| 开发者 | digitalspacellc |
|---|---|
| 更新时间 | 2026年9月25日 05:18 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
j***@example.com or DE89**************3000. It never becomes a second copy of your personal data.manage_options capability and a nonce.wp pdscan scan, wp pdscan status, wp pdscan findings, wp pdscan infoPDScan\Scan\SourceInterface and hook pdscan/sourcesPDScan\Scan\DetectorInterface and hook pdscan/detectorssrc/Scan/Detectors/national-ids.php or via pdscan/national_idssrc/Scan/Detectors/secret-keys.php or via pdscan/secret_keyssrc/Scan/Detectors/vat-ids.php or via pdscan/vat_idspdscan/is_pro, pdscan/batch_findings, pdscan/keep_scans, pdscan/health_keywords, pdscan/woocommerce/hpos, pdscan/posts/skip_types, pdscan/options/skip_namesassets/src/, shipped alongside the built assets/build/index.js it compiles to. Rebuild with npm install then npm run build (uses webpack.config.js and @wordpress/scripts); nothing outside WordPress core's own bundled @wordpress/* packages is used./wp-content/plugins/ or install it from the Plugins screen.wp pdscan scan with WP-CLI.No. Scanning runs entirely on your server and the plugin makes no outbound requests of any kind.
No. It stores a masked version of each value plus a link to the record it was found in. Uninstalling the plugin drops its tables.
Because it is personal data sitting in the options table. Findings on reserved domains like example.com get a low confidence. Use Ignore for anything you have reviewed.
No. Name detection in prose is noisy and slow. The scanner reports names only in fields whose name says it is a name (first_name, billing_last_name, comment author, and so on).
Yes. Both HPOS tables and legacy post-based orders are supported, and the mode is detected automatically.
Yes. Formats live in one config file with a pattern, an optional checksum validator and a confidence. Pull requests welcome.
No. The scanner shows you where personal data sits. What you must do with it depends on your jurisdiction and your lawful basis for processing.
By design. A personal data scanner has to read raw tables in batches to find data other tools don't know to look for, which is exactly what the object cache and WP_Query are not built for. Every query is still safely prepared with $wpdb->prepare(); the warnings that remain are false positives from table names built with $wpdb->prefix, which Plugin Check cannot statically tell apart from user input. No warning involves unescaped user-supplied data.