled in by another package, not declared directly in a manifest. shell-quo…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 395f 4hp3 45gv
high System graph dependencies dependencies conf 0.90 Vulnerable dependency tar 6.2.1: GHSA-23hp-3jrh-7fpw
OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-23hp-3jrh-7fpw (aka CVE-2026-59873). Note: `tar` is a transitive dependency — pulled in by another package, not declared directly in a manifest. node-tar: Decompression/p…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 23hp 3jrh 7fpw
high System graph dependencies dependencies conf 0.90 Vulnerable dependency tar 6.2.1: GHSA-34x7-hfp2-rc4v
OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-34x7-hfp2-rc4v (aka CVE-2026-24842). Note: `tar` is a transitive dependency — pulled in by another package, not declared directly in a manifest. node-tar Vulnerable to Ar…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 34x7 hfp2 rc4v
high System graph dependencies dependencies conf 0.90 Vulnerable dependency tar 6.2.1: GHSA-83g3-92jg-28cx
OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-83g3-92jg-28cx (aka CVE-2026-26960). Note: `tar` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Arbitrary File Read/Write…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 83g3 92jg 28cx
high System graph dependencies dependencies conf 0.90 Vulnerable dependency tar 6.2.1: GHSA-8qq5-rm4j-mr97
OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-8qq5-rm4j-mr97 (aka CVE-2026-23745). Note: `tar` is a transitive dependency — pulled in by another package, not declared directly in a manifest. node-tar is Vulnerable to…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 8qq5 rm4j mr97
high System graph dependencies dependencies conf 0.90 Vulnerable dependency tar 6.2.1: GHSA-8x88-c5mf-7j5w
OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-8x88-c5mf-7j5w (aka CVE-2026-59874). Note: `tar` is a transitive dependency — pulled in by another package, not declared directly in a manifest. node-tar: Negative tar en…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 8x88 c5mf 7j5w
high System graph dependencies dependencies conf 0.90 Vulnerable dependency tar 6.2.1: GHSA-9ppj-qmqm-q256
OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-9ppj-qmqm-q256 (aka CVE-2026-31802). Note: `tar` is a transitive dependency — pulled in by another package, not declared directly in a manifest. node-tar Symlink Path Tra…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 9ppj qmqm q256
high System graph dependencies dependencies conf 0.90 Vulnerable dependency tar 6.2.1: GHSA-qffp-2rhf-9h96
OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-qffp-2rhf-9h96 (aka CVE-2026-29786). Note: `tar` is a transitive dependency — pulled in by another package, not declared directly in a manifest. tar has Hardlink Path Tra…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa qffp 2rhf 9h96
high System graph dependencies dependencies conf 0.90 Vulnerable dependency tar 6.2.1: GHSA-r6q2-hw4h-h46w
OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-r6q2-hw4h-h46w (aka CVE-2026-23950). Note: `tar` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Race Condition in node-ta…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa r6q2 hw4h h46w
medium System graph security Analyzer error conf 1.00 Analyzer timeout: security.semgrep
analyzer exceeded 60.0s wall-clock (thread mode — daemon abandoned). Bump REPOBILITY_ANALYZER_TIMEOUT_S if expected.
Timeout
medium System graph quality Placeholder conf 1.00 Critical user flow still appears backed by mock or placeholder data
A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded.
Mock dataCritical flowGenerated repo pattern
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-admin/js/password-toggle.js:28
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-admin/js/password-toggle.js:28 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-admin/js/password-toggle.min.js:2
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-admin/js/password-toggle.min.js:2 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/colorpicker.js:256
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/colorpicker.js:256 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/colorpicker.min.js:2
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/colorpicker.min.js:2 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/jquery/jquery-migrate.js:886
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/jquery/jquery-migrate.js:886 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/jquery/jquery-migrate.min.js:2
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/jquery/jquery-migrate.min.js:2 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/quicktags.js:297
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/quicktags.js:297 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/quicktags.min.js:2
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/quicktags.min.js:2 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/lists/plugin.js:570
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/tinymce/plugins/lists/plugin.js:570 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/lists/plugin.min.js:1
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/tinymce/plugins/lists/plugin.min.js:1 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/wordpress/plugin.js:163
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/tinymce/plugins/wordpress/plugin.js:163 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/wordpress/plugin.min.js:1
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/tinymce/plugins/wordpress/plugin.min.js:1 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/themes/inlite/theme.js:776
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/tinymce/themes/inlite/theme.js:776 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/themes/modern/theme.js:1174
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/tinymce/themes/modern/theme.js:1174 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/tiny_mce_popup.js:377
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/tinymce/tiny_mce_popup.js:377 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tw-sack.js:172
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/tw-sack.js:172 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tw-sack.min.js:2
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/tw-sack.min.js:2 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/wp-custom-header.js:124
Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible.
