← Home

@wp-playground/wordpress

WordPress-related plumbing for WordPress Playground

51
Versions
GPL-2.0-or-later
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

bgrgicakadamzielbrandonpayton-a8csejasdanielbachhuberyannickdecatjanjakesakirk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:zstddec-stream.modern-C2FJ34ZP.js AI (source-diff): Bundled WASM decoder lib, minified not obfuscated; base64 is embedded wasm binary. ai
source-diff obfuscated-file:zstddec-stream.modern-D_CFiovn.cjs AI (source-diff): Same file, cjs build; benign bundled WASM decoder. ai
semgrep semgrep:base64-decode AI (semgrep): base64 decode of embedded wasm binary, standard for wasm-in-JS bundling. ai
phantom-deps phantom-dep:zstddec AI (phantom-deps): Used indirectly via bundled wasm wrapper, not a direct import. ai
source-diff obfuscated-file:legacy-wp/mysql-shims.d.ts AI (source-diff): Long line is a PHP string literal in a .d.ts declaration file; not obfuscated code. ai
maintainer-change maintainer-added AI (maintainer-change): Official WordPress Playground project; team growth is expected and consistent with the open-source org. ai
provenance publisher-changed AI (provenance): Package is published via GitHub Actions CI/CD from the official WordPress/wordpress-playground repo with SLSA attestation; automated publisher is expected. ai
phantom-deps phantom-dep:wasm-feature-detect AI (phantom-deps): Same monorepo bundling pattern; stable false positive. ai
phantom-deps phantom-dep:ws AI (phantom-deps): Monorepo package; deps declared for bundling/re-export, not direct import in this sub-package. ai
bogus-package bogus-package AI (bogus-package): Legitimate monorepo sub-package; sparse README is expected for internal plumbing packages. ai
phantom-deps phantom-dep:fs-ext-extra-prebuilt AI (phantom-deps): Platform-specific prebuilt binary dep; expected pattern for this package. ai
phantom-deps phantom-dep:ini AI (phantom-deps): Same monorepo bundling pattern; stable false positive. ai
phantom-deps phantom-dep:yargs AI (phantom-deps): Same monorepo bundling pattern; stable false positive. ai
phantom-deps phantom-dep:express AI (phantom-deps): Same monorepo bundling pattern; stable false positive. ai
phantom-deps phantom-dep:jsonc-parser AI (phantom-deps): Same monorepo bundling pattern; stable false positive. ai
phantom-deps phantom-dep:@php-wasm/node AI (phantom-deps): Platform-specific binary sibling package in same monorepo; expected pattern. ai
phantom-deps phantom-dep:fast-xml-parser AI (phantom-deps): Same monorepo bundling pattern; stable false positive. ai

Versions (showing 51 of 80)

View all versions
Version Deps Published
3.1.47 5 / 0
3.1.46 5 / 0
3.1.45 5 / 0
3.1.44 4 / 0
3.1.43 4 / 0
3.1.42 4 / 0
3.1.41 4 / 0
3.1.40 4 / 0
3.1.39 4 / 0
3.1.38 4 / 0
3.1.36 4 / 0
3.1.35 4 / 0
3.1.34 4 / 0
3.1.33 4 / 0
3.1.32 4 / 0
3.1.31 4 / 0
3.1.30 4 / 0
3.1.29 4 / 0
3.1.28 15 / 0
3.1.27 15 / 0
3.1.26 15 / 0
3.1.25 14 / 0
3.1.22 14 / 0
3.1.21 13 / 0
3.1.20 13 / 0
3.1.19 13 / 0
3.1.18 13 / 0
3.1.16 13 / 0
3.1.15 13 / 0
3.1.14 13 / 0
3.1.13 13 / 0
3.1.12 13 / 0
3.1.11 13 / 0
3.1.10 13 / 0
3.1.9 13 / 0
3.1.8 13 / 0
3.1.5 13 / 0
3.1.4 13 / 0
3.1.3 13 / 0
3.1.2 11 / 0
3.1.1 11 / 0
3.1.0 11 / 0
3.0.54 10 / 0
3.0.53 10 / 0
3.0.52 10 / 0
3.0.51 10 / 0
3.0.46 10 / 0
3.0.45 10 / 0
3.0.44 10 / 0
3.0.43 10 / 0
3.0.42 10 / 0

v3.1.47

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.46

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.45

3 findings
HIGH New obfuscated file: zstddec-stream.modern-C2FJ34ZP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: zstddec-stream.modern-D_CFiovn.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.