@wp-playground/wordpress
WordPress-related plumbing for WordPress Playground
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:zstddec-stream.modern-C2FJ34ZP.js | AI (source-diff): Bundled WASM decoder lib, minified not obfuscated; base64 is embedded wasm binary. | ai | |
| source-diff | obfuscated-file:zstddec-stream.modern-D_CFiovn.cjs | AI (source-diff): Same file, cjs build; benign bundled WASM decoder. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): base64 decode of embedded wasm binary, standard for wasm-in-JS bundling. | ai | |
| phantom-deps | phantom-dep:zstddec | AI (phantom-deps): Used indirectly via bundled wasm wrapper, not a direct import. | ai | |
| source-diff | obfuscated-file:legacy-wp/mysql-shims.d.ts | AI (source-diff): Long line is a PHP string literal in a .d.ts declaration file; not obfuscated code. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Official WordPress Playground project; team growth is expected and consistent with the open-source org. | ai | |
| provenance | publisher-changed | AI (provenance): Package is published via GitHub Actions CI/CD from the official WordPress/wordpress-playground repo with SLSA attestation; automated publisher is expected. | ai | |
| phantom-deps | phantom-dep:wasm-feature-detect | AI (phantom-deps): Same monorepo bundling pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): Monorepo package; deps declared for bundling/re-export, not direct import in this sub-package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Legitimate monorepo sub-package; sparse README is expected for internal plumbing packages. | ai | |
| phantom-deps | phantom-dep:fs-ext-extra-prebuilt | AI (phantom-deps): Platform-specific prebuilt binary dep; expected pattern for this package. | ai | |
| phantom-deps | phantom-dep:ini | AI (phantom-deps): Same monorepo bundling pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): Same monorepo bundling pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:express | AI (phantom-deps): Same monorepo bundling pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:jsonc-parser | AI (phantom-deps): Same monorepo bundling pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@php-wasm/node | AI (phantom-deps): Platform-specific binary sibling package in same monorepo; expected pattern. | ai | |
| phantom-deps | phantom-dep:fast-xml-parser | AI (phantom-deps): Same monorepo bundling pattern; stable false positive. | ai |
Versions (showing 51 of 80)
| Version | Deps | Published |
|---|---|---|
| 3.1.47 | 5 / 0 | |
| 3.1.46 | 5 / 0 | |
| 3.1.45 | 5 / 0 | |
| 3.1.44 | 4 / 0 | |
| 3.1.43 | 4 / 0 | |
| 3.1.42 | 4 / 0 | |
| 3.1.41 | 4 / 0 | |
| 3.1.40 | 4 / 0 | |
| 3.1.39 | 4 / 0 | |
| 3.1.38 | 4 / 0 | |
| 3.1.36 | 4 / 0 | |
| 3.1.35 | 4 / 0 | |
| 3.1.34 | 4 / 0 | |
| 3.1.33 | 4 / 0 | |
| 3.1.32 | 4 / 0 | |
| 3.1.31 | 4 / 0 | |
| 3.1.30 | 4 / 0 | |
| 3.1.29 | 4 / 0 | |
| 3.1.28 | 15 / 0 | |
| 3.1.27 | 15 / 0 | |
| 3.1.26 | 15 / 0 | |
| 3.1.25 | 14 / 0 | |
| 3.1.22 | 14 / 0 | |
| 3.1.21 | 13 / 0 | |
| 3.1.20 | 13 / 0 | |
| 3.1.19 | 13 / 0 | |
| 3.1.18 | 13 / 0 | |
| 3.1.16 | 13 / 0 | |
| 3.1.15 | 13 / 0 | |
| 3.1.14 | 13 / 0 | |
| 3.1.13 | 13 / 0 | |
| 3.1.12 | 13 / 0 | |
| 3.1.11 | 13 / 0 | |
| 3.1.10 | 13 / 0 | |
| 3.1.9 | 13 / 0 | |
| 3.1.8 | 13 / 0 | |
| 3.1.5 | 13 / 0 | |
| 3.1.4 | 13 / 0 | |
| 3.1.3 | 13 / 0 | |
| 3.1.2 | 11 / 0 | |
| 3.1.1 | 11 / 0 | |
| 3.1.0 | 11 / 0 | |
| 3.0.54 | 10 / 0 | |
| 3.0.53 | 10 / 0 | |
| 3.0.52 | 10 / 0 | |
| 3.0.51 | 10 / 0 | |
| 3.0.46 | 10 / 0 | |
| 3.0.45 | 10 / 0 | |
| 3.0.44 | 10 / 0 | |
| 3.0.43 | 10 / 0 | |
| 3.0.42 | 10 / 0 |
v3.1.47
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.45
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.