One of the things that we appear to uniquely do in compiling data on vulnerabilities in WordPress plugins is that is that we fully review and test out vulnerabilities when adding them to our data set. That means that unlike other sources we won’t falsely tell people that an unfixed vulnerability has been fixed. It also means that we don’t include false reports of vulnerabilities in our data. One of the things that we do to make sure we exclude false reports, but don’t miss out including vulnerabilities even if the reports are inaccurate, is by writing up the details of false reports, which helps to make sure we have fully review things before making a determination on a report.
…
[Read more]