wp-taint-scan. Go static taint-analysis engine that finds vulnerabilities in WordPress plugins — WordPress-aware (capability tiers, nonce≠authz, REST/AJAX entrypoints). Detects SQLi, XSS, IDOR, privesc, RCE. Built on php-parser-go.

github.com/dimasma0305/wp-taint-scan

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.