{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-255815a1a50e3789", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-admin/js/password-strength-meter.js:65", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-admin/js/password-strength-meter.js:65"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-5430a8dc4228927d", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-admin/js/updates.js:349", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-admin/js/updates.js:349"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-24c233dee23dc680", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-admin/js/password-strength-meter.min.js:2", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-admin/js/password-strength-meter.min.js:2"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-396ac6bf84baf399", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-admin/js/updates.min.js:2", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-admin/js/updates.min.js:2"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-b81198fa40ba85eb", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/wp-api.js:1225", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/wp-api.js:1225"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-18879bdda300941c", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/wp-api.min.js:2", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/wp-api.min.js:2"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-4c16cb546d0aeb03", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/jquery/jquery.form.min.js:1", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/jquery/jquery.form.min.js:1"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-f963aa78d70005db", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/jquery.js:4200", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/jquery.js:4200"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-ab171ff01add1f42", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/jquery.form.js:326", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/jquery.form.js:326"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-109a3edc2c3cd5f8", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/jquery/jquery.form.js:1534", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/jquery/jquery.form.js:1534"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-aeca843c7daead00", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/jquery/jquery-migrate.js:97", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/jquery/jquery-migrate.js:97"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-e65203939cb7028f", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/jquery/jquery-migrate.min.js:2", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/jquery/jquery-migrate.min.js:2"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-f5a7e785412cd200", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/dialog.js:852", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/dialog.js:852"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-21fc2eb2db58a798", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/droppable.js:244", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/droppable.js:244"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-83927d1224c117df", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/spinner.js:226", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/spinner.js:226"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-6284e36fd9f0da19", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/tooltip.js:502", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/tooltip.js:502"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-93ea029025be682f", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/menu.js:685", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/menu.js:685"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-8ecdf21cc3d26b00", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/controlgroup.js:132", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/controlgroup.js:132"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-558bc730813591db", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/draggable.js:915", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/draggable.js:915"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-ba49b29cd0384eb1", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/core.js:157", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/core.js:157"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-2a515bfc03d31e3c", "name": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 wp-includes/js/jquery/ui/autocomplete.min.js", "shortDescription": {"text": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 wp-includes/js/jquery/ui/autocomplete.min.js:9"}, "fullDescription": {"text": "React Flow edge labels render with a white rectangle behind the text by default, which scatters bright boxes across a dark canvas. Either drop the label, or override `.react-flow__edge-textbg` and `.react-flow__edge-text` in your stylesheet.\n\nWhy: P-H in CHECKLIST.md \u2014 vendor edge labels bleed white through a dark canvas.\nRule id: fq.edge-label.no-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-b74ce546435d3f1b", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/sortable.js:239", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/sortable.js:239"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-0fbbdc0288a94443", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/button.js:29", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/button.js:29"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-b2dd7056eab706a9", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/tabs.js:899", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/tabs.js:899"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-f288c269387d5b43", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/datepicker.js:174", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/datepicker.js:174"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-c18675e9a6689a8f", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/effect-size.js:122", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/effect-size.js:122"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-8b4012b62fa9b9d3", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/mouse.js:64", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/mouse.js:64"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-6ea5180d261c6fc4", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/resizable.js:100", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/resizable.js:100"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-c7b83102d4d1dc48", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/plupload/moxie.min.js:1", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/plupload/moxie.min.js:1"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-5894680dbd0d2236", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/plupload/moxie.js:1172", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/plupload/moxie.js:1172"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-1b50bad0b1d5671f", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/plupload/moxie.js:1183", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/plupload/moxie.js:1183"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-93f7c24134769853", "name": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/codemirror/csslint.js:1582", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/codemirror/csslint.js:1582"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-8de5fb6335f3c3d5", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/codemirror/codemirror.min.js:11", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/codemirror/codemirror.min.js:11"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-8a7f7f9878efd901", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/wp-tinymce.js:3", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/wp-tinymce.js:3"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-162d2579e9a0e074", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/tinymce.min.js:2", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/tinymce.min.js:2"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-fd8160eb45d3be76", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/wpdialogs/plugin.js:48", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/wpdialogs/plugin.js:48"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-baca905633dd11a1", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/wpdialogs/plugin.min.js:1", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/wpdialogs/plugin.min.js:1"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-c5bc42538d8407bb", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/paste/plugin.js:28", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/paste/plugin.js:28"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-463701da83243ac7", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/paste/plugin.min.js:1", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/paste/plugin.min.js:1"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-38bbfaf0e00eeb1f", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/compat3x/plugin.js:31", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/compat3x/plugin.js:31"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-b1ae0b5bc3688ca3", "name": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/compat3x/plugin.min.js:1", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/compat3x/plugin.min.js:1"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-10f5d905b00946e3", "name": "Analyzer timeout: security.semgrep", "shortDescription": {"text": "Analyzer timeout: security.semgrep"}, "fullDescription": {"text": "analyzer exceeded 60.0s wall-clock (thread mode \u2014 daemon abandoned). Bump REPOBILITY_ANALYZER_TIMEOUT_S if expected."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-053ca0144e45d35b", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-admin/js/password-toggle.js:28", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-admin/js/password-toggle.js:28"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-06242daf286b8170", "name": "Possible secret in wp-admin/js/auth-app.min.js", "shortDescription": {"text": "Possible secret in wp-admin/js/auth-app.min.js"}, "fullDescription": {"text": "Detected 1 occurrence(s) matching password_literal. Rotate real credentials and move them to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.58}}, {"id": "scanner-78c138c57990f36b", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-admin/js/password-toggle.min.js:2", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-admin/js/password-toggle.min.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-4234394945279e48", "name": "Insecure pattern 'eval_used' in wp-includes/js/tw-sack.js:119", "shortDescription": {"text": "Insecure pattern 'eval_used' in wp-includes/js/tw-sack.js:119"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aca22486811c5a70", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tw-sack.js:172", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tw-sack.js:172"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-057b93e1a8f58684", "name": "Insecure pattern 'domparser_html_parse' in wp-includes/js/wp-sanitize.min.js:2", "shortDescription": {"text": "Insecure pattern 'domparser_html_parse' in wp-includes/js/wp-sanitize.min.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (domparser_html_parse). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-19d04b6eba856bb9", "name": "Insecure pattern 'new_function_used' in wp-includes/js/colorpicker.min.js:2", "shortDescription": {"text": "Insecure pattern 'new_function_used' in wp-includes/js/colorpicker.min.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7048e7f3d10405fe", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/colorpicker.min.js:2", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/colorpicker.min.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-bdb263eca19cf752", "name": "Insecure pattern 'domparser_html_parse' in wp-includes/js/wp-sanitize.js:29", "shortDescription": {"text": "Insecure pattern 'domparser_html_parse' in wp-includes/js/wp-sanitize.js:29"}, "fullDescription": {"text": "Found a known-risky pattern (domparser_html_parse). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-13e0254e7ef1e893", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tw-sack.min.js:2", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tw-sack.min.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-9f6ba5f311b91d84", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/quicktags.js:297", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/quicktags.js:297"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-2bc425cdbd7fa6f7", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/quicktags.min.js:2", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/quicktags.min.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-f8be0f7d0532d176", "name": "Insecure pattern 'new_function_used' in wp-includes/js/underscore.js:951", "shortDescription": {"text": "Insecure pattern 'new_function_used' in wp-includes/js/underscore.js:951"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2c79d43bc4fae925", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/wp-custom-header.js:124", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/wp-custom-header.js:124"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-b6b37810068d6b7a", "name": "Insecure pattern 'new_function_used' in wp-includes/js/underscore.min.js:2", "shortDescription": {"text": "Insecure pattern 'new_function_used' in wp-includes/js/underscore.min.