wp-block-security
CommunityIdentify stored XSS in WordPress Gutenberg blocks.
Authorobenland
Version1.0.0
Installs0
System Documentation
What problem does it solve?
WordPress security teams and developers need a structured methodology to identify stored XSS vulnerabilities in Gutenberg blocks by tracing how user-controlled $attributes propagate through render_callback output.
Core Features & Use Cases
- Stepwise mapping of render_callback registrations to their output contexts to surface unsafe attribute usage.
- Context-aware escaping guidance, severity classification, and a structured report format for reproducible audits.
- Real-world reference patterns illustrating insecure and secure render paths to train developers and CI pipelines.
Quick Start
Run a targeted audit on a WordPress Gutenberg block by tracing how $attributes flow from render_callback to HTML output and validating the escaping at each step.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: wp-block-security Download link: https://github.com/obenland/dotfiles/archive/main.zip#wp-block-security Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.