wp-includes/js/wp-custom-header.js:124 Direct innerhtml assignment
medium System graph security security conf 0.65 Insecure pattern 'domparser_html_parse' in wp-includes/js/wp-sanitize.js:29
Found a known-risky pattern (domparser_html_parse). Review and replace if possible.
wp-includes/js/wp-sanitize.js:29 Domparser html parse
medium System graph security security conf 0.65 Insecure pattern 'domparser_html_parse' in wp-includes/js/wp-sanitize.min.js:2
Found a known-risky pattern (domparser_html_parse). Review and replace if possible.
wp-includes/js/wp-sanitize.min.js:2 Domparser html parse
medium System graph security Coverage conf 1.00 No auth library detected
The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing.
auth
medium System graph quality Placeholder conf 1.00 Placeholder or mock-heavy implementation detected
Found 622 placeholder/mock markers across 176 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data.
Mock dataIncompleteGenerated repo pattern
medium System graph security Secrets conf 0.58 Possible secret in wp-admin/js/auth-app.min.js
Detected 1 occurrence(s) matching password_literal. Rotate real credentials and move them to a secret manager.
wp-admin/js/auth-app.min.js:2 Password literal
medium System graph quality Tests conf 1.00 Very low test-to-source ratio
0 test file(s) for 458 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths.
Coverage
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v
OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-f886-m6hf-6m8v (aka CVE-2026-33750). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. …
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa f886 m6hf 6m8v
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 2.0.2: GHSA-f886-m6hf-6m8v
OSV.dev reports `brace-expansion` at version `2.0.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-f886-m6hf-6m8v (aka CVE-2026-33750). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. b…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa f886 m6hf 6m8v
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency ip-address 9.0.5: GHSA-mwp4-54f8-5fhr
OSV.dev reports `ip-address` at version `9.0.5` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-mwp4-54f8-5fhr. Note: `ip-address` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advis…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa mwp4 54f8 5fhr
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency ip-address 9.0.5: GHSA-v2v4-37r5-5v8g
OSV.dev reports `ip-address` at version `9.0.5` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-v2v4-37r5-5v8g. Note: `ip-address` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advis…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa v2v4 37r5 5v8g
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.0: GHSA-h67p-54hq-rp68
OSV.dev reports `js-yaml` at version `4.1.0` (resolved in `wp-content/themes/twentytwenty/package-lock.json`) is affected by GHSA-h67p-54hq-rp68. Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: htt…
wp-content/themes/twentytwenty/package-lock.json ScaOsvGhsa h67p 54hq rp68
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.0: GHSA-mh29-5h37-fv8m
OSV.dev reports `js-yaml` at version `4.1.0` (resolved in `wp-content/themes/twentytwenty/package-lock.json`) is affected by GHSA-mh29-5h37-fv8m. Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: htt…
wp-content/themes/twentytwenty/package-lock.json ScaOsvGhsa mh29 5h37 fv8m
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency lodash 4.17.21: GHSA-f23m-r3pf-42rh
OSV.dev reports `lodash` at version `4.17.21` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-f23m-r3pf-42rh (aka CVE-2025-13465, CVE-2026-2950). Note: `lodash` is a transitive dependency — pulled in by another package, not declared directly in a manifest. lo…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa f23m r3pf 42rh
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency lodash 4.17.21: GHSA-r5fr-rjxr-66jc
OSV.dev reports `lodash` at version `4.17.21` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-r5fr-rjxr-66jc. Note: `lodash` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: h…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa r5fr rjxr 66jc
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency nanoid 3.3.11: GHSA-xwg4-73v4-xw9w
OSV.dev reports `nanoid` at version `3.3.11` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-xwg4-73v4-xw9w. Note: `nanoid` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: ht…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa xwg4 73v4 xw9w
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency picomatch 2.3.1: GHSA-3v7f-55p6-f55p
OSV.dev reports `picomatch` at version `2.3.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3v7f-55p6-f55p (aka CVE-2026-33672). Note: `picomatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Picomatch: Me…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 3v7f 55p6 f55p
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency picomatch 4.0.3: GHSA-3v7f-55p6-f55p
OSV.dev reports `picomatch` at version `4.0.3` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3v7f-55p6-f55p (aka CVE-2026-33672). Note: `picomatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Picomatch: Me…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 3v7f 55p6 f55p
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency postcss 8.5.6: GHSA-fxqj-rqcc-2cmp
OSV.dev reports `postcss` at version `8.5.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-fxqj-rqcc-2cmp (aka CVE-2026-69153). PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is u…
wp-content/themes/twentynineteen/package.json ScaOsvGhsa fxqj rqcc 2cmp
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93
OSV.dev reports `postcss` at version `8.5.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-qx2v-qp2m-jg93 (aka CVE-2026-41305). PostCSS has XSS via Unescaped </style> in its CSS Stringify Output Aliases: CVE-2026-41305 Advisory: https://osv.dev/vulnerabili…
wp-content/themes/twentynineteen/package.json ScaOsvGhsa qx2v qp2m jg93
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency shell-quote 1.7.3: GHSA-w7jw-789q-3m8p