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-47e2e0e4a0d5e872", "name": "Insecure pattern 'new_function_used' in wp-includes/js/colorpicker.js:413", "shortDescription": {"text": "Insecure pattern 'new_function_used' in wp-includes/js/colorpicker.js:413"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ff90d30e98b89709", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/colorpicker.js:256", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/colorpicker.js:256"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-935fe33251fc0e75", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/jquery/jquery-migrate.js:886", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/jquery/jquery-migrate.js:886"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-f0d94769c5969e47", "name": "Insecure pattern 'eval_used' in wp-includes/js/jquery/jquery.schedule.js:30", "shortDescription": {"text": "Insecure pattern 'eval_used' in wp-includes/js/jquery/jquery.schedule.js:30"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8cae2d40e6cf552c", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/jquery/jquery-migrate.min.js:2", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/jquery/jquery-migrate.min.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-7a358a4e9ff485c9", "name": "Insecure pattern 'document_write' in wp-includes/js/tinymce/wp-tinymce.js:3", "shortDescription": {"text": "Insecure pattern 'document_write' in wp-includes/js/tinymce/wp-tinymce.js:3"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d896abebd2088bcf", "name": "Insecure pattern 'eval_used' in wp-includes/js/tinymce/tiny_mce_popup.js:192", "shortDescription": {"text": "Insecure pattern 'eval_used' in wp-includes/js/tinymce/tiny_mce_popup.js:192"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a71d237d82908767", "name": "Insecure pattern 'document_write' in wp-includes/js/tinymce/tiny_mce_popup.js:237", "shortDescription": {"text": "Insecure pattern 'document_write' in wp-includes/js/tinymce/tiny_mce_popup.js:237"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43a1fd2a78816989", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/tiny_mce_popup.js:377", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/tiny_mce_popup.js:377"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-0726e1aeaf9c4d42", "name": "Insecure pattern 'document_write' in wp-includes/js/tinymce/tinymce.min.js:2", "shortDescription": {"text": "Insecure pattern 'document_write' in wp-includes/js/tinymce/tinymce.min.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8493e8618725e38", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/themes/inlite/theme.js:776", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/themes/inlite/theme.js:776"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-515eba03407611c5", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/themes/modern/theme.js:1174", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/themes/modern/theme.js:1174"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-126016e1fa457ddb", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/lists/plugin.js:570", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/lists/plugin.js:570"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-6d1c5124e56a4885", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/lists/plugin.min.js:1", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/lists/plugin.min.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-774e4ae68da08a57", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/wordpress/plugin.js:163", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/wordpress/plugin.js:163"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-2eb715853d810a04", "name": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/wordpress/plugin.min.js:1", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/wordpress/plugin.min.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d351a127db4a9160", "name": "Very large file: wp-admin/js/customize-widgets.js (2373 lines)", "shortDescription": {"text": "Very large file: wp-admin/js/customize-widgets.js (2373 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-984b766664241ce7", "name": "Very large file: wp-admin/js/customize-nav-menus.js (3556 lines)", "shortDescription": {"text": "Very large file: wp-admin/js/customize-nav-menus.js (3556 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7dd9b5c25464c103", "name": "Very large file: wp-admin/js/common.js (2598 lines)", "shortDescription": {"text": "Very large file: wp-admin/js/common.js (2598 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-154d49290a7f9ed5", "name": "Very large file: wp-admin/js/nav-menu.js (1906 lines)", "shortDescription": {"text": "Very large file: wp-admin/js/nav-menu.js (1906 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84324ecf5c2b3ede", "name": "Very large file: wp-admin/js/updates.js (3497 lines)", "shortDescription": {"text": "Very large file: wp-admin/js/updates.js (3497 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-48ea19041f52cec5", "name": "Very large file: wp-admin/js/theme.js (2176 lines)", "shortDescription": {"text": "Very large file: wp-admin/js/theme.js (2176 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e48d38beba470c5", "name": "Very large file: wp-admin/js/customize-controls.js (9407 lines)", "shortDescription": {"text": "Very large file: wp-admin/js/customize-controls.js (9407 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-11c4e5de0bb60f32", "name": "Very large file: wp-includes/js/media-views.js (10656 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/media-views.js (10656 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c88b471b5a94716", "name": "Very large file: wp-includes/js/backbone.js (2157 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/backbone.js (2157 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-273af316330e3bfd", "name": "Very large file: wp-includes/js/underscore.js (2063 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/underscore.js (2063 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-291e7f6d64768e0b", "name": "Very large file: wp-includes/js/jquery/jquery.js (10716 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/jquery/jquery.js (10716 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f46bd7799532b2a", "name": "Very large file: wp-includes/js/jquery/ui/datepicker.js (2237 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/jquery/ui/datepicker.js (2237 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5075e62eed5e7f45", "name": "Very large file: wp-includes/js/plupload/plupload.js (2379 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/plupload/plupload.js (2379 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-527eb2bfedd97681", "name": "Very large file: wp-includes/js/plupload/moxie.js (9904 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/plupload/moxie.js (9904 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d862213295133636", "name": "Very large file: wp-includes/js/mediaelement/mediaelement.js (3984 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/mediaelement/mediaelement.js (3984 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-956faf144bc88ff1", "name": "Very large file: wp-includes/js/mediaelement/mediaelement-and-player.js (8540 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/mediaelement/mediaelement-and-player.js (8540 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9fec8bb20f266df4", "name": "Very large file: wp-includes/js/codemirror/csslint.js (10858 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/codemirror/csslint.js (10858 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a45a8e3f5a39fa46", "name": "Very large file: wp-includes/js/codemirror/esprima.js (6708 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/codemirror/esprima.js (6708 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-adf7402590ed4a47", "name": "Very large file: wp-includes/js/tinymce/themes/inlite/theme.js (9792 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/tinymce/themes/inlite/theme.js (9792 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-89c64cdb566c3c8c", "name": "Very large file: wp-includes/js/tinymce/themes/modern/theme.js (9607 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/tinymce/themes/modern/theme.js (9607 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dac7a020b936d02b", "name": "Very large file: wp-includes/js/tinymce/plugins/paste/plugin.js (2367 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/tinymce/plugins/paste/plugin.js (2367 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b21cdd2dff4c7c8", "name": "Very large file: wp-includes/js/tinymce/plugins/lists/plugin.js (2148 lines)", "shortDescription": {"text": "Very large file: wp-includes/js/tinymce/plugins/lists/plugin.js (2148 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 458 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-47d713c72673a90e", "name": "111 TODO/FIXME markers", "shortDescription": {"text": "111 TODO/FIXME markers"}, "fullDescription": {"text": "High count of TODO/FIXME/HACK markers \u2014 track them as issues so they're not forgotten."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 45 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 622 placeholder/mock markers across 176 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: ci, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-960af6733c429673", "name": "Legacy-named symbol `actions_copy` in wp-includes/js/clipboard.js:139", "shortDescription": {"text": "Legacy-named symbol `actions_copy` in wp-includes/js/clipboard.js:139"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f9d818f9961e3e7c", "name": "Commented-code block (6 lines) in wp-includes/js/hoverIntent.js:133", "shortDescription": {"text": "Commented-code block (6 lines) in wp-includes/js/hoverIntent.js:133"}, "fullDescription": {"text": "4 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-9664ef11e6389900", "name": "Legacy-named symbol `pdataOld` in wp-includes/js/jquery/jquery.js:5819", "shortDescription": {"text": "Legacy-named symbol `pdataOld` in wp-includes/js/jquery/jquery.js:5819"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c5890d253d8ab46c", "name": "Legacy-named symbol `pg_end_copy` in wp-includes/js/codemirror/codemirror.min.js:11", "shortDescription": {"text": "Legacy-named symbol `pg_end_copy` in wp-includes/js/codemirror/codemirror.min.js:11"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d64eb5196032c730", "name": "Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623).\n\nPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments\n\nAliases: CVE-2026-45623\nAdvisory: https://osv.dev/vulnerability/GHSA-6g55-p6wh-862q\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-58803bf97cd3b47a", "name": "Vulnerable dependency postcss 8.5.6: GHSA-fxqj-rqcc-2cmp", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-fxqj-rqcc-2cmp"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-fxqj-rqcc-2cmp (aka CVE-2026-69153).\n\nPostCSS: incomplete fix of GHSA-6g55-p6wh-862q \u2014 attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset\n\nAliases: CVE-2026-69153\nAdvisory: https://osv.dev/vulnerability/GHSA-fxqj-rqcc-2cmp\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b9db4b13e9ca2f79", "name": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-qx2v-qp2m-jg93 (aka CVE-2026-41305).\n\nPostCSS has XSS via Unescaped </style> in its CSS Stringify Output\n\nAliases: CVE-2026-41305\nAdvisory: https://osv.dev/vulnerability/GHSA-qx2v-qp2m-jg93\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9f15a37a28de7477", "name": "Vulnerable dependency postcss 8.5.6: GHSA-r28c-9q8g-f849", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-r28c-9q8g-f849"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-r28c-9q8g-f849 (aka CVE-2026-73646).\n\nPostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure\n\nAliases: CVE-2026-73646\nAdvisory: https://osv.dev/vulnerability/GHSA-r28c-9q8g-f849\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1251bfaf32937934", "name": "Vulnerable dependency @tootallnate/once 2.0.0: GHSA-vpq2-c234-7xj6", "shortDescription": {"text": "Vulnerable dependency @tootallnate/once 2.0.0: GHSA-vpq2-c234-7xj6"}, "fullDescription": {"text": "OSV.dev reports `@tootallnate/once` at version `2.0.0` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-vpq2-c234-7xj6 (aka CVE-2026-3449).\nNote: `@tootallnate/once` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\n@tootallnate/once vulnerable to Incorrect Control Flow Scoping\n\nAliases: CVE-2026-3449\nAdvisory: https://osv.dev/vulnerability/GHSA-vpq2-c234-7xj6\nFix: upgrade `@tootallnate/once` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-53831c221a214668", "name": "Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-4ac29452ba3d0843", "name": "Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-f886-m6hf-6m8v (aka CVE-2026-33750).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: Zero-step sequence causes process hang and memory exhaustion\n\nAliases: CVE-2026-33750\nAdvisory: https://osv.dev/vulnerability/GHSA-f886-m6hf-6m8v\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-77cdbbacdb312aca", "name": "Vulnerable dependency brace-expansion 1.1.12: GHSA-mh99-v99m-4gvg", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-mh99-v99m-4gvg"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash\n\nAliases: CVE-2026-14257\nAdvisory: https://osv.dev/vulnerability/GHSA-mh99-v99m-4gvg\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-06546c6990b7fcb5", "name": "Vulnerable dependency brace-expansion 1.1.12: GHSA-rgw5-rvv9-x895", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-rgw5-rvv9-x895"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-rgw5-rvv9-x895 (aka CVE-2026-69152).