Skip to content

Intrinsic Verification - Direct Malware Detection #16

@toderash

Description

@toderash

This standalone application is intended to be used in running automated static code scans on each release of wp-plugin and wp-theme packages to assess whether they contain suspected malware. These checks will be based on static code scans rather than runtime evaluation or CVE checks using available APIs. Examples of prior art are shown here along with other resources, but are not intended as an exhaustive or approved list of libraries to be used.

As described in Direct Malware Detection:

Resulting output to STDOUT is fine, can be piped where we need it later. Output format should be along these lines:

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requesthelp wantedExtra attention is needed

    Projects

    Status

    Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions