Repository navigation
fix: correct the External services disclosure (#228) - #234
Merged
Merged
Conversation
Audit before resubmission found the External services section describing
something the code does not do. Guideline 6 is the section under review,
so the disclosure has to match reality.
- CVE lookups were attributed to a `plugin-vulnerability-scan` ability
that does not exist anywhere in the codebase. NVD and MITRE are called
by `security-scan`, unconditionally, via
agentic_admin_scan_for_vulnerabilities() at security-scan.php:149.
- `core.svn.wordpress.org` was undisclosed. verify-core-checksums.php:273
fetches the original core file to build a diff when a checksum
mismatches. Now documented, including that the checksum list itself
comes from core's own get_core_checksums().
- Two absolute claims ("No admin data ever leaves your device", "no
admin data are sent to any server unless you enable the external LLM
provider") were contradicted by the section's own list a few
paragraphs below. Reworded to separate AI inference, which really is
local, from the public-data lookups a few abilities make.
- Dropped a changelog reference to sw-loader.php, removed in the same
release by #227.
Verified: every host the code contacts is now disclosed, and every
ability named in the section exists.
Readme only, no code change.
Refs #228
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
ivdimova
approved these changes
Aug 25, 2026
ivdimova
left a comment
Collaborator
There was a problem hiding this comment.
Verified every claim against the code, not just the description:
plugin-vulnerability-scanability genuinely does not exist (grep of includes/ + src/ is empty) — correctly reattributed tosecurity-scan, whose NVD/MITRE calls live in plugin-helpers.php (services.nvd.nist.gov, cveawg.mitre.org).- The newly disclosed
core.svn.wordpress.orgfetch is real (verify-core-checksums.php:273) and was previously undisclosed. - The strong new claim 'every external request is listed here' holds: every runtime host in the code (jsdelivr Transformers.js CDN, huggingface/raw.githubusercontent weights, DuckDuckGo, downloads/plugins/core .svn.wordpress.org, NVD, MITRE) appears in the section. The only code hosts not listed (caniuse, developer.chrome, webgpureport) are UI hyperlinks in WebGPUFallback.jsx — user-clicked navigation, not plugin-initiated requests — correctly excluded.
- Changelog fix is right: sw-loader.php was removed (#227), so dropping the #123 credit is accurate.
- The reworded Privacy-First line no longer contradicts its own External services list.
Readme-only, CI green. LGTM.
8 of 14 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Readme only, no code change. Found while auditing before resubmission.
The External services section is the part of the readme under Guideline 6 review, and it described things the code does not do.
plugin-vulnerability-scanabilitysecurity-scan, unconditionally (security-scan.php:149)core.svn.wordpress.orgnot mentioned at allverify-core-checksums.php:273fetches the original core file to build a diff when a checksum mismatchessw-loader.phpworkReworded so AI inference (genuinely local) is separated from the public-data lookups a few abilities make.
Verified: every host in the code is now disclosed, and every ability named in the section exists.
Merge order does not matter versus #231, they touch different parts of the file. The dist zip needs rebuilding after both land.
Part of #228.