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation\n\nAliases: CVE-2026-69152\nAdvisory: https://osv.dev/vulnerability/GHSA-rgw5-rvv9-x895\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-8441fbde3dfce5cc", "name": "Vulnerable dependency browserslist 4.28.0: GHSA-73wf-gq98-2v4g", "shortDescription": {"text": "Vulnerable dependency browserslist 4.28.0: GHSA-73wf-gq98-2v4g"}, "fullDescription": {"text": "OSV.dev reports `browserslist` at version `4.28.0` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-73wf-gq98-2v4g (aka CVE-2026-73088).\nNote: `browserslist` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nBrowserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)\n\nAliases: CVE-2026-73088\nAdvisory: https://osv.dev/vulnerability/GHSA-73wf-gq98-2v4g\nFix: upgrade `browserslist` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a350c219720a6fb0", "name": "Vulnerable dependency browserslist 4.28.0: GHSA-c83g-rgw3-j3cx", "shortDescription": {"text": "Vulnerable dependency browserslist 4.28.0: GHSA-c83g-rgw3-j3cx"}, "fullDescription": {"text": "OSV.dev reports `browserslist` at version `4.28.0` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-c83g-rgw3-j3cx (aka CVE-2026-73089).\nNote: `browserslist` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nBrowserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM\n\nAliases: CVE-2026-73089\nAdvisory: https://osv.dev/vulnerability/GHSA-c83g-rgw3-j3cx\nFix: upgrade `browserslist` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-26f6c4ae2d044c45", "name": "Vulnerable dependency brace-expansion 2.0.2: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 2.0.2: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `2.0.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2c3dc9c4f3e82346", "name": "Vulnerable dependency brace-expansion 2.0.2: GHSA-f886-m6hf-6m8v", "shortDescription": {"text": "Vulnerable dependency brace-expansion 2.0.2: GHSA-f886-m6hf-6m8v"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `2.0.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-f886-m6hf-6m8v (aka CVE-2026-33750).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: Zero-step sequence causes process hang and memory exhaustion\n\nAliases: CVE-2026-33750\nAdvisory: https://osv.dev/vulnerability/GHSA-f886-m6hf-6m8v\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-1e4d8698658a1a9d", "name": "Vulnerable dependency brace-expansion 2.0.2: GHSA-mh99-v99m-4gvg", "shortDescription": {"text": "Vulnerable dependency brace-expansion 2.0.2: GHSA-mh99-v99m-4gvg"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `2.0.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash\n\nAliases: CVE-2026-14257\nAdvisory: https://osv.dev/vulnerability/GHSA-mh99-v99m-4gvg\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a36ad53d93ed1409", "name": "Vulnerable dependency brace-expansion 2.0.2: GHSA-rgw5-rvv9-x895", "shortDescription": {"text": "Vulnerable dependency brace-expansion 2.0.2: GHSA-rgw5-rvv9-x895"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `2.0.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-rgw5-rvv9-x895 (aka CVE-2026-69152).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation\n\nAliases: CVE-2026-69152\nAdvisory: https://osv.dev/vulnerability/GHSA-rgw5-rvv9-x895\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d4777e90f1ac1fe7", "name": "Vulnerable dependency minimatch 5.1.6: GHSA-23c5-xmqv-rm74", "shortDescription": {"text": "Vulnerable dependency minimatch 5.1.6: GHSA-23c5-xmqv-rm74"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `5.1.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-23c5-xmqv-rm74 (aka CVE-2026-27904).\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nminimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions\n\nAliases: CVE-2026-27904\nAdvisory: https://osv.dev/vulnerability/GHSA-23c5-xmqv-rm74\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f55f97a9eeedbfde", "name": "Vulnerable dependency minimatch 5.1.6: GHSA-3ppc-4f35-3m26", "shortDescription": {"text": "Vulnerable dependency minimatch 5.1.6: GHSA-3ppc-4f35-3m26"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `5.1.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3ppc-4f35-3m26 (aka CVE-2026-26996).\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nminimatch has a ReDoS via repeated wildcards with non-matching literal in pattern\n\nAliases: CVE-2026-26996\nAdvisory: https://osv.dev/vulnerability/GHSA-3ppc-4f35-3m26\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-08ebd35bb0a901a9", "name": "Vulnerable dependency minimatch 5.1.6: GHSA-7r86-cg39-jmmj", "shortDescription": {"text": "Vulnerable dependency minimatch 5.1.6: GHSA-7r86-cg39-jmmj"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `5.1.6` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-7r86-cg39-jmmj (aka CVE-2026-27903).\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nminimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments\n\nAliases: CVE-2026-27903\nAdvisory: https://osv.dev/vulnerability/GHSA-7r86-cg39-jmmj\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d04cf937a1b9c1f3", "name": "Vulnerable dependency minimatch 3.1.2: GHSA-23c5-xmqv-rm74", "shortDescription": {"text": "Vulnerable dependency minimatch 3.1.2: GHSA-23c5-xmqv-rm74"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `3.1.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-23c5-xmqv-rm74 (aka CVE-2026-27904).\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nminimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions\n\nAliases: CVE-2026-27904\nAdvisory: https://osv.dev/vulnerability/GHSA-23c5-xmqv-rm74\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-9f480a4a342ebf1d", "name": "Vulnerable dependency minimatch 3.1.2: GHSA-3ppc-4f35-3m26", "shortDescription": {"text": "Vulnerable dependency minimatch 3.1.2: GHSA-3ppc-4f35-3m26"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `3.1.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3ppc-4f35-3m26 (aka CVE-2026-26996).\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nminimatch has a ReDoS via repeated wildcards with non-matching literal in pattern\n\nAliases: CVE-2026-26996\nAdvisory: https://osv.dev/vulnerability/GHSA-3ppc-4f35-3m26\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-6cac3710355ac301", "name": "Vulnerable dependency minimatch 3.1.2: GHSA-7r86-cg39-jmmj", "shortDescription": {"text": "Vulnerable dependency minimatch 3.1.2: GHSA-7r86-cg39-jmmj"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `3.1.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-7r86-cg39-jmmj (aka CVE-2026-27903).\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nminimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments\n\nAliases: CVE-2026-27903\nAdvisory: https://osv.dev/vulnerability/GHSA-7r86-cg39-jmmj\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c963864adf58023b", "name": "Vulnerable dependency ip-address 9.0.5: GHSA-mwp4-54f8-5fhr", "shortDescription": {"text": "Vulnerable dependency ip-address 9.0.5: GHSA-mwp4-54f8-5fhr"}, "fullDescription": {"text": "OSV.dev reports `ip-address` at version `9.0.5` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-mwp4-54f8-5fhr.\nNote: `ip-address` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mwp4-54f8-5fhr\nFix: upgrade `ip-address` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5be8d563b6661d64", "name": "Vulnerable dependency ip-address 9.0.5: GHSA-v2v4-37r5-5v8g", "shortDescription": {"text": "Vulnerable dependency ip-address 9.0.5: GHSA-v2v4-37r5-5v8g"}, "fullDescription": {"text": "OSV.dev reports `ip-address` at version `9.0.5` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-v2v4-37r5-5v8g.\nNote: `ip-address` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v2v4-37r5-5v8g\nFix: upgrade `ip-address` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ba0724a70b545741", "name": "Vulnerable dependency lodash 4.17.21: GHSA-f23m-r3pf-42rh", "shortDescription": {"text": "Vulnerable dependency lodash 4.17.21: GHSA-f23m-r3pf-42rh"}, "fullDescription": {"text": "OSV.dev reports `lodash` at version `4.17.21` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-f23m-r3pf-42rh (aka CVE-2025-13465, CVE-2026-2950).\nNote: `lodash` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nlodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`\n\nAliases: CVE-2025-13465, CVE-2026-2950, GHSA-xxjr-mmjv-4gpg\nAdvisory: https://osv.dev/vulnerability/GHSA-f23m-r3pf-42rh\nFix: upgrade `lodash` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f35831884e62775b", "name": "Vulnerable dependency lodash 4.17.21: GHSA-r5fr-rjxr-66jc", "shortDescription": {"text": "Vulnerable dependency lodash 4.17.21: GHSA-r5fr-rjxr-66jc"}, "fullDescription": {"text": "OSV.dev reports `lodash` at version `4.17.21` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-r5fr-rjxr-66jc.\nNote: `lodash` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r5fr-rjxr-66jc\nFix: upgrade `lodash` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b0d973210c14481d", "name": "Vulnerable dependency minimatch 3.0.8: GHSA-23c5-xmqv-rm74", "shortDescription": {"text": "Vulnerable dependency minimatch 3.0.8: GHSA-23c5-xmqv-rm74"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `3.0.8` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-23c5-xmqv-rm74 (aka CVE-2026-27904).\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nminimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions\n\nAliases: CVE-2026-27904\nAdvisory: https://osv.dev/vulnerability/GHSA-23c5-xmqv-rm74\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1f1ec5157283b5f5", "name": "Vulnerable dependency minimatch 3.0.8: GHSA-3ppc-4f35-3m26", "shortDescription": {"text": "Vulnerable dependency minimatch 3.0.8: GHSA-3ppc-4f35-3m26"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `3.0.8` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3ppc-4f35-3m26 (aka CVE-2026-26996).\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nminimatch has a ReDoS via repeated wildcards with non-matching literal in pattern\n\nAliases: CVE-2026-26996\nAdvisory: https://osv.dev/vulnerability/GHSA-3ppc-4f35-3m26\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-ab6ce85b3ab6578d", "name": "Vulnerable dependency minimatch 3.0.8: GHSA-7r86-cg39-jmmj", "shortDescription": {"text": "Vulnerable dependency minimatch 3.0.8: GHSA-7r86-cg39-jmmj"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `3.0.8` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-7r86-cg39-jmmj (aka CVE-2026-27903).\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nminimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments\n\nAliases: CVE-2026-27903\nAdvisory: https://osv.dev/vulnerability/GHSA-7r86-cg39-jmmj\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b6a9736f4cb7abd7", "name": "Vulnerable dependency nanoid 3.3.11: GHSA-28wg-ghj8-5hjv", "shortDescription": {"text": "Vulnerable dependency nanoid 3.3.11: GHSA-28wg-ghj8-5hjv"}, "fullDescription": {"text": "OSV.dev reports `nanoid` at version `3.3.11` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-28wg-ghj8-5hjv (aka CVE-2026-67214).\nNote: `nanoid` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nnanoid: non-secure generators can loop indefinitely with negative size\n\nAliases: CVE-2026-67214\nAdvisory: https://osv.dev/vulnerability/GHSA-28wg-ghj8-5hjv\nFix: upgrade `nanoid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-42e87a360f2f6fb9", "name": "Vulnerable dependency nanoid 3.3.11: GHSA-2v37-7h3g-55p8", "shortDescription": {"text": "Vulnerable dependency nanoid 3.3.11: GHSA-2v37-7h3g-55p8"}, "fullDescription": {"text": "OSV.dev reports `nanoid` at version `3.3.11` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-2v37-7h3g-55p8 (aka CVE-2026-67213).\nNote: `nanoid` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nnanoid: custom generators can loop indefinitely when size is zero\n\nAliases: CVE-2026-67213\nAdvisory: https://osv.dev/vulnerability/GHSA-2v37-7h3g-55p8\nFix: upgrade `nanoid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-4a5b852867a91fda", "name": "Vulnerable dependency nanoid 3.3.11: GHSA-xwg4-73v4-xw9w", "shortDescription": {"text": "Vulnerable dependency nanoid 3.3.11: GHSA-xwg4-73v4-xw9w"}, "fullDescription": {"text": "OSV.dev reports `nanoid` at version `3.3.11` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-xwg4-73v4-xw9w.\nNote: `nanoid` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xwg4-73v4-xw9w\nFix: upgrade `nanoid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-886c0ccc7bac38cc", "name": "Vulnerable dependency @tootallnate/once 1.1.2: GHSA-vpq2-c234-7xj6", "shortDescription": {"text": "Vulnerable dependency @tootallnate/once 1.1.2: GHSA-vpq2-c234-7xj6"}, "fullDescription": {"text": "OSV.dev reports `@tootallnate/once` at version `1.1.2` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-vpq2-c234-7xj6 (aka CVE-2026-3449).\nNote: `@tootallnate/once` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\n@tootallnate/once vulnerable to Incorrect Control Flow Scoping\n\nAliases: CVE-2026-3449\nAdvisory: https://osv.dev/vulnerability/GHSA-vpq2-c234-7xj6\nFix: upgrade `@tootallnate/once` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-7daf56731b132095", "name": "Vulnerable dependency picomatch 2.3.1: GHSA-3v7f-55p6-f55p", "shortDescription": {"text": "Vulnerable dependency picomatch 2.3.1: GHSA-3v7f-55p6-f55p"}, "fullDescription": {"text": "OSV.dev reports `picomatch` at version `2.3.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3v7f-55p6-f55p (aka CVE-2026-33672).\nNote: `picomatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPicomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching\n\nAliases: CVE-2026-33672\nAdvisory: https://osv.dev/vulnerability/GHSA-3v7f-55p6-f55p\nFix: upgrade `picomatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f498ead34397886e", "name": "Vulnerable dependency picomatch 2.3.1: GHSA-c2c7-rcm5-vvqj", "shortDescription": {"text": "Vulnerable dependency picomatch 2.3.1: GHSA-c2c7-rcm5-vvqj"}, "fullDescription": {"text": "OSV.dev reports `picomatch` at version `2.3.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-c2c7-rcm5-vvqj (aka CVE-2026-33671).\nNote: `picomatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPicomatch has a ReDoS vulnerability via extglob quantifiers\n\nAliases: CVE-2026-33671\nAdvisory: https://osv.dev/vulnerability/GHSA-c2c7-rcm5-vvqj\nFix: upgrade `picomatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5f0fbbf31dcbdf2d", "name": "Vulnerable dependency shell-quote 1.7.3: GHSA-395f-4hp3-45gv", "shortDescription": {"text": "Vulnerable dependency shell-quote 1.7.3: GHSA-395f-4hp3-45gv"}, "fullDescription": {"text": "OSV.dev reports `shell-quote` at version `1.7.3` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-395f-4hp3-45gv (aka CVE-2026-13311).\nNote: `shell-quote` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nshell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)\n\nAliases: CVE-2026-13311\nAdvisory: https://osv.dev/vulnerability/GHSA-395f-4hp3-45gv\nFix: upgrade `shell-quote` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b3bf19a91b3e301d", "name": "Vulnerable dependency shell-quote 1.7.3: GHSA-w7jw-789q-3m8p", "shortDescription": {"text": "Vulnerable dependency shell-quote 1.7.3: GHSA-w7jw-789q-3m8p"}, "fullDescription": {"text": "OSV.dev reports `shell-quote` at version `1.7.3` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-w7jw-789q-3m8p.\nNote: `shell-quote` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w7jw-789q-3m8p\nFix: upgrade `shell-quote` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f390f3f5d86bd30c", "name": "Vulnerable dependency tar 6.2.1: GHSA-23hp-3jrh-7fpw", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-23hp-3jrh-7fpw"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-23hp-3jrh-7fpw (aka CVE-2026-59873).\nNote: `tar` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nnode-tar: Decompression/parse DoS via unlimited input\n\nAliases: CVE-2026-59873\nAdvisory: https://osv.dev/vulnerability/GHSA-23hp-3jrh-7fpw\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-49a64695ab27ffc8", "name": "Vulnerable dependency tar 6.2.1: GHSA-34x7-hfp2-rc4v", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-34x7-hfp2-rc4v"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-34x7-hfp2-rc4v (aka CVE-2026-24842).\nNote: `tar` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nnode-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal\n\nAliases: CVE-2026-24842\nAdvisory: https://osv.dev/vulnerability/GHSA-34x7-hfp2-rc4v\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-07d0ecdfa4948e5b", "name": "Vulnerable dependency tar 6.2.1: GHSA-83g3-92jg-28cx", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-83g3-92jg-28cx"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-83g3-92jg-28cx (aka CVE-2026-26960).\nNote: `tar` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nArbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction\n\nAliases: CVE-2026-26960\nAdvisory: https://osv.dev/vulnerability/GHSA-83g3-92jg-28cx\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-290b753c48a04c6a", "name": "Vulnerable dependency tar 6.2.1: GHSA-8qq5-rm4j-mr97", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-8qq5-rm4j-mr97"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-8qq5-rm4j-mr97 (aka CVE-2026-23745).\nNote: `tar` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nnode-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization\n\nAliases: CVE-2026-23745\nAdvisory: https://osv.dev/vulnerability/GHSA-8qq5-rm4j-mr97\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2e08f06d3a917f54", "name": "Vulnerable dependency tar 6.2.1: GHSA-8x88-c5mf-7j5w", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-8x88-c5mf-7j5w"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-8x88-c5mf-7j5w (aka CVE-2026-59874).\nNote: `tar` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nnode-tar: Negative tar entry size causes infinite loop in archive replace\n\nAliases: CVE-2026-59874\nAdvisory: https://osv.dev/vulnerability/GHSA-8x88-c5mf-7j5w\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-62991adc9495b1df", "name": "Vulnerable dependency tar 6.2.1: GHSA-9ppj-qmqm-q256", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-9ppj-qmqm-q256"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-9ppj-qmqm-q256 (aka CVE-2026-31802).\nNote: `tar` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nnode-tar Symlink Path Traversal via Drive-Relative Linkpath\n\nAliases: CVE-2026-31802\nAdvisory: https://osv.dev/vulnerability/GHSA-9ppj-qmqm-q256\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-e06177827de95006", "name": "Vulnerable dependency tar 6.2.1: GHSA-gvwx-54wh-qm9j", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-gvwx-54wh-qm9j"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-gvwx-54wh-qm9j (aka CVE-2026-59875).\nNote: `tar` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nnode-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records\n\nAliases: CVE-2026-59875\nAdvisory: https://osv.dev/vulnerability/GHSA-gvwx-54wh-qm9j\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e65104fd1bc5287f", "name": "Vulnerable dependency tar 6.2.1: GHSA-qffp-2rhf-9h96", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-qffp-2rhf-9h96"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-qffp-2rhf-9h96 (aka CVE-2026-29786).\nNote: `tar` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\ntar has Hardlink Path Traversal via Drive-Relative Linkpath\n\nAliases: CVE-2026-29786\nAdvisory: https://osv.dev/vulnerability/GHSA-qffp-2rhf-9h96\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-7844c29a6a6e19b6", "name": "Vulnerable dependency tar 6.2.1: GHSA-r292-9mhp-454m", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-r292-9mhp-454m"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-r292-9mhp-454m.\nNote: `tar` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nnode-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r292-9mhp-454m\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-d7e7fe188951d172", "name": "Vulnerable dependency tar 6.2.1: GHSA-r6q2-hw4h-h46w", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-r6q2-hw4h-h46w"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-r6q2-hw4h-h46w (aka CVE-2026-23950).\nNote: `tar` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nRace Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS\n\nAliases: CVE-2026-23950\nAdvisory: https://osv.dev/vulnerability/GHSA-r6q2-hw4h-h46w\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f071e338471d4df1", "name": "Vulnerable dependency tar 6.2.1: GHSA-vmf3-w455-68vh", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-vmf3-w455-68vh"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-vmf3-w455-68vh.\nNote: `tar` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vmf3-w455-68vh\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-227e71c32e7eb052", "name": "Vulnerable dependency tar 6.2.1: GHSA-w8wr-v893-vjvp", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-w8wr-v893-vjvp"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-w8wr-v893-vjvp.\nNote: `tar` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w8wr-v893-vjvp\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7f3f59f8c6c6f9eb", "name": "Vulnerable dependency picomatch 4.0.3: GHSA-3v7f-55p6-f55p", "shortDescription": {"text": "Vulnerable dependency picomatch 4.0.3: GHSA-3v7f-55p6-f55p"}, "fullDescription": {"text": "OSV.dev reports `picomatch` at version `4.0.3` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-3v7f-55p6-f55p (aka CVE-2026-33672).\nNote: `picomatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPicomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching\n\nAliases: CVE-2026-33672\nAdvisory: https://osv.dev/vulnerability/GHSA-3v7f-55p6-f55p\nFix: upgrade `picomatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-75ce9751dd210b1a", "name": "Vulnerable dependency picomatch 4.0.3: GHSA-c2c7-rcm5-vvqj", "shortDescription": {"text": "Vulnerable dependency picomatch 4.0.3: GHSA-c2c7-rcm5-vvqj"}, "fullDescription": {"text": "OSV.dev reports `picomatch` at version `4.0.3` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-c2c7-rcm5-vvqj (aka CVE-2026-33671).\nNote: `picomatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPicomatch has a ReDoS vulnerability via extglob quantifiers\n\nAliases: CVE-2026-33671\nAdvisory: https://osv.dev/vulnerability/GHSA-c2c7-rcm5-vvqj\nFix: upgrade `picomatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-ff904d525b7c4280", "name": "Vulnerable dependency yaml 2.3.4: GHSA-48c2-rrv3-qjmp", "shortDescription": {"text": "Vulnerable dependency yaml 2.3.4: GHSA-48c2-rrv3-qjmp"}, "fullDescription": {"text": "OSV.dev reports `yaml` at version `2.3.4` (resolved in `wp-content/themes/twentynineteen/package-lock.json`) is affected by GHSA-48c2-rrv3-qjmp (aka CVE-2026-33532).\nNote: `yaml` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nyaml is vulnerable to Stack Overflow via deeply nested YAML collections\n\nAliases: CVE-2026-33532\nAdvisory: https://osv.dev/vulnerability/GHSA-48c2-rrv3-qjmp\nFix: upgrade `yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0aa99309d057fc19", "name": "Vulnerable dependency @babel/core 7.25.7: GHSA-4x5r-pxfx-6jf8", "shortDescription": {"text": "Vulnerable dependency @babel/core 7.25.7: GHSA-4x5r-pxfx-6jf8"}, "fullDescription": {"text": "OSV.dev reports `@babel/core` at version `7.25.7` (resolved in `wp-content/themes/twentytwenty/package-lock.json`) is affected by GHSA-4x5r-pxfx-6jf8 (aka CVE-2026-49356).\nNote: `@babel/core` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\n@babel/core: Arbitrary File Read via sourceMappingURL Comment\n\nAliases: CVE-2026-49356\nAdvisory: https://osv.dev/vulnerability/GHSA-4x5r-pxfx-6jf8\nFix: upgrade `@babel/core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-cb5d0c0545527de0", "name": "Vulnerable dependency @babel/plugin-transform-modules-systemjs 7.28.5: GHSA-fv7c-fp4j-7gwp", "shortDescription": {"text": "Vulnerable dependency @babel/plugin-transform-modules-systemjs 7.28.5: GHSA-fv7c-fp4j-7gwp"}, "fullDescription": {"text": "OSV.dev reports `@babel/plugin-transform-modules-systemjs` at version `7.28.5` (resolved in `wp-content/themes/twentytwenty/package-lock.json`) is affected by GHSA-fv7c-fp4j-7gwp (aka CVE-2026-44728).\nNote: `@babel/plugin-transform-modules-systemjs` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\n@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input\n\nAliases: CVE-2026-44728\nAdvisory: https://osv.dev/vulnerability/GHSA-fv7c-fp4j-7gwp\nFix: upgrade `@babel/plugin-transform-modules-systemjs` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c63f94090e16d9f6", "name": "Vulnerable dependency js-yaml 4.1.0: GHSA-52cp-r559-cp3m", "shortDescription": {"text": "Vulnerable dependency js-yaml 4.1.0: GHSA-52cp-r559-cp3m"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `4.1.0` (resolved in `wp-content/themes/twentytwenty/package-lock.json`) is affected by GHSA-52cp-r559-cp3m (aka CVE-2026-59869).\nNote: `js-yaml` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\njs-yaml: YAML merge-key chains can force quadratic CPU consumption\n\nAliases: CVE-2026-59869\nAdvisory: https://osv.dev/vulnerability/GHSA-52cp-r559-cp3m\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-7b68ea3a3f939cc4", "name": "Vulnerable dependency js-yaml 4.1.0: GHSA-5p4m-2wfm-xmqj", "shortDescription": {"text": "Vulnerable dependency js-yaml 4.1.0: GHSA-5p4m-2wfm-xmqj"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `4.1.0` (resolved in `wp-content/themes/twentytwenty/package-lock.json`) is affected by GHSA-5p4m-2wfm-xmqj.\nNote: `js-yaml` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nJS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) \u2014 CVE-2026-59870 fix not backported\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5p4m-2wfm-xmqj\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-e861b5906df28ef8", "name": "Vulnerable dependency js-yaml 4.1.0: GHSA-h67p-54hq-rp68", "shortDescription": {"text": "Vulnerable dependency js-yaml 4.1.0: GHSA-h67p-54hq-rp68"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `4.1.0` (resolved in `wp-content/themes/twentytwenty/package-lock.json`) is affected by GHSA-h67p-54hq-rp68.\nNote: `js-yaml` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h67p-54hq-rp68\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-6f135cbd72617edb", "name": "Vulnerable dependency js-yaml 4.1.0: GHSA-mh29-5h37-fv8m", "shortDescription": {"text": "Vulnerable dependency js-yaml 4.1.0: GHSA-mh29-5h37-fv8m"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `4.1.0` (resolved in `wp-content/themes/twentytwenty/package-lock.json`) is affected by GHSA-mh29-5h37-fv8m.