rp-source-wordpress
Warn
Audited by Snyk on Jul 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider free text is fetched at runtime from the user-supplied WordPress base URL (public REST index + per-entity OPTIONS/GET responses), and
scripts/wp-discovery.jsparsesresponse.text()/JSON and writes sample records/schemas into markdown that is then used as LLM context by later stages.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata