Clear licensing and a complete package make adoption straightforward. A missing security policy and single-contributor activity leave some maintenance and continuity risk.
76%
Total Score
67
100
88
83
The repository is owned by an individual account rather than an organization, so the single-contributor concentration is not offset by visible organization backing.
All 385 recent commits came from one contributor, johnpbloch-bot, leaving a significant continuity risk despite the high activity level.
The repository name matches the package, reducing identity concern, but the README does not mention the package explicitly; this is a minor provenance caution.
Composer is used as a build tool, but no security-scanning tools were detected, leaving a security-process gap.
The repository has no security policy, which reduces transparency about vulnerability reporting and maintenance response.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-180761 New johnpbloch/wordpress-core is vulnerable to Cross-Site Scripting (XSS) in versions 7.1.0 - 7.1.0, 7.0.0 - 7.0.4, 6.9.0 - 6.9.7, 6.8.0 - 6.8.8, 6.7.0 - 6.7.7, 6.6.0 - 6.6.7, 6.5.0 - 6.5.10, 6.4.0 - 6.4.10, 6.3.0 - 6.3.10, 6.2.0 - 6.2.11, 6.1.0 - 6.1.12, 6.0.0 - 6.0.14, 5.9.0 - 5.9.16, 5.8.0 - 5.8.15, 5.7.0 - 5.7.17, 5.6.0 - 5.6.19, 5.5.0 - 5.5.20, 5.4.0 - 5.4.21, 5.3.0 - 5.3.23, 5.2.0 - 5.2.26, 5.1.0 - 5.1.24, 5.0.0 - 5.0.27, 4.9.0 - 4.9.31, 4.8.0 - 4.8.30 and 4.7.0 - 4.7.35. | 4.7.0 - 4.7.354.8.0 - 4.8.304.9.0 - 4.9.31 +22 more | High |
AIKIDO-2026-594951 johnpbloch/wordpress-core is vulnerable to Remote Code Execution (RCE) in versions 7.0.0 - 7.0.3, 6.9.0 - 6.9.6, 6.8.0 - 6.8.7, 6.7.0 - 6.7.6, 6.6.0 - 6.6.6, 6.5.0 - 6.5.9, 6.4.0 - 6.4.9, 6.3.0 - 6.3.9, 6.2.0 - 6.2.10, 6.1.0 - 6.1.11, 6.0.0 - 6.0.13, 5.9.0 - 5.9.15, 5.8.0 - 5.8.14, 5.7.0 - 5.7.16, 5.6.0 - 5.6.18, 5.5.0 - 5.5.19, 5.4.0 - 5.4.20, 5.3.0 - 5.3.22, 5.2.0 - 5.2.25, 5.1.0 - 5.1.23, 5.0.0 - 5.0.26, 4.9.0 - 4.9.30, 4.8.0 - 4.8.29 and 4.7.0 - 4.7.34. | 4.7.0 - 4.7.344.8.0 - 4.8.294.9.0 - 4.9.30 +21 more | High |
AIKIDO-2026-590188 johnpbloch/wordpress-core is vulnerable to Cross-Site Scripting (XSS) in versions 7.0.0 - 7.0.2, 6.9.0 - 6.9.5, 6.8.0 - 6.8.6, 6.7.0 - 6.7.5, 6.6.0 - 6.6.5, 6.5.0 - 6.5.8, 6.4.0 - 6.4.8, 6.3.0 - 6.3.8, 6.2.0 - 6.2.9, 6.1.0 - 6.1.10, 6.0.0 - 6.0.12, 5.9.0 - 5.9.13, 5.8.0 - 5.8.13, 5.7.0 - 5.7.15, 5.6.0 - 5.6.17, 5.5.0 - 5.5.18, 5.4.0 - 5.4.19, 5.3.0 - 5.3.21, 5.2.0 - 5.2.24, 5.1.0 - 5.1.22, 5.0.0 - 5.0.25, 4.9.0 - 4.9.29, 4.8.0 - 4.8.28 and 3.7.38 - 4.7.33. | 3.7.38 - 4.7.334.8.0 - 4.8.284.9.0 - 4.9.29 +21 more | High |
AIKIDO-2026-362570 johnpbloch/wordpress-core is vulnerable to SQL Injection in versions 6.8.0 - 6.8.5, 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1. | 6.8.0 - 6.8.56.9.0 - 6.9.47.0.0 - 7.0.1 | High |
AIKIDO-2026-696183 johnpbloch/wordpress-core is vulnerable to Remote Code Execution (RCE) in versions 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1. | 6.9.0 - 6.9.47.0.0 - 7.0.1 | Critical |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.