\nNote: `js-yaml` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mh29-5h37-fv8m\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}]}}, "automationDetails": {"id": "repobility/30823"}, "properties": {"repository": "mohamad186466/WordPress", "repoUrl": "https://github.com/mohamad186466/WordPress", "branch": "main"}, "results": [{"ruleId": "scanner-255815a1a50e3789", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-admin/js/password-strength-meter.js:65"}, "properties": {"repobilityId": "0ce78097df51ecf7", "scanner": "scanner-primary", "fingerprint": "255815a1a50e3789", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-admin/js/password-strength-meter.js"}, "region": {"startLine": 65}}}]}, {"ruleId": "scanner-5430a8dc4228927d", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-admin/js/updates.js:349"}, "properties": {"repobilityId": "1c2d95974fb95301", "scanner": "scanner-primary", "fingerprint": "5430a8dc4228927d", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-admin/js/updates.js"}, "region": {"startLine": 349}}}]}, {"ruleId": "scanner-24c233dee23dc680", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-admin/js/password-strength-meter.min.js:2"}, "properties": {"repobilityId": "78584acc54c1f763", "scanner": "scanner-primary", "fingerprint": "24c233dee23dc680", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-admin/js/password-strength-meter.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-396ac6bf84baf399", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-admin/js/updates.min.js:2"}, "properties": {"repobilityId": "ef5edfddeb420ff2", "scanner": "scanner-primary", "fingerprint": "396ac6bf84baf399", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-admin/js/updates.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-b81198fa40ba85eb", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/wp-api.js:1225"}, "properties": {"repobilityId": "13f44c6b45f095a6", "scanner": "scanner-primary", "fingerprint": "b81198fa40ba85eb", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/wp-api.js"}, "region": {"startLine": 1225}}}]}, {"ruleId": "scanner-18879bdda300941c", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/wp-api.min.js:2"}, "properties": {"repobilityId": "244e6109f3e712e9", "scanner": "scanner-primary", "fingerprint": "18879bdda300941c", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/wp-api.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-4c16cb546d0aeb03", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/jquery/jquery.form.min.js:1"}, "properties": {"repobilityId": "32e69c57164e351b", "scanner": "scanner-primary", "fingerprint": "4c16cb546d0aeb03", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/jquery.form.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f963aa78d70005db", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/jquery.js:4200"}, "properties": {"repobilityId": "3c7558af8d3600bd", "scanner": "scanner-primary", "fingerprint": "f963aa78d70005db", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/jquery.js"}, "region": {"startLine": 4200}}}]}, {"ruleId": "scanner-ab171ff01add1f42", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/jquery.form.js:326"}, "properties": {"repobilityId": "57fd05558b2b5fa5", "scanner": "scanner-primary", "fingerprint": "ab171ff01add1f42", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/jquery.form.js"}, "region": {"startLine": 326}}}]}, {"ruleId": "scanner-109a3edc2c3cd5f8", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/jquery/jquery.form.js:1534"}, "properties": {"repobilityId": "51fc496fd3ab0c74", "scanner": "scanner-primary", "fingerprint": "109a3edc2c3cd5f8", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/jquery.form.js"}, "region": {"startLine": 1534}}}]}, {"ruleId": "scanner-aeca843c7daead00", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/jquery/jquery-migrate.js:97"}, "properties": {"repobilityId": "f07a7d18b89dbc0c", "scanner": "scanner-primary", "fingerprint": "aeca843c7daead00", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/jquery-migrate.js"}, "region": {"startLine": 97}}}]}, {"ruleId": "scanner-e65203939cb7028f", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/jquery/jquery-migrate.min.js:2"}, "properties": {"repobilityId": "8f2ceca065dbafb2", "scanner": "scanner-primary", "fingerprint": "e65203939cb7028f", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/jquery-migrate.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-f5a7e785412cd200", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/dialog.js:852"}, "properties": {"repobilityId": "4a3ac2f8ccebd7fb", "scanner": "scanner-primary", "fingerprint": "f5a7e785412cd200", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/dialog.js"}, "region": {"startLine": 852}}}]}, {"ruleId": "scanner-21fc2eb2db58a798", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/droppable.js:244"}, "properties": {"repobilityId": "24b786863bcaaed8", "scanner": "scanner-primary", "fingerprint": "21fc2eb2db58a798", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/droppable.js"}, "region": {"startLine": 244}}}]}, {"ruleId": "scanner-83927d1224c117df", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/spinner.js:226"}, "properties": {"repobilityId": "b1b9dbe902408486", "scanner": "scanner-primary", "fingerprint": "83927d1224c117df", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/spinner.js"}, "region": {"startLine": 226}}}]}, {"ruleId": "scanner-6284e36fd9f0da19", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/tooltip.js:502"}, "properties": {"repobilityId": "e6d66c4763ed830e", "scanner": "scanner-primary", "fingerprint": "6284e36fd9f0da19", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/tooltip.js"}, "region": {"startLine": 502}}}]}, {"ruleId": "scanner-93ea029025be682f", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/menu.js:685"}, "properties": {"repobilityId": "689641667e1e67f5", "scanner": "scanner-primary", "fingerprint": "93ea029025be682f", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/menu.js"}, "region": {"startLine": 685}}}]}, {"ruleId": "scanner-8ecdf21cc3d26b00", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/controlgroup.js:132"}, "properties": {"repobilityId": "310f5c4202eaabbc", "scanner": "scanner-primary", "fingerprint": "8ecdf21cc3d26b00", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/controlgroup.js"}, "region": {"startLine": 132}}}]}, {"ruleId": "scanner-558bc730813591db", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/draggable.js:915"}, "properties": {"repobilityId": "7d1f8e1142fa8557", "scanner": "scanner-primary", "fingerprint": "558bc730813591db", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/draggable.js"}, "region": {"startLine": 915}}}]}, {"ruleId": "scanner-ba49b29cd0384eb1", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/core.js:157"}, "properties": {"repobilityId": "ab3b0bc56f162651", "scanner": "scanner-primary", "fingerprint": "ba49b29cd0384eb1", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/core.js"}, "region": {"startLine": 157}}}]}, {"ruleId": "scanner-2a515bfc03d31e3c", "level": "note", "message": {"text": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 wp-includes/js/jquery/ui/autocomplete.min.js:9"}, "properties": {"repobilityId": "99977a581c3a951e", "scanner": "scanner-primary", "fingerprint": "2a515bfc03d31e3c", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.edge-label.no-bg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/autocomplete.min.js"}, "region": {"startLine": 9}}}]}, {"ruleId": "scanner-b74ce546435d3f1b", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/sortable.js:239"}, "properties": {"repobilityId": "9f740bc1743cd915", "scanner": "scanner-primary", "fingerprint": "b74ce546435d3f1b", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/sortable.js"}, "region": {"startLine": 239}}}]}, {"ruleId": "scanner-0fbbdc0288a94443", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/button.js:29"}, "properties": {"repobilityId": "1da01a51fa65ec54", "scanner": "scanner-primary", "fingerprint": "0fbbdc0288a94443", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/button.js"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-b2dd7056eab706a9", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/tabs.js:899"}, "properties": {"repobilityId": "9f070d23c88d6bc4", "scanner": "scanner-primary", "fingerprint": "b2dd7056eab706a9", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/tabs.js"}, "region": {"startLine": 899}}}]}, {"ruleId": "scanner-f288c269387d5b43", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/datepicker.js:174"}, "properties": {"repobilityId": "50f93a9c97fd4e4e", "scanner": "scanner-primary", "fingerprint": "f288c269387d5b43", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/datepicker.js"}, "region": {"startLine": 174}}}]}, {"ruleId": "scanner-c18675e9a6689a8f", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/effect-size.js:122"}, "properties": {"repobilityId": "7e153749312722a9", "scanner": "scanner-primary", "fingerprint": "c18675e9a6689a8f", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/effect-size.js"}, "region": {"startLine": 122}}}]}, {"ruleId": "scanner-8b4012b62fa9b9d3", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/mouse.js:64"}, "properties": {"repobilityId": "5d11b0b2f1d02a00", "scanner": "scanner-primary", "fingerprint": "8b4012b62fa9b9d3", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/mouse.js"}, "region": {"startLine": 64}}}]}, {"ruleId": "scanner-6ea5180d261c6fc4", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/jquery/ui/resizable.js:100"}, "properties": {"repobilityId": "12836e88461c76b0", "scanner": "scanner-primary", "fingerprint": "6ea5180d261c6fc4", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/ui/resizable.js"}, "region": {"startLine": 100}}}]}, {"ruleId": "scanner-c7b83102d4d1dc48", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/plupload/moxie.min.js:1"}, "properties": {"repobilityId": "a13e3ca0ceeecb7a", "scanner": "scanner-primary", "fingerprint": "c7b83102d4d1dc48", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/plupload/moxie.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5894680dbd0d2236", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/plupload/moxie.js:1172"}, "properties": {"repobilityId": "2eb9d16caa87883f", "scanner": "scanner-primary", "fingerprint": "5894680dbd0d2236", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/plupload/moxie.js"}, "region": {"startLine": 1172}}}]}, {"ruleId": "scanner-1b50bad0b1d5671f", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/plupload/moxie.js:1183"}, "properties": {"repobilityId": "87c6cbd07cc40d15", "scanner": "scanner-primary", "fingerprint": "1b50bad0b1d5671f", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/plupload/moxie.js"}, "region": {"startLine": 1183}}}]}, {"ruleId": "scanner-93f7c24134769853", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 wp-includes/js/codemirror/csslint.js:1582"}, "properties": {"repobilityId": "3758b7e39b937994", "scanner": "scanner-primary", "fingerprint": "93f7c24134769853", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/codemirror/csslint.js"}, "region": {"startLine": 1582}}}]}, {"ruleId": "scanner-8de5fb6335f3c3d5", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/codemirror/codemirror.min.js:11"}, "properties": {"repobilityId": "0a434c2198c7a11f", "scanner": "scanner-primary", "fingerprint": "8de5fb6335f3c3d5", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/codemirror/codemirror.min.js"}, "region": {"startLine": 11}}}]}, {"ruleId": "scanner-8a7f7f9878efd901", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/wp-tinymce.js:3"}, "properties": {"repobilityId": "b9f4931d59e04b26", "scanner": "scanner-primary", "fingerprint": "8a7f7f9878efd901", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/wp-tinymce.js"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-162d2579e9a0e074", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/tinymce.min.js:2"}, "properties": {"repobilityId": "d4a87b9e85ef76a5", "scanner": "scanner-primary", "fingerprint": "162d2579e9a0e074", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/tinymce.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-fd8160eb45d3be76", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/wpdialogs/plugin.js:48"}, "properties": {"repobilityId": "b30ddef7e301d386", "scanner": "scanner-primary", "fingerprint": "fd8160eb45d3be76", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/plugins/wpdialogs/plugin.js"}, "region": {"startLine": 48}}}]}, {"ruleId": "scanner-baca905633dd11a1", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/wpdialogs/plugin.min.js:1"}, "properties": {"repobilityId": "ee2aefb72f5e1460", "scanner": "scanner-primary", "fingerprint": "baca905633dd11a1", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/plugins/wpdialogs/plugin.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c5bc42538d8407bb", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/paste/plugin.js:28"}, "properties": {"repobilityId": "90dfdea5598ef4ae", "scanner": "scanner-primary", "fingerprint": "c5bc42538d8407bb", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/plugins/paste/plugin.js"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-463701da83243ac7", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/paste/plugin.min.js:1"}, "properties": {"repobilityId": "da4ed88599c01ded", "scanner": "scanner-primary", "fingerprint": "463701da83243ac7", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/plugins/paste/plugin.