hosting
GET /v1/sites/{siteId}/wordpress/vulnerabilities
Published advisories against the plugin and theme versions installed here.
Упълномощаване
Изпратете API ключ като токен за носене. Ключът трябва да притежава разрешението sites.view; ключ без него се отхвърля с 403, а не с 404.
Този ендпойнт не изисква идентификатор на организация. Вашият ключ вече идентифицира организацията, към която принадлежи, и отговорът е ограничен до нея.
Опитайте
Заменете всичко в квадратни скоби със собствени стойности, а ключовия заместващ символ – с ключ от вашето табло за управление.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/wordpress/vulnerabilities \
-H "Authorization: Bearer zdk_live_…"Влязохте ли в профила си? API конзолата във вашето табло за управление попълва действителното идентификационно число на вашата организация и вашия собствен ключ и изпълнява заявката спрямо реалното API, за да можете да видите действителния отговор. Отворете този крайpoint в API конзолата
Детайли
Joins the site's installed component versions to a public vulnerability feed, so the answer is about **the version this site runs** rather than about the plugin in general. ⛔⛔ `checked: false` means **we could not assess this component**, not "nothing found". Every bespoke plugin, every premium plugin with no public listing and every advisory published in the last hour reads as unchecked. A client that renders an unchecked row as clean is making a safety claim the platform has no basis for — the one output this endpoint must never produce. `unchecked` counts them. ⛔ `truncated` is `true` when the site has more components than one request will look up. A bounded answer that does not say it is bounded reads as a complete one. ⛔ `fixed_in` is blank when the advisory is unfixed **or** names only an upper bound — "affected at or below X" does not mean "fixed in X", and reporting it as such would send a customer to a version that is still vulnerable. Available on **both** product lines: the inputs are the plugin and theme listings, which every WordPress surface answers. Requires `sites.view`.
Параметри
| Име | Тип | Задължително | Какво представлява |
|---|---|---|---|
siteId (path) | Uuid | Да | Site ID (UUIDv7). |
Отговор
| Име | Тип | Задължително | Какво представлява |
|---|---|---|---|
data | WordPressComponentRisk[] | Да | — |
worst | string | Да | The worst severity found across the site, or `""`. |
unchecked | integer | Да | How many components could not be assessed. ⛔ The number that says how much of the estate this screen cannot speak for. |
checked_components | integer | Да | How many components were assessed. |
advisories | integer | Да | How many advisories were found in total. |
truncated | boolean | Да | True when the site has more components than one request will look up. |
Грешки, които този крайpoint може да върне
401 · 403 · 404 · 429 · 503