https://github.com/wordpress/wordpress
· scanned 2026-05-20 14:54 UTC (2 weeks, 1 day ago)
· 10 languages
360 findings (30 legacy + 330 scanner) 11/13 scanners ran Scanner says 73 (lower by 23)
Last scanned 2 weeks, 1 day ago · v2 · 195 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
0.0 | 0.20 | 0.00 |
documentation_score |
68.0 | 0.15 | 10.20 |
practices_score |
30.0 | 0.15 | 4.50 |
code_quality |
50.0 | 0.10 | 5.00 |
| Overall | 1.00 | 50.7 |
Showing 147 of 195 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
wp-admin/js/auth-app.js:84
secrets
wp-admin/js/auth-app.min.js:2
secrets
wp-admin/includes/import.php:140
qualitylegacy
wp-admin/js/tags-suggest.js:14
qualitylegacy
wp-admin/js/tags-box.js:65
qualitylegacy
wp-includes/js/jquery/jquery.form.min.js:1
owaspeval_used
wp-includes/js/jquery/jquery.schedule.js:30
owaspeval_used
wp-includes/js/tinymce/tiny_mce_popup.js:192
owaspeval_used
wp-includes/js/tw-sack.js:119
owaspeval_used
wp-admin/js/privacy-tools.js:91
open_redirectlegacy
wp-includes:1
qualitylegacy
wp-admin:1
qualitylegacy
wp-includes/js/mediaelement/mediaelement-and-player.min.js:12
owaspcors_wildcard
wp-includes/js/mediaelement/mediaelement.min.js:12
owaspcors_wildcard
wp-includes/js/plupload/moxie.min.js:1
owaspcors_wildcard
wp-includes/js/tinymce/tinymce.min.js:2
owaspcors_wildcard
wp-includes/js/tinymce/wp-tinymce.js:3
owaspcors_wildcard
wp-admin/js/media-gallery.js:23
qualitylegacy
wp-admin/js/link.js:82
qualitylegacy
wp-admin/js/application-passwords.js:50
qualitylegacy
wp-content/themes/twentysixteen/index.php:1
qualitylegacy
wp-includes/js/tinymce/tiny_mce_popup.js:237
owaspdocument_write
wp-includes/js/tinymce/tinymce.min.js:2
owaspdocument_write
wp-includes/js/tinymce/wp-tinymce.js:3
owaspdocument_write
wp-admin/includes/credits.php:35
qualitylegacy
wp-admin/includes/class-wp-importer.php:151
qualitylegacy
wp-activate.php:159
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/d9dc5cbb-cc4d-4a84-828d-f7c23a11ff2a/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/d9dc5cbb-cc4d-4a84-828d-f7c23a11ff2a/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.