{"repo":"typisttech/wpsecadv","free":true,"listed":false,"github":"https://github.com/typisttech/wpsecadv","clone":"git clone https://github.com/typisttech/wpsecadv.git","description":"Composer repository for WordPress security advisories.","language":"Go","stars":24,"topics":["composer","wordpress","vulnerability"],"license":"MIT","category":"security-tools","readme_excerpt":"WP Sec Adv Composer repository for WordPress security advisories. Built with ♥ by Typist Tech --- [!TIP] Hire Tang Rufus! I am looking for my next role, freelance or full-time. If you find this tool useful, I can build you more weird stuff like this. Let's talk if you are hiring PHP / Ruby / Go developers. Contact me at https://typist.tech/contact/ --- Quick Start It generates audit report like this: Command \"repo\" is not defined. The composer repo subcommand is added since Composer v2.9.0. If you are using an older Composer version, manually append it to your composer.json : Tutorial First, create a fresh Bedrock project and cd into it: Install some vulnerabilities: Add WP Sec Adv: Checks for security vulnerability advisories for installed packages: Full console output The best course of action is to update packages to patched versions. Update the Twenty Fifteen theme: Full console output However, there may not be a patch yet or never will be (as the two WordPress core CVEs). [!WARNING] Blindly ignoring packages from security blocking is dangerous . You should do so only in exceptional cases. Ignore roots/wordpress-no-content from auditing, edit composer.json : When installing packages with known vulnerabilities, Composer resolver blocks them and fails composer update require . Install a vulnerable WooCommerce version: Full console output Unfortunately, a WooCommerce add-on compatibility issue forces us to stay with WooCommerce v10.5.0. To disable security blocking during in","default_branch":null,"files":null,"tree":[],"storefront":"/r/typisttech","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/typisttech/wpsecadv/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}