OSV.dev reports `shell-quote` at version `1.7.3` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-w7jw-789q-3m8p. Note: `shell-quote` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Adv…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa w7jw 789q 3m8p
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency tar 6.2.1: GHSA-gvwx-54wh-qm9j
OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-gvwx-54wh-qm9j (aka CVE-2026-59875). Note: `tar` is a transitive dependency — pulled in by another package, not declared directly in a manifest. node-tar: Uncaught Except…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa gvwx 54wh qm9j
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency tar 6.2.1: GHSA-r292-9mhp-454m
OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-r292-9mhp-454m. Note: `tar` is a transitive dependency — pulled in by another package, not declared directly in a manifest. node-tar: Uncontrolled recursion in mapHas/fil…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa r292 9mhp 454m
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency tar 6.2.1: GHSA-vmf3-w455-68vh
OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-vmf3-w455-68vh. Note: `tar` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://o…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa vmf3 w455 68vh
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency tar 6.2.1: GHSA-w8wr-v893-vjvp
OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-w8wr-v893-vjvp. Note: `tar` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://o…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa w8wr v893 vjvp
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency yaml 2.3.4: GHSA-48c2-rrv3-qjmp
OSV.dev reports `yaml` at version `2.3.4` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-48c2-rrv3-qjmp (aka CVE-2026-33532). Note: `yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. yaml is vulnerable to S…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa 48c2 rrv3 qjmp
low System graph quality Maintenance conf 1.00 111 TODO/FIXME markers
High count of TODO/FIXME/HACK markers — track them as issues so they're not forgotten.
low System graph quality Production readiness conf 1.00 Composite production-readiness gap
Multiple low-cost hardening controls are missing together: ci, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation.
Repo hardeningGenerated repo pattern
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-admin/js/password-strength-meter.js:65
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-admin/js/password-strength-meter.js:65 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-admin/js/password-strength-meter.min.js:2
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-admin/js/password-strength-meter.min.js:2 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-admin/js/updates.js:349
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-admin/js/updates.js:349 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-admin/js/updates.min.js:2
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-admin/js/updates.min.js:2 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/codemirror/codemirror.min.js:11
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/codemirror/codemirror.min.js:11 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/jquery/jquery-migrate.js:97
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/jquery/jquery-migrate.js:97 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/jquery/jquery-migrate.min.js:2
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/jquery/jquery-migrate.min.js:2 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/jquery/jquery.form.js:1534
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/jquery/jquery.form.js:1534 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/jquery/jquery.form.min.js:1
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/jquery/jquery.form.min.js:1 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/plupload/moxie.js:1183
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/plupload/moxie.js:1183 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/plupload/moxie.min.js:1
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/plupload/moxie.min.js:1 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/tinymce/plugins/compat3x/plugin.js:31
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/tinymce/plugins/compat3x/plugin.js:31 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/tinymce/plugins/compat3x/plugin.min.js:1
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/tinymce/plugins/compat3x/plugin.min.js:1 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/tinymce/plugins/paste/plugin.js:28
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/tinymce/plugins/paste/plugin.js:28 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/tinymce/plugins/paste/plugin.min.js:1
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/tinymce/plugins/paste/plugin.min.js:1 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/tinymce/plugins/wpdialogs/plugin.js:48
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/tinymce/plugins/wpdialogs/plugin.js:48 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/tinymce/plugins/wpdialogs/plugin.min.js:1
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/tinymce/plugins/wpdialogs/plugin.min.js:1 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/tinymce/tinymce.min.js:2
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/tinymce/tinymce.min.js:2 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/tinymce/wp-tinymce.js:3
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/tinymce/wp-tinymce.js:3 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/wp-api.js:1225
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/wp-api.js:1225 Fq console leak
low System graph frontend Frontend quality conf 0.85 Debug `console.log` remains in browser-facing code — wp-includes/js/wp-api.min.js:2
Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope. Why: Hygiene — easy to leak debug output. Rule id: fq.console-leak
wp-includes/js/wp-api.min.js:2 Fq console leak
low System graph quality Debug conf 1.00 Debug logging residue appears in source files
Found 45 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup.
