class
Analyzer::Php::Wordpress
Overview
WordPress attack-surface extractor.
WordPress does not expose a conventional route table; its HTTP surface is registered imperatively through a handful of well-known APIs:
- REST API —
register_rest_route( $namespace, $route, $args )served under/wp-json/{namespace}/{route}. - Admin AJAX —
add_action( 'wp_ajax_{action}', ... )and the publicwp_ajax_nopriv_{action}variant, dispatched by/wp-admin/admin-ajax.php?action={action}. - Admin POST —
add_action( 'admin_post_{action}', ... )/admin_post_nopriv_{action}, dispatched by/wp-admin/admin-post.php?action={action}.
Defined in:
analyzer/analyzers/php/wordpress.crConstant Summary
-
ADMIN_AJAX_PATH =
"/wp-admin/admin-ajax.php" -
ADMIN_POST_PATH =
"/wp-admin/admin-post.php" -
ALL_HTTP_VERBS =
["GET", "POST", "PUT", "PATCH", "DELETE"] -
DISPATCH_METHODS =
["GET", "POST"] -
WordPress admin-ajax / admin-post dispatch on
$_REQUEST['action'], so both verbs are valid entry points. -
REST_METHOD_CONSTANTS =
{"READABLE" => ["GET"], "CREATABLE" => ["POST"], "EDITABLE" => ["POST", "PUT", "PATCH"], "DELETABLE" => ["DELETE"], "ALLMETHODS" => ["GET", "POST", "PUT", "PATCH", "DELETE"]} -
WP_REST_Server::method-group constants → concrete HTTP verbs. -
SPLIT_ARGS_RULES =
Noir::TopLevelSplit::Rules.new(nest: (Noir::TopLevelSplit::Nest::Paren | Noir::TopLevelSplit::Nest::Bracket) | Noir::TopLevelSplit::Nest::Brace, quotes: "\"'", escape: Noir::TopLevelSplit::Escape::InQuotes, strip: false, empties: Noir::TopLevelSplit::Empties::DropTrailing, per_kind: false, clamp: false) -
Rules::SHARED_DEPTH_RAWwith a trailing empty dropped and, like erlang/cowboy.cr, WITHOUT clamping: the body this replaces closed brackets with a baredepth -= 1, so a fragment beginning with a closer (")x, y") drives depth negative and stops splitting. That is observable on the regex-sliced input this actually receives, so it is preserved rather than normalised.File-local because wordpress is the only splitter pairing
clamp: falsewith unstripped parts.
Class Method Summary
Instance Method Summary
- #analyze_file(path : String) : Array(Endpoint)
-
#tech : String
Instance-side view of the same declaration.
Class methods inherited from class Analyzer::Php::PhpEngine
test_path?(relative_path : String) : Bool
test_path?
Instance methods inherited from class FileScanEngine
analyze
analyze,
analyze_file(path : String) : Array(Endpoint)
analyze_file
Instance methods inherited from class Analyzer
analyze
analyze,
base_path : String
base_path,
base_paths : Array(String)
base_paths,
base_relative_path(path : String) : String
base_relative_path,
callees_needed? : Bool
callees_needed?,
content_matches?(content : String, markers : Regex) : Bool
content_matches?,
http_header_name(name : String) : String | Nil
http_header_name,
line_number_for_index(content : String, char_index : Int32) : Int32
line_number_for_index,
logger : NoirLogger
logger,
parallel_analyze(files : Array(String), &block : String -> Nil)
parallel_analyze,
read_file_content(path : String) : String
read_file_content,
result : Array(Endpoint)
result,
tech : String
tech,
unique_params(params : Array(Param)) : Array(Param)
unique_params,
url : String
url,
web_root_path(path : String, markers : Array(String)) : String
web_root_path
Constructor methods inherited from class Analyzer
new(options : Hash(String, YAML::Any))
new
Macros inherited from class Analyzer
analyzer_for(tech)
analyzer_for
Instance methods inherited from module FileHelper
all_files : Array(String)
all_files,
get_files_by_basename(basename : String) : Array(String)
get_files_by_basename,
get_files_by_extension(extension : String) : Array(String)
get_files_by_extension,
get_files_by_extensions(extensions : Array(String)) : Array(String)
get_files_by_extensions,
get_files_by_prefix(prefix : String) : Array(String)
get_files_by_prefix,
get_files_by_prefix_and_extension(prefix : String, extension : String) : Array(String)
get_files_by_prefix_and_extension,
get_files_by_relative_path(relative_path : String, root : String = "") : Array(String)
get_files_by_relative_path,
get_public_dir_files(base_path : String, folder : String) : Array(String)
get_public_dir_files,
get_public_files(base_path : String, anchors : Array(String) = ["shard.yml", "Gemfile"]) : Array(String)
get_public_files,
walked_path(expanded : String) : String
walked_path
Class Method Detail
Instance Method Detail
Instance-side view of the same declaration. The per-file rescues live on
this base class, which has no way to name the analyzer that is running
inside them, so a skipped file could not be attributed to a tech.
Deriving it from analyzer_for keeps the name written exactly once.