wp-block-security

Community

Identify stored XSS in WordPress Gutenberg blocks.

Authorobenland
Version1.0.0
Installs0

System Documentation

What problem does it solve?

WordPress security teams and developers need a structured methodology to identify stored XSS vulnerabilities in Gutenberg blocks by tracing how user-controlled $attributes propagate through render_callback output.

Core Features & Use Cases

  • Stepwise mapping of render_callback registrations to their output contexts to surface unsafe attribute usage.
  • Context-aware escaping guidance, severity classification, and a structured report format for reproducible audits.
  • Real-world reference patterns illustrating insecure and secure render paths to train developers and CI pipelines.

Quick Start

Run a targeted audit on a WordPress Gutenberg block by tracing how $attributes flow from render_callback to HTML output and validating the escaping at each step.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: wp-block-security
Download link: https://github.com/obenland/dotfiles/archive/main.zip#wp-block-security

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.