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-38bbfaf0e00eeb1f", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/compat3x/plugin.js:31"}, "properties": {"repobilityId": "d9db1eaa735529ea", "scanner": "scanner-primary", "fingerprint": "38bbfaf0e00eeb1f", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/plugins/compat3x/plugin.js"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-b1ae0b5bc3688ca3", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 wp-includes/js/tinymce/plugins/compat3x/plugin.min.js:1"}, "properties": {"repobilityId": "a25653f2e6d71980", "scanner": "scanner-primary", "fingerprint": "b1ae0b5bc3688ca3", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/plugins/compat3x/plugin.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-10f5d905b00946e3", "level": "warning", "message": {"text": "Analyzer timeout: security.semgrep"}, "properties": {"repobilityId": "err::timeout::security.semgrep", "scanner": "scanner-primary", "fingerprint": "10f5d905b00946e3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["analyzer-error", "timeout"]}}, {"ruleId": "scanner-053ca0144e45d35b", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-admin/js/password-toggle.js:28"}, "properties": {"repobilityId": "1b89a288676f37f4", "scanner": "scanner-primary", "fingerprint": "053ca0144e45d35b", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-admin/js/password-toggle.js"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-06242daf286b8170", "level": "warning", "message": {"text": "Possible secret in wp-admin/js/auth-app.min.js"}, "properties": {"repobilityId": "3462a77b422c29e3", "scanner": "scanner-primary", "fingerprint": "06242daf286b8170", "layer": "security", "severity": "medium", "confidence": 0.58, "tags": ["secrets", "password_literal"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-admin/js/auth-app.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-78c138c57990f36b", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-admin/js/password-toggle.min.js:2"}, "properties": {"repobilityId": "a6c25f995ca68689", "scanner": "scanner-primary", "fingerprint": "78c138c57990f36b", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-admin/js/password-toggle.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-4234394945279e48", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in wp-includes/js/tw-sack.js:119"}, "properties": {"repobilityId": "02298e1c8a602f72", "scanner": "scanner-primary", "fingerprint": "4234394945279e48", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tw-sack.js"}, "region": {"startLine": 119}}}]}, {"ruleId": "scanner-aca22486811c5a70", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tw-sack.js:172"}, "properties": {"repobilityId": "30ef3303a1b5f25e", "scanner": "scanner-primary", "fingerprint": "aca22486811c5a70", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tw-sack.js"}, "region": {"startLine": 172}}}]}, {"ruleId": "scanner-057b93e1a8f58684", "level": "warning", "message": {"text": "Insecure pattern 'domparser_html_parse' in wp-includes/js/wp-sanitize.min.js:2"}, "properties": {"repobilityId": "20b677ea312a3ce8", "scanner": "scanner-primary", "fingerprint": "057b93e1a8f58684", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "domparser_html_parse"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/wp-sanitize.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-19d04b6eba856bb9", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in wp-includes/js/colorpicker.min.js:2"}, "properties": {"repobilityId": "a0e968ff26f8a9b9", "scanner": "scanner-primary", "fingerprint": "19d04b6eba856bb9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/colorpicker.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-7048e7f3d10405fe", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/colorpicker.min.js:2"}, "properties": {"repobilityId": "b26fd58bf1b90eb0", "scanner": "scanner-primary", "fingerprint": "7048e7f3d10405fe", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/colorpicker.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-bdb263eca19cf752", "level": "warning", "message": {"text": "Insecure pattern 'domparser_html_parse' in wp-includes/js/wp-sanitize.js:29"}, "properties": {"repobilityId": "be378e35bafbf141", "scanner": "scanner-primary", "fingerprint": "bdb263eca19cf752", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "domparser_html_parse"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/wp-sanitize.js"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-13e0254e7ef1e893", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tw-sack.min.js:2"}, "properties": {"repobilityId": "ec57f2f53dd9ece4", "scanner": "scanner-primary", "fingerprint": "13e0254e7ef1e893", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tw-sack.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-9f6ba5f311b91d84", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/quicktags.js:297"}, "properties": {"repobilityId": "d4dc8a8d8642233c", "scanner": "scanner-primary", "fingerprint": "9f6ba5f311b91d84", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/quicktags.js"}, "region": {"startLine": 297}}}]}, {"ruleId": "scanner-2bc425cdbd7fa6f7", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/quicktags.min.js:2"}, "properties": {"repobilityId": "41c6b45349b53d13", "scanner": "scanner-primary", "fingerprint": "2bc425cdbd7fa6f7", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/quicktags.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-f8be0f7d0532d176", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in wp-includes/js/underscore.js:951"}, "properties": {"repobilityId": "0ad450b8121f9fae", "scanner": "scanner-primary", "fingerprint": "f8be0f7d0532d176", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/underscore.js"}, "region": {"startLine": 951}}}]}, {"ruleId": "scanner-2c79d43bc4fae925", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/wp-custom-header.js:124"}, "properties": {"repobilityId": "c36507a08e3dd605", "scanner": "scanner-primary", "fingerprint": "2c79d43bc4fae925", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/wp-custom-header.js"}, "region": {"startLine": 124}}}]}, {"ruleId": "scanner-b6b37810068d6b7a", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in wp-includes/js/underscore.min.js:2"}, "properties": {"repobilityId": "a874b03648219aae", "scanner": "scanner-primary", "fingerprint": "b6b37810068d6b7a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/underscore.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-47e2e0e4a0d5e872", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in wp-includes/js/colorpicker.js:413"}, "properties": {"repobilityId": "e674c0951d645661", "scanner": "scanner-primary", "fingerprint": "47e2e0e4a0d5e872", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/colorpicker.js"}, "region": {"startLine": 413}}}]}, {"ruleId": "scanner-ff90d30e98b89709", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/colorpicker.js:256"}, "properties": {"repobilityId": "5eb1c8e4d2255551", "scanner": "scanner-primary", "fingerprint": "ff90d30e98b89709", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/colorpicker.js"}, "region": {"startLine": 256}}}]}, {"ruleId": "scanner-935fe33251fc0e75", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/jquery/jquery-migrate.js:886"}, "properties": {"repobilityId": "4b633c946dac44d4", "scanner": "scanner-primary", "fingerprint": "935fe33251fc0e75", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/jquery-migrate.js"}, "region": {"startLine": 886}}}]}, {"ruleId": "scanner-f0d94769c5969e47", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in wp-includes/js/jquery/jquery.schedule.js:30"}, "properties": {"repobilityId": "cfeb8247085eaf6b", "scanner": "scanner-primary", "fingerprint": "f0d94769c5969e47", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/jquery.schedule.js"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-8cae2d40e6cf552c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/jquery/jquery-migrate.min.js:2"}, "properties": {"repobilityId": "d14102675d8a0f08", "scanner": "scanner-primary", "fingerprint": "8cae2d40e6cf552c", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/jquery/jquery-migrate.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-7a358a4e9ff485c9", "level": "note", "message": {"text": "Insecure pattern 'document_write' in wp-includes/js/tinymce/wp-tinymce.js:3"}, "properties": {"repobilityId": "7028cf9348dcffeb", "scanner": "scanner-primary", "fingerprint": "7a358a4e9ff485c9", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/wp-tinymce.js"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-d896abebd2088bcf", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in wp-includes/js/tinymce/tiny_mce_popup.js:192"}, "properties": {"repobilityId": "fc4499afc4e72035", "scanner": "scanner-primary", "fingerprint": "d896abebd2088bcf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/tiny_mce_popup.js"}, "region": {"startLine": 192}}}]}, {"ruleId": "scanner-a71d237d82908767", "level": "note", "message": {"text": "Insecure pattern 'document_write' in wp-includes/js/tinymce/tiny_mce_popup.js:237"}, "properties": {"repobilityId": "abea6be4dee06dbe", "scanner": "scanner-primary", "fingerprint": "a71d237d82908767", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/tiny_mce_popup.js"}, "region": {"startLine": 237}}}]}, {"ruleId": "scanner-43a1fd2a78816989", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/tiny_mce_popup.js:377"}, "properties": {"repobilityId": "cc037401168abbda", "scanner": "scanner-primary", "fingerprint": "43a1fd2a78816989", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/tiny_mce_popup.js"}, "region": {"startLine": 377}}}]}, {"ruleId": "scanner-0726e1aeaf9c4d42", "level": "note", "message": {"text": "Insecure pattern 'document_write' in wp-includes/js/tinymce/tinymce.min.js:2"}, "properties": {"repobilityId": "9dcccd11b77dc6ad", "scanner": "scanner-primary", "fingerprint": "0726e1aeaf9c4d42", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/tinymce.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-b8493e8618725e38", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/themes/inlite/theme.js:776"}, "properties": {"repobilityId": "0bb0818a1e2a129e", "scanner": "scanner-primary", "fingerprint": "b8493e8618725e38", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/themes/inlite/theme.js"}, "region": {"startLine": 776}}}]}, {"ruleId": "scanner-515eba03407611c5", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/themes/modern/theme.js:1174"}, "properties": {"repobilityId": "e610b72a3a77f88f", "scanner": "scanner-primary", "fingerprint": "515eba03407611c5", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/themes/modern/theme.js"}, "region": {"startLine": 1174}}}]}, {"ruleId": "scanner-126016e1fa457ddb", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/lists/plugin.js:570"}, "properties": {"repobilityId": "e13456ef46243862", "scanner": "scanner-primary", "fingerprint": "126016e1fa457ddb", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/plugins/lists/plugin.js"}, "region": {"startLine": 570}}}]}, {"ruleId": "scanner-6d1c5124e56a4885", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/lists/plugin.min.js:1"}, "properties": {"repobilityId": "235cb11d74eba1c3", "scanner": "scanner-primary", "fingerprint": "6d1c5124e56a4885", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/plugins/lists/plugin.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-774e4ae68da08a57", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/wordpress/plugin.js:163"}, "properties": {"repobilityId": "23b0f91120520574", "scanner": "scanner-primary", "fingerprint": "774e4ae68da08a57", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/plugins/wordpress/plugin.js"}, "region": {"startLine": 163}}}]}, {"ruleId": "scanner-2eb715853d810a04", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in wp-includes/js/tinymce/plugins/wordpress/plugin.min.js:1"}, "properties": {"repobilityId": "c50b34bf84ea86dc", "scanner": "scanner-primary", "fingerprint": "2eb715853d810a04", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/tinymce/plugins/wordpress/plugin.