Linux 软件免费装
Banner图

CodeMedic SupplyScope

开发者 adrianmikula
更新时间 2026年7月25日 10:47
PHP版本: 7.4 及以上
WordPress版本: 7.0
版权: GPLv2 or later

标签

security composer vulnerabilities dependencies cve

下载

详情介绍:

CodeMedic SupplyScope detects vulnerable Composer packages bundled within your WordPress plugins. Every hour, it scans your active plugins against a continuously updated CVE intelligence feed and displays the results in a clear admin dashboard. Stop guessing which plugins have unpatched vulnerabilities. Get visibility into the hidden dependency chain of every plugin on your site. How It Works
  1. Discovery — Every hour, the plugin scans all active WordPress plugins for bundled Composer dependencies and checks them against our cloud CVE API.
  2. Review — Detected vulnerabilities are listed in the admin screen with CVE details, severity, and affected library information.
  3. Act — The plugin reports what's vulnerable so you can take action — whether that means updating the plugin, replacing it, or applying patches manually.
Why Dependency Scanning? WordPress plugins often bundle Composer dependencies (Guzzle, Monolog, PHPUnit, etc.) directly in their vendor directory. Plugin authors may not update these dependencies promptly after a CVE is disclosed. Without a scanner, you have no visibility into these hidden risks. Patchstack and Wordfence block exploit attempts at the perimeter. This plugin tells you what's vulnerable so you can take action — whether that means updating the plugin, replacing it, or applying patches manually.

安装:

  1. Upload the codemedic-supplyscope folder to the /wp-content/plugins/ directory.
  2. Activate the plugin through the 'Plugins' menu in WordPress.
  3. The plugin begins scanning hourly for vulnerable dependencies. Review findings from Tools > Dep Scanner.

常见问题:

Does this plugin modify my files?

No. The free version is read-only — it scans and reports vulnerabilities but never modifies any files.

How do I fix the vulnerabilities this plugin finds?

Update the affected plugin if a newer version is available, replace it with an alternative, or use the patch history to manually apply fixes.

Can I use this alongside other security plugins?

Yes. This plugin is complementary to firewalls and WAFs. It focuses on visibility into bundled Composer dependencies that other tools don't inspect.

更新日志:

1.0.0