Skip to content

fix: correct the External services disclosure (#228) - #234

Merged
pluginslab merged 1 commit into
mainfrom
fix/228-external-services-accuracy
Aug 27, 2026
Merged

pluginslab merged 1 commit into
mainfrom
fix/228-external-services-accuracy

Conversation

@pluginslab

Copy link
Copy Markdown
Owner

Readme only, no code change. Found while auditing before resubmission.

The External services section is the part of the readme under Guideline 6 review, and it described things the code does not do.

Problem Reality
CVE lookups attributed to a plugin-vulnerability-scan ability That ability does not exist. NVD and MITRE are called by security-scan, unconditionally (security-scan.php:149)
core.svn.wordpress.org not mentioned at all verify-core-checksums.php:273 fetches the original core file to build a diff when a checksum mismatches
"No admin data ever leaves your device" Contradicted by the section's own list three paragraphs below, which discloses plugin names going to NVD and queries going to DuckDuckGo
Changelog credits sw-loader.php work That file was removed in the same release by #227

Reworded so AI inference (genuinely local) is separated from the public-data lookups a few abilities make.

Verified: every host in the code is now disclosed, and every ability named in the section exists.

Merge order does not matter versus #231, they touch different parts of the file. The dist zip needs rebuilding after both land.

Part of #228.

Audit before resubmission found the External services section describing
something the code does not do. Guideline 6 is the section under review,
so the disclosure has to match reality.

- CVE lookups were attributed to a `plugin-vulnerability-scan` ability
  that does not exist anywhere in the codebase. NVD and MITRE are called
  by `security-scan`, unconditionally, via
  agentic_admin_scan_for_vulnerabilities() at security-scan.php:149.
- `core.svn.wordpress.org` was undisclosed. verify-core-checksums.php:273
  fetches the original core file to build a diff when a checksum
  mismatches. Now documented, including that the checksum list itself
  comes from core's own get_core_checksums().
- Two absolute claims ("No admin data ever leaves your device", "no
  admin data are sent to any server unless you enable the external LLM
  provider") were contradicted by the section's own list a few
  paragraphs below. Reworded to separate AI inference, which really is
  local, from the public-data lookups a few abilities make.
- Dropped a changelog reference to sw-loader.php, removed in the same
  release by #227.

Verified: every host the code contacts is now disclosed, and every
ability named in the section exists.

Readme only, no code change.

Refs #228

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@pluginslab
pluginslab requested a review from ivdimova August 23, 2026 16:16

@ivdimova ivdimova left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified every claim against the code, not just the description:

  • plugin-vulnerability-scan ability genuinely does not exist (grep of includes/ + src/ is empty) — correctly reattributed to security-scan, whose NVD/MITRE calls live in plugin-helpers.php (services.nvd.nist.gov, cveawg.mitre.org).
  • The newly disclosed core.svn.wordpress.org fetch is real (verify-core-checksums.php:273) and was previously undisclosed.
  • The strong new claim 'every external request is listed here' holds: every runtime host in the code (jsdelivr Transformers.js CDN, huggingface/raw.githubusercontent weights, DuckDuckGo, downloads/plugins/core .svn.wordpress.org, NVD, MITRE) appears in the section. The only code hosts not listed (caniuse, developer.chrome, webgpureport) are UI hyperlinks in WebGPUFallback.jsx — user-clicked navigation, not plugin-initiated requests — correctly excluded.
  • Changelog fix is right: sw-loader.php was removed (#227), so dropping the #123 credit is accurate.
  • The reworded Privacy-First line no longer contradicts its own External services list.

Readme-only, CI green. LGTM.

@pluginslab
pluginslab merged commit 5614594 into main Aug 27, 2026
4 checks passed
@pluginslab
pluginslab deleted the fix/228-external-services-accuracy branch August 27, 2026 17:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants