hosting

GET /v1/sites/{siteId}/wordpress/vulnerabilities

Published advisories against the plugin and theme versions installed here.

Tutti gli endpoint hosting

Autenticazione

Invia una chiave API come token di tipo bearer. La chiave deve disporre dell'autorizzazione sites.view; una chiave sprovvista di tale autorizzazione viene rifiutata con 403 anziché 404.

Questo endpoint non richiede alcun ID organizzazione. La tua chiave identifica già l'organizzazione a cui appartiene e la risposta è limitata ad essa.

Provalo

Sostituisci qualsiasi elemento tra parentesi angolari con i tuoi valori e il segnaposto key con una chiave dalla tua dashboard.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/wordpress/vulnerabilities \
  -H "Authorization: Bearer zdk_live_…"

Hai effettuato l'accesso? La console API nella tua dashboard inserisce il tuo ID organizzazione reale e la tua chiave personale, ed esegue la richiesta sull'API live in modo da poter vedere la risposta effettiva. Apri questo endpoint nella console API

Dettagli

Joins the site's installed component versions to a public vulnerability feed, so the answer is about **the version this site runs** rather than about the plugin in general. ⛔⛔ `checked: false` means **we could not assess this component**, not "nothing found". Every bespoke plugin, every premium plugin with no public listing and every advisory published in the last hour reads as unchecked. A client that renders an unchecked row as clean is making a safety claim the platform has no basis for — the one output this endpoint must never produce. `unchecked` counts them. ⛔ `truncated` is `true` when the site has more components than one request will look up. A bounded answer that does not say it is bounded reads as a complete one. ⛔ `fixed_in` is blank when the advisory is unfixed **or** names only an upper bound — "affected at or below X" does not mean "fixed in X", and reporting it as such would send a customer to a version that is still vulnerable. Available on **both** product lines: the inputs are the plugin and theme listings, which every WordPress surface answers. Requires `sites.view`.

Parametri

NomeTipoObbligatorioChe cos'è
siteId (path)UuidSite ID (UUIDv7).

Risposta

NomeTipoObbligatorioChe cos'è
dataWordPressComponentRisk[]
worststringThe worst severity found across the site, or `""`.
uncheckedintegerHow many components could not be assessed. ⛔ The number that says how much of the estate this screen cannot speak for.
checked_componentsintegerHow many components were assessed.
advisoriesintegerHow many advisories were found in total.
truncatedbooleanTrue when the site has more components than one request will look up.

Errori che questo endpoint può restituire

401 · 403 · 404 · 429 · 503