| 开发者 |
digitalkind
airworthywp |
|---|---|
| 更新时间 | 2026年10月4日 05:56 |
| PHP版本: | 7.2 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
wp airworthy scan --target=8.4 checks every plugin and theme and prints the results. Add --wporg to include the WordPress.org checks.wp airworthy scan --only=my-plugin --fail-on=blocker exits with code 1 if anything would break, for CI.wp airworthy results --verdict=blocker,unknown shows what needs attention.wp airworthy issues <slug> lists one plugin's findings with file and line.wp airworthy rescan <slug>, wp airworthy export --file=report.csv, wp airworthy status, wp airworthy cancel, wp airworthy resume and wp airworthy targets do what their names say.--wporg or --no-wporg). If you say no, nothing leaves your server.
If you say yes, it looks up each plugin's slug (its folder name) in the public WordPress.org plugin directory (api.wordpress.org), one plugin per request, to show whether it is still maintained. Nothing else is sent: not your site's address (the requests use their own "Airworthy" user agent instead of WordPress's default, which includes your site URL), not your PHP version. As with any web request, WordPress.org sees your server's IP address. Answers are cached for 24 hours.
Airworthy sets no cookies, adds nothing to your site's front end, and has no tracking, account or sign-up.
Source code and build
The full, human-readable source code is public at https://github.com/DigitalKind/airworthy.
The scan engine is built from open-source libraries: PHP_CodeSniffer, PHPCompatibility and PHPCSUtils. Other plugins, or your own tools, may load their own copies of these, possibly different versions. To keep the copies apart, the release build runs them through PHP-Scoper (https://github.com/humbug/php-scoper), which moves their code into Airworthy's own Airworthy\Vendor namespace. The scoped code in the vendor/ folder is ordinary, readable PHP; only the namespace names change.
To rebuild the plugin from source, clone the repository and run bin/build.sh. It installs the exact library versions pinned in plugin/composer.lock, scopes them, checks the result and writes dist/airworthy.zip. docs/ENGINE.md explains each step.
Action Scheduler is bundled unscoped, as WooCommerce and other plugins do, because it is designed to share one copy between all plugins that include it.
Bundled libraries and licences
Airworthy's own code is GPLv2 or later. It bundles:
sbom.cdx.json, CycloneDX format) lists every bundled component and version.
airworthy.zip under Plugins > Add New > Upload Plugin.No. It only reads files and reports. You change the PHP version yourself, usually in your hosting control panel, when you're ready.
Airworthy reads the code without running it. That catches most PHP upgrade problems: functions, classes and constants that were removed, changed syntax, removed extensions, and new reserved words. It sees every file, including code paths your visitors rarely trigger. It can't see what only happens when code runs. For example: code that builds function names at run time, behaviour that depends on your data or settings, and problems in files a plugin downloads or generates later. Some newer PHP changes (such as a few PHP 8.1 and 8.5 deprecations) can't be detected reliably by reading code yet. So a "Ready" verdict means no problems were found, not a guarantee. Test on a staging copy of your site, and keep a backup, before you switch.
No. Airworthy reads code without running it, so some problems can't be seen this way: code that only fails when it runs with your data or settings, your server's configuration, or other software on your site. Treat the results as guidance for planning. Before changing PHP on your live site, back up your files and database, try the new version on a staging copy and check the pages that matter most (checkout, forms, logins), and make sure you know how to switch back. Airworthy is free software provided without any warranty (see the licence), and DigitalKind isn't liable for the results of changing your PHP version.
Airworthy compares the PHP version your site runs now with the one you're moving to. Only PHP changes in between can break something when you upgrade. Code hit by an older change (for example a function removed in PHP 7.0, on a site that already runs PHP 8.3) either never runs on your site or is already failing today, and upgrading doesn't change that. Those findings are still listed in each plugin's details, but they aren't counted as Blockers. If you're checking a copy of a site that runs on another server, choose its PHP version under "Compare from another PHP version".
Nothing, unless you allow it when you start a scan. If you do, only each plugin's slug (its folder name), to look up its public directory entry: not your site address, not your PHP version. See Privacy above. Themes aren't looked up.
Update it first, if an update is available; then rescan just that plugin with the Rescan button. If it's still a Blocker, open the details, download the CSV and send it to the plugin's author or your developer. If the plugin was closed on WordPress.org, look for a maintained replacement.
Scans run in the background in short batches of about 20 seconds, using WordPress's own scheduled tasks (Action Scheduler). Visitors aren't affected. A typical site with 20–30 plugins takes a few minutes; Airworthy estimates the time before you start.
PHP 8.0, 8.1, 8.2, 8.3, 8.4 and 8.5. Versions that no longer get security fixes are marked as ended; you can still check them, but results for them are less precise.
That menu comes from Action Scheduler, the background-job library Airworthy uses (WooCommerce uses the same one). It's harmless, and lists Airworthy's jobs under the "airworthy" group.
Email security@airworthywp.com. Please don't post it in the public support forum. See SECURITY.md in the source repository for how reports are handled.