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-d351a127db4a9160", "level": "note", "message": {"text": "Very large file: wp-admin/js/customize-widgets.js (2373 lines)"}, "properties": {"repobilityId": "ca40146fe8634147", "scanner": "scanner-primary", "fingerprint": "d351a127db4a9160", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-984b766664241ce7", "level": "note", "message": {"text": "Very large file: wp-admin/js/customize-nav-menus.js (3556 lines)"}, "properties": {"repobilityId": "fa5eae508cb635f2", "scanner": "scanner-primary", "fingerprint": "984b766664241ce7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-7dd9b5c25464c103", "level": "note", "message": {"text": "Very large file: wp-admin/js/common.js (2598 lines)"}, "properties": {"repobilityId": "13200184aa153876", "scanner": "scanner-primary", "fingerprint": "7dd9b5c25464c103", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-154d49290a7f9ed5", "level": "note", "message": {"text": "Very large file: wp-admin/js/nav-menu.js (1906 lines)"}, "properties": {"repobilityId": "75190305256247eb", "scanner": "scanner-primary", "fingerprint": "154d49290a7f9ed5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-84324ecf5c2b3ede", "level": "note", "message": {"text": "Very large file: wp-admin/js/updates.js (3497 lines)"}, "properties": {"repobilityId": "ae9324bf0c782eec", "scanner": "scanner-primary", "fingerprint": "84324ecf5c2b3ede", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-48ea19041f52cec5", "level": "note", "message": {"text": "Very large file: wp-admin/js/theme.js (2176 lines)"}, "properties": {"repobilityId": "fe85bccd517cbefd", "scanner": "scanner-primary", "fingerprint": "48ea19041f52cec5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-9e48d38beba470c5", "level": "note", "message": {"text": "Very large file: wp-admin/js/customize-controls.js (9407 lines)"}, "properties": {"repobilityId": "2a87c84206958f20", "scanner": "scanner-primary", "fingerprint": "9e48d38beba470c5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-11c4e5de0bb60f32", "level": "note", "message": {"text": "Very large file: wp-includes/js/media-views.js (10656 lines)"}, "properties": {"repobilityId": "0999aa7d0b37720f", "scanner": "scanner-primary", "fingerprint": "11c4e5de0bb60f32", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6c88b471b5a94716", "level": "note", "message": {"text": "Very large file: wp-includes/js/backbone.js (2157 lines)"}, "properties": {"repobilityId": "056a21d2405b28a2", "scanner": "scanner-primary", "fingerprint": "6c88b471b5a94716", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-273af316330e3bfd", "level": "note", "message": {"text": "Very large file: wp-includes/js/underscore.js (2063 lines)"}, "properties": {"repobilityId": "53accafa1fd8c7ad", "scanner": "scanner-primary", "fingerprint": "273af316330e3bfd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-291e7f6d64768e0b", "level": "note", "message": {"text": "Very large file: wp-includes/js/jquery/jquery.js (10716 lines)"}, "properties": {"repobilityId": "3e0cc03d81e5323a", "scanner": "scanner-primary", "fingerprint": "291e7f6d64768e0b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-1f46bd7799532b2a", "level": "note", "message": {"text": "Very large file: wp-includes/js/jquery/ui/datepicker.js (2237 lines)"}, "properties": {"repobilityId": "d56f14865ca5c953", "scanner": "scanner-primary", "fingerprint": "1f46bd7799532b2a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-5075e62eed5e7f45", "level": "note", "message": {"text": "Very large file: wp-includes/js/plupload/plupload.js (2379 lines)"}, "properties": {"repobilityId": "9be74ace9ac87f51", "scanner": "scanner-primary", "fingerprint": "5075e62eed5e7f45", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-527eb2bfedd97681", "level": "note", "message": {"text": "Very large file: wp-includes/js/plupload/moxie.js (9904 lines)"}, "properties": {"repobilityId": "a7a683ae4c61f3a6", "scanner": "scanner-primary", "fingerprint": "527eb2bfedd97681", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-d862213295133636", "level": "note", "message": {"text": "Very large file: wp-includes/js/mediaelement/mediaelement.js (3984 lines)"}, "properties": {"repobilityId": "d6b20d8478ac42b9", "scanner": "scanner-primary", "fingerprint": "d862213295133636", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-956faf144bc88ff1", "level": "note", "message": {"text": "Very large file: wp-includes/js/mediaelement/mediaelement-and-player.js (8540 lines)"}, "properties": {"repobilityId": "436fa4585e84ce5f", "scanner": "scanner-primary", "fingerprint": "956faf144bc88ff1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-9fec8bb20f266df4", "level": "note", "message": {"text": "Very large file: wp-includes/js/codemirror/csslint.js (10858 lines)"}, "properties": {"repobilityId": "1ea4c36f94d54abb", "scanner": "scanner-primary", "fingerprint": "9fec8bb20f266df4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-a45a8e3f5a39fa46", "level": "note", "message": {"text": "Very large file: wp-includes/js/codemirror/esprima.js (6708 lines)"}, "properties": {"repobilityId": "68de7363ddd3c30d", "scanner": "scanner-primary", "fingerprint": "a45a8e3f5a39fa46", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-adf7402590ed4a47", "level": "note", "message": {"text": "Very large file: wp-includes/js/tinymce/themes/inlite/theme.js (9792 lines)"}, "properties": {"repobilityId": "d71b013e8114eba6", "scanner": "scanner-primary", "fingerprint": "adf7402590ed4a47", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-89c64cdb566c3c8c", "level": "note", "message": {"text": "Very large file: wp-includes/js/tinymce/themes/modern/theme.js (9607 lines)"}, "properties": {"repobilityId": "226cfd14cdac7adc", "scanner": "scanner-primary", "fingerprint": "89c64cdb566c3c8c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-dac7a020b936d02b", "level": "note", "message": {"text": "Very large file: wp-includes/js/tinymce/plugins/paste/plugin.js (2367 lines)"}, "properties": {"repobilityId": "d4dc2054ac8d2b37", "scanner": "scanner-primary", "fingerprint": "dac7a020b936d02b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3b21cdd2dff4c7c8", "level": "note", "message": {"text": "Very large file: wp-includes/js/tinymce/plugins/lists/plugin.js (2148 lines)"}, "properties": {"repobilityId": "0f9f21c00cde5181", "scanner": "scanner-primary", "fingerprint": "3b21cdd2dff4c7c8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-47d713c72673a90e", "level": "note", "message": {"text": "111 TODO/FIXME markers"}, "properties": {"repobilityId": "4b38c118003e07d2", "scanner": "scanner-primary", "fingerprint": "47d713c72673a90e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["maintenance"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "a2bd670e911c2e86", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "9126be2ae47a1f97", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "1ed06f38e1e0526d", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "b0de5955f09ac645", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-960af6733c429673", "level": "note", "message": {"text": "Legacy-named symbol `actions_copy` in wp-includes/js/clipboard.js:139"}, "properties": {"repobilityId": "beb3817808e2832a", "scanner": "scanner-primary", "fingerprint": "960af6733c429673", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-f9d818f9961e3e7c", "level": "none", "message": {"text": "Commented-code block (6 lines) in wp-includes/js/hoverIntent.js:133"}, "properties": {"repobilityId": "8f82d3ce2c5ec027", "scanner": "scanner-primary", "fingerprint": "f9d818f9961e3e7c", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-includes/js/hoverIntent.js"}, "region": {"startLine": 133}}}]}, {"ruleId": "scanner-9664ef11e6389900", "level": "note", "message": {"text": "Legacy-named symbol `pdataOld` in wp-includes/js/jquery/jquery.js:5819"}, "properties": {"repobilityId": "4609578180b367ec", "scanner": "scanner-primary", "fingerprint": "9664ef11e6389900", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-c5890d253d8ab46c", "level": "note", "message": {"text": "Legacy-named symbol `pg_end_copy` in wp-includes/js/codemirror/codemirror.min.js:11"}, "properties": {"repobilityId": "3e94746cfb1c9d75", "scanner": "scanner-primary", "fingerprint": "c5890d253d8ab46c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-d64eb5196032c730", "level": "error", "message": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q"}, "properties": {"repobilityId": "b8944461c8644339", "scanner": "scanner-primary", "fingerprint": "d64eb5196032c730", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6g55-p6wh-862q", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-58803bf97cd3b47a", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-fxqj-rqcc-2cmp"}, "properties": {"repobilityId": "1f793820cbec4a56", "scanner": "scanner-primary", "fingerprint": "58803bf97cd3b47a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fxqj-rqcc-2cmp", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b9db4b13e9ca2f79", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": "6c83605d3aa8fcef", "scanner": "scanner-primary", "fingerprint": "b9db4b13e9ca2f79", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-qx2v-qp2m-jg93", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9f15a37a28de7477", "level": "error", "message": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-r28c-9q8g-f849"}, "properties": {"repobilityId": "952a6afbc97e5c3e", "scanner": "scanner-primary", "fingerprint": "9f15a37a28de7477", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r28c-9q8g-f849", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1251bfaf32937934", "level": "note", "message": {"text": "Vulnerable dependency @tootallnate/once 2.0.0: GHSA-vpq2-c234-7xj6"}, "properties": {"repobilityId": "f9b1d757847fb290", "scanner": "scanner-primary", "fingerprint": "1251bfaf32937934", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-vpq2-c234-7xj6", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-53831c221a214668", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "5d2ce580505ef5a7", "scanner": "scanner-primary", "fingerprint": "53831c221a214668", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4ac29452ba3d0843", "level": "warning", "message": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v"}, "properties": {"repobilityId": "c4fa6cea7167ee7e", "scanner": "scanner-primary", "fingerprint": "4ac29452ba3d0843", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-f886-m6hf-6m8v", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-77cdbbacdb312aca", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-mh99-v99m-4gvg"}, "properties": {"repobilityId": "0fc24bfbdae70a7f", "scanner": "scanner-primary", "fingerprint": "77cdbbacdb312aca", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mh99-v99m-4gvg", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-06546c6990b7fcb5", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-rgw5-rvv9-x895"}, "properties": {"repobilityId": "3d617062bafcab77", "scanner": "scanner-primary", "fingerprint": "06546c6990b7fcb5", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-rgw5-rvv9-x895", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8441fbde3dfce5cc", "level": "error", "message": {"text": "Vulnerable dependency browserslist 4.28.0: GHSA-73wf-gq98-2v4g"}, "properties": {"repobilityId": "4f2d80dd45310d81", "scanner": "scanner-primary", "fingerprint": "8441fbde3dfce5cc", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-73wf-gq98-2v4g", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a350c219720a6fb0", "level": "error", "message": {"text": "Vulnerable dependency browserslist 4.28.0: GHSA-c83g-rgw3-j3cx"}, "properties": {"repobilityId": "c611e5a47b4fc7e1", "scanner": "scanner-primary", "fingerprint": "a350c219720a6fb0", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-c83g-rgw3-j3cx", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-26f6c4ae2d044c45", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 2.0.2: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "d0f259a88c45355f", "scanner": "scanner-primary", "fingerprint": "26f6c4ae2d044c45", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2c3dc9c4f3e82346", "level": "warning", "message": {"text": "Vulnerable dependency brace-expansion 2.0.2: GHSA-f886-m6hf-6m8v"}, "properties": {"repobilityId": "1154f43f37764268", "scanner": "scanner-primary", "fingerprint": "2c3dc9c4f3e82346", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-f886-m6hf-6m8v", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1e4d8698658a1a9d", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 2.0.2: GHSA-mh99-v99m-4gvg"}, "properties": {"repobilityId": "7d3e92999f8a85d7", "scanner": "scanner-primary", "fingerprint": "1e4d8698658a1a9d", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mh99-v99m-4gvg", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a36ad53d93ed1409", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 2.0.2: GHSA-rgw5-rvv9-x895"}, "properties": {"repobilityId": "fa64862e1c20cdaf", "scanner": "scanner-primary", "fingerprint": "a36ad53d93ed1409", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-rgw5-rvv9-x895", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d4777e90f1ac1fe7", "level": "error", "message": {"text": "Vulnerable dependency minimatch 5.1.6: GHSA-23c5-xmqv-rm74"}, "properties": {"repobilityId": "79c754df4fc4817a", "scanner": "scanner-primary", "fingerprint": "d4777e90f1ac1fe7", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-23c5-xmqv-rm74", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f55f97a9eeedbfde", "level": "error", "message": {"text": "Vulnerable dependency minimatch 5.1.6: GHSA-3ppc-4f35-3m26"}, "properties": {"repobilityId": "769b5efe286120d2", "scanner": "scanner-primary", "fingerprint": "f55f97a9eeedbfde", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3ppc-4f35-3m26", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-08ebd35bb0a901a9", "level": "error", "message": {"text": "Vulnerable dependency minimatch 5.1.6: GHSA-7r86-cg39-jmmj"}, "properties": {"repobilityId": "c1d2f27da8cb3fa9", "scanner": "scanner-primary", "fingerprint": "08ebd35bb0a901a9", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-7r86-cg39-jmmj", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d04cf937a1b9c1f3", "level": "error", "message": {"text": "Vulnerable dependency minimatch 3.1.2: GHSA-23c5-xmqv-rm74"}, "properties": {"repobilityId": "9f7f5897e94c3644", "scanner": "scanner-primary", "fingerprint": "d04cf937a1b9c1f3", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-23c5-xmqv-rm74", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9f480a4a342ebf1d", "level": "error", "message": {"text": "Vulnerable dependency minimatch 3.1.2: