Automattic / Automattic/jetpack

Enhancement: Increase Listed Vulnerabilities Number

Open
#36,884 0 comments 0 reactions 0 assignees View on GitHub
[Plugin] Protect Enhancement
Dominant language
PHP
Stars
1.8k
Forks
898
Avg merge
1d 18h
Merged PRs (30d)
774

Description

### Impacted plugin

Protect

### What

Jetpack Protect says it detects "over 22,000" vulnerabilities but that number is actually closer to 50k

### How

![Annotation on 2024-04-12 at 15-37-55](https://github.com/Automattic/jetpack/assets/45246438/caa5f645-e73e-4667-a2e8-eb32b46128bf)

When scanning a site, we cite over 22,000 vulnerabilities in the WPScan database. However, that number is closer to 50k:

https://wpscan.com/statistics/

I don't think it needs to be perfectly in sync but it feels like
We also show this number when asking folks to upgrade:

![Annotation on 2024-04-12 at 15-43-43](https://github.com/Automattic/jetpack/assets/45246438/f6355f80-0e31-4e61-b9c5-a3516a88e0a9)

Contributor guide

Open the contributing guide

Research direction

No file or test is named. Search the Jetpack Protect code for the “over 22,000” text, inspect the scanning and upgrade-prompt surfaces, and update the displayed approximate vulnerability count to reflect the current WPScan statistics. Verify that both locations show the revised wording.

Written by the indexing model from the issue text.

Assessment

Tech stack
php, wordpress
Domain
frontend, security
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.