CleanupRepo hardeningGenerated repo pattern
low System graph security security conf 1.00 Insecure pattern 'document_write' in wp-includes/js/tinymce/tiny_mce_popup.js:237
Found a known-risky pattern (document_write). Review and replace if possible.
wp-includes/js/tinymce/tiny_mce_popup.js:237 Document write
low System graph security security conf 1.00 Insecure pattern 'document_write' in wp-includes/js/tinymce/tinymce.min.js:2
Found a known-risky pattern (document_write). Review and replace if possible.
wp-includes/js/tinymce/tinymce.min.js:2 Document write
low System graph security security conf 1.00 Insecure pattern 'document_write' in wp-includes/js/tinymce/wp-tinymce.js:3
Found a known-risky pattern (document_write). Review and replace if possible.
wp-includes/js/tinymce/wp-tinymce.js:3 Document write
low System graph quality Integrity conf 1.00 Old/deprecated-named symbol `actions_copy` in wp-includes/js/clipboard.js:139
Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version.
old markerDead code
low System graph quality Integrity conf 1.00 Old/deprecated-named symbol `pdataOld` in wp-includes/js/jquery/jquery.js:5819
Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version.
old markerDead code
low System graph quality Integrity conf 1.00 Old/deprecated-named symbol `pg_end_copy` in wp-includes/js/codemirror/codemirror.min.js:11
Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version.
old markerDead code
low System graph frontend Frontend quality conf 0.85 React Flow edge with `label=` but no project-wide edge-label CSS override — wp-includes/js/jquery/ui/autocomplete.min.js:9
React Flow edge labels render with a white rectangle behind the text by default, which scatters bright boxes across a dark canvas. Either drop the label, or override `.react-flow__edge-textbg` and `.react-flow__edge-text` in your stylesheet. Why: P-H in CHECKLIST.md — vendor edge labels bleed whit…
wp-includes/js/jquery/ui/autocomplete.min.js:9 Fq edge label no bg
low System graph quality Complexity conf 1.00 Very large file: wp-admin/js/common.js (2598 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-admin/js/customize-controls.js (9407 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-admin/js/customize-nav-menus.js (3556 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-admin/js/customize-widgets.js (2373 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-admin/js/nav-menu.js (1906 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-admin/js/theme.js (2176 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-admin/js/updates.js (3497 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/backbone.js (2157 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/codemirror/csslint.js (10858 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/codemirror/esprima.js (6708 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/jquery/jquery.js (10716 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/jquery/ui/datepicker.js (2237 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/media-views.js (10656 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/mediaelement/mediaelement-and-player.js (8540 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/mediaelement/mediaelement.js (3984 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/plupload/moxie.js (9904 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/plupload/plupload.js (2379 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/tinymce/plugins/lists/plugin.js (2148 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/tinymce/plugins/paste/plugin.js (2367 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/tinymce/themes/inlite/theme.js (9792 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/tinymce/themes/modern/theme.js (9607 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph quality Complexity conf 1.00 Very large file: wp-includes/js/underscore.js (2063 lines)
Files with >800 lines often hide complexity hotspots and discourage tests.
low System graph dependencies dependencies conf 0.90 Vulnerable dependency @babel/core 7.25.7: GHSA-4x5r-pxfx-6jf8
OSV.dev reports `@babel/core` at version `7.25.7` (resolved in `wp-content/themes/twentytwenty/package-lock.json`) is affected by GHSA-4x5r-pxfx-6jf8 (aka CVE-2026-49356). Note: `@babel/core` is a transitive dependency — pulled in by another package, not declared directly in a manifest. @babel/cor…
wp-content/themes/twentytwenty/package-lock.json ScaOsvGhsa 4x5r pxfx 6jf8
low System graph dependencies dependencies conf 0.90 Vulnerable dependency @tootallnate/once 1.1.2: GHSA-vpq2-c234-7xj6
OSV.dev reports `@tootallnate/once` at version `1.1.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-vpq2-c234-7xj6 (aka CVE-2026-3449). Note: `@tootallnate/once` is a transitive dependency — pulled in by another package, not declared directly in a manifest.…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa vpq2 c234 7xj6
low System graph dependencies dependencies conf 0.90 Vulnerable dependency @tootallnate/once 2.0.0: GHSA-vpq2-c234-7xj6
OSV.dev reports `@tootallnate/once` at version `2.0.0` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-vpq2-c234-7xj6 (aka CVE-2026-3449). Note: `@tootallnate/once` is a transitive dependency — pulled in by another package, not declared directly in a manifest.…
wp-content/themes/twentynineteen/package-lock.json ScaOsvGhsa vpq2 c234 7xj6
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/c82c46e7-362b-4cbf-91ce-0303e694eef7/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/c82c46e7-362b-4cbf-91ce-0303e694eef7/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.