GHSA-3ppc-4f35-3m26"}, "properties": {"repobilityId": "1f348c9c38426ebf", "scanner": "scanner-primary", "fingerprint": "9f480a4a342ebf1d", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3ppc-4f35-3m26", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6cac3710355ac301", "level": "error", "message": {"text": "Vulnerable dependency minimatch 3.1.2: GHSA-7r86-cg39-jmmj"}, "properties": {"repobilityId": "20c31d31e282c8df", "scanner": "scanner-primary", "fingerprint": "6cac3710355ac301", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-7r86-cg39-jmmj", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c963864adf58023b", "level": "warning", "message": {"text": "Vulnerable dependency ip-address 9.0.5: GHSA-mwp4-54f8-5fhr"}, "properties": {"repobilityId": "3d654ce7f63e7cb2", "scanner": "scanner-primary", "fingerprint": "c963864adf58023b", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mwp4-54f8-5fhr", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5be8d563b6661d64", "level": "warning", "message": {"text": "Vulnerable dependency ip-address 9.0.5: GHSA-v2v4-37r5-5v8g"}, "properties": {"repobilityId": "801c64e558760268", "scanner": "scanner-primary", "fingerprint": "5be8d563b6661d64", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v2v4-37r5-5v8g", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ba0724a70b545741", "level": "warning", "message": {"text": "Vulnerable dependency lodash 4.17.21: GHSA-f23m-r3pf-42rh"}, "properties": {"repobilityId": "cc4bf4eecb219236", "scanner": "scanner-primary", "fingerprint": "ba0724a70b545741", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-f23m-r3pf-42rh", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f35831884e62775b", "level": "warning", "message": {"text": "Vulnerable dependency lodash 4.17.21: GHSA-r5fr-rjxr-66jc"}, "properties": {"repobilityId": "2b726702cde61827", "scanner": "scanner-primary", "fingerprint": "f35831884e62775b", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r5fr-rjxr-66jc", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b0d973210c14481d", "level": "error", "message": {"text": "Vulnerable dependency minimatch 3.0.8: GHSA-23c5-xmqv-rm74"}, "properties": {"repobilityId": "5088e306f1e87f2d", "scanner": "scanner-primary", "fingerprint": "b0d973210c14481d", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-23c5-xmqv-rm74", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1f1ec5157283b5f5", "level": "error", "message": {"text": "Vulnerable dependency minimatch 3.0.8: GHSA-3ppc-4f35-3m26"}, "properties": {"repobilityId": "ca4d91db3c14518e", "scanner": "scanner-primary", "fingerprint": "1f1ec5157283b5f5", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3ppc-4f35-3m26", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ab6ce85b3ab6578d", "level": "error", "message": {"text": "Vulnerable dependency minimatch 3.0.8: GHSA-7r86-cg39-jmmj"}, "properties": {"repobilityId": "b488260753351f09", "scanner": "scanner-primary", "fingerprint": "ab6ce85b3ab6578d", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-7r86-cg39-jmmj", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b6a9736f4cb7abd7", "level": "error", "message": {"text": "Vulnerable dependency nanoid 3.3.11: GHSA-28wg-ghj8-5hjv"}, "properties": {"repobilityId": "a28fc942b5b14d8c", "scanner": "scanner-primary", "fingerprint": "b6a9736f4cb7abd7", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-28wg-ghj8-5hjv", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-42e87a360f2f6fb9", "level": "error", "message": {"text": "Vulnerable dependency nanoid 3.3.11: GHSA-2v37-7h3g-55p8"}, "properties": {"repobilityId": "b8c23ab323f99001", "scanner": "scanner-primary", "fingerprint": "42e87a360f2f6fb9", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-2v37-7h3g-55p8", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4a5b852867a91fda", "level": "warning", "message": {"text": "Vulnerable dependency nanoid 3.3.11: GHSA-xwg4-73v4-xw9w"}, "properties": {"repobilityId": "d10186191bb440f8", "scanner": "scanner-primary", "fingerprint": "4a5b852867a91fda", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-xwg4-73v4-xw9w", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-886c0ccc7bac38cc", "level": "note", "message": {"text": "Vulnerable dependency @tootallnate/once 1.1.2: GHSA-vpq2-c234-7xj6"}, "properties": {"repobilityId": "dde2d5815aec1ff8", "scanner": "scanner-primary", "fingerprint": "886c0ccc7bac38cc", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-vpq2-c234-7xj6", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7daf56731b132095", "level": "warning", "message": {"text": "Vulnerable dependency picomatch 2.3.1: GHSA-3v7f-55p6-f55p"}, "properties": {"repobilityId": "a2746cb9d8be4794", "scanner": "scanner-primary", "fingerprint": "7daf56731b132095", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3v7f-55p6-f55p", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f498ead34397886e", "level": "error", "message": {"text": "Vulnerable dependency picomatch 2.3.1: GHSA-c2c7-rcm5-vvqj"}, "properties": {"repobilityId": "676e59b75389f27b", "scanner": "scanner-primary", "fingerprint": "f498ead34397886e", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-c2c7-rcm5-vvqj", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f0fbbf31dcbdf2d", "level": "error", "message": {"text": "Vulnerable dependency shell-quote 1.7.3: GHSA-395f-4hp3-45gv"}, "properties": {"repobilityId": "70658a593e59d847", "scanner": "scanner-primary", "fingerprint": "5f0fbbf31dcbdf2d", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-395f-4hp3-45gv", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b3bf19a91b3e301d", "level": "warning", "message": {"text": "Vulnerable dependency shell-quote 1.7.3: GHSA-w7jw-789q-3m8p"}, "properties": {"repobilityId": "e3fa34da17efc179", "scanner": "scanner-primary", "fingerprint": "b3bf19a91b3e301d", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-w7jw-789q-3m8p", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f390f3f5d86bd30c", "level": "error", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-23hp-3jrh-7fpw"}, "properties": {"repobilityId": "2b31f5b015f63b19", "scanner": "scanner-primary", "fingerprint": "f390f3f5d86bd30c", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-23hp-3jrh-7fpw", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-49a64695ab27ffc8", "level": "error", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-34x7-hfp2-rc4v"}, "properties": {"repobilityId": "6278a266c23d1504", "scanner": "scanner-primary", "fingerprint": "49a64695ab27ffc8", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-34x7-hfp2-rc4v", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-07d0ecdfa4948e5b", "level": "error", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-83g3-92jg-28cx"}, "properties": {"repobilityId": "de5b704a7f8378d1", "scanner": "scanner-primary", "fingerprint": "07d0ecdfa4948e5b", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-83g3-92jg-28cx", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-290b753c48a04c6a", "level": "error", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-8qq5-rm4j-mr97"}, "properties": {"repobilityId": "f87ce42440b8ea48", "scanner": "scanner-primary", "fingerprint": "290b753c48a04c6a", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-8qq5-rm4j-mr97", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2e08f06d3a917f54", "level": "error", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-8x88-c5mf-7j5w"}, "properties": {"repobilityId": "a97460913e322b17", "scanner": "scanner-primary", "fingerprint": "2e08f06d3a917f54", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-8x88-c5mf-7j5w", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-62991adc9495b1df", "level": "error", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-9ppj-qmqm-q256"}, "properties": {"repobilityId": "ba7848efc0447c3d", "scanner": "scanner-primary", "fingerprint": "62991adc9495b1df", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-9ppj-qmqm-q256", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e06177827de95006", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-gvwx-54wh-qm9j"}, "properties": {"repobilityId": "af4ef3e7bc207515", "scanner": "scanner-primary", "fingerprint": "e06177827de95006", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-gvwx-54wh-qm9j", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e65104fd1bc5287f", "level": "error", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-qffp-2rhf-9h96"}, "properties": {"repobilityId": "2cc0d011c816508c", "scanner": "scanner-primary", "fingerprint": "e65104fd1bc5287f", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-qffp-2rhf-9h96", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7844c29a6a6e19b6", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-r292-9mhp-454m"}, "properties": {"repobilityId": "4f27b729ab5c153f", "scanner": "scanner-primary", "fingerprint": "7844c29a6a6e19b6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r292-9mhp-454m", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d7e7fe188951d172", "level": "error", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-r6q2-hw4h-h46w"}, "properties": {"repobilityId": "9d2e042e0c9a08f0", "scanner": "scanner-primary", "fingerprint": "d7e7fe188951d172", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r6q2-hw4h-h46w", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f071e338471d4df1", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-vmf3-w455-68vh"}, "properties": {"repobilityId": "120517fd80ea2fcd", "scanner": "scanner-primary", "fingerprint": "f071e338471d4df1", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-vmf3-w455-68vh", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-227e71c32e7eb052", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-w8wr-v893-vjvp"}, "properties": {"repobilityId": "7b9b54b883d7996a", "scanner": "scanner-primary", "fingerprint": "227e71c32e7eb052", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-w8wr-v893-vjvp", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7f3f59f8c6c6f9eb", "level": "warning", "message": {"text": "Vulnerable dependency picomatch 4.0.3: GHSA-3v7f-55p6-f55p"}, "properties": {"repobilityId": "7c1f64a4b9d5ab32", "scanner": "scanner-primary", "fingerprint": "7f3f59f8c6c6f9eb", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3v7f-55p6-f55p", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-75ce9751dd210b1a", "level": "error", "message": {"text": "Vulnerable dependency picomatch 4.0.3: GHSA-c2c7-rcm5-vvqj"}, "properties": {"repobilityId": "75ae39eb60c1525e", "scanner": "scanner-primary", "fingerprint": "75ce9751dd210b1a", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-c2c7-rcm5-vvqj", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ff904d525b7c4280", "level": "warning", "message": {"text": "Vulnerable dependency yaml 2.3.4: GHSA-48c2-rrv3-qjmp"}, "properties": {"repobilityId": "efd4b4a473a2e4e7", "scanner": "scanner-primary", "fingerprint": "ff904d525b7c4280", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-48c2-rrv3-qjmp", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentynineteen/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0aa99309d057fc19", "level": "note", "message": {"text": "Vulnerable dependency @babel/core 7.25.7: GHSA-4x5r-pxfx-6jf8"}, "properties": {"repobilityId": "6025b1704a283b06", "scanner": "scanner-primary", "fingerprint": "0aa99309d057fc19", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4x5r-pxfx-6jf8", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentytwenty/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cb5d0c0545527de0", "level": "error", "message": {"text": "Vulnerable dependency @babel/plugin-transform-modules-systemjs 7.28.5: GHSA-fv7c-fp4j-7gwp"}, "properties": {"repobilityId": "cd4e9e10c1584e84", "scanner": "scanner-primary", "fingerprint": "cb5d0c0545527de0", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fv7c-fp4j-7gwp", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentytwenty/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c63f94090e16d9f6", "level": "error", "message": {"text": "Vulnerable dependency js-yaml 4.1.0: GHSA-52cp-r559-cp3m"}, "properties": {"repobilityId": "2295971a92c54b9e", "scanner": "scanner-primary", "fingerprint": "c63f94090e16d9f6", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-52cp-r559-cp3m", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentytwenty/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b68ea3a3f939cc4", "level": "error", "message": {"text": "Vulnerable dependency js-yaml 4.1.0: GHSA-5p4m-2wfm-xmqj"}, "properties": {"repobilityId": "fde71304366222c8", "scanner": "scanner-primary", "fingerprint": "7b68ea3a3f939cc4", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-5p4m-2wfm-xmqj", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentytwenty/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e861b5906df28ef8", "level": "warning", "message": {"text": "Vulnerable dependency js-yaml 4.1.0: GHSA-h67p-54hq-rp68"}, "properties": {"repobilityId": "950027314cda83d8", "scanner": "scanner-primary", "fingerprint": "e861b5906df28ef8", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-h67p-54hq-rp68", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentytwenty/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6f135cbd72617edb", "level": "warning", "message": {"text": "Vulnerable dependency js-yaml 4.1.0: GHSA-mh29-5h37-fv8m"}, "properties": {"repobilityId": "3860211bb978525c", "scanner": "scanner-primary", "fingerprint": "6f135cbd72617edb", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mh29-5h37-fv8m", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wp-content/themes/twentytwenty/package-lock.json"}, "region": {"startLine": 1}}}]}]}]}