hosting
GET /v1/sites/{siteId}/wordpress/vulnerabilities
Published advisories against the plugin and theme versions installed here.
Autenticação
Envie uma chave de API como um token de portador. A chave deve ter a permissão sites.view; uma chave sem ela é recusada com 403, e não 404.
Este endpoint não requer um ID de organização. Sua chave já identifica a organização à qual pertence, e a resposta é delimitada a ela.
Experimente
Substitua qualquer item entre colchetes por seus próprios valores e o espaço reservado para a chave por uma chave do seu painel.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/wordpress/vulnerabilities \
-H "Authorization: Bearer zdk_live_…"Conectado? O console da API no seu painel preenche o ID da sua organização real e a sua própria chave, e executa a requisição contra a API de produção para que você possa ver a resposta real. Abra este endpoint no console da API
Detalhes
Joins the site's installed component versions to a public vulnerability feed, so the answer is about **the version this site runs** rather than about the plugin in general. ⛔⛔ `checked: false` means **we could not assess this component**, not "nothing found". Every bespoke plugin, every premium plugin with no public listing and every advisory published in the last hour reads as unchecked. A client that renders an unchecked row as clean is making a safety claim the platform has no basis for — the one output this endpoint must never produce. `unchecked` counts them. ⛔ `truncated` is `true` when the site has more components than one request will look up. A bounded answer that does not say it is bounded reads as a complete one. ⛔ `fixed_in` is blank when the advisory is unfixed **or** names only an upper bound — "affected at or below X" does not mean "fixed in X", and reporting it as such would send a customer to a version that is still vulnerable. Available on **both** product lines: the inputs are the plugin and theme listings, which every WordPress surface answers. Requires `sites.view`.
Parâmetros
| Nome | Tipo | Obrigatório | O que é |
|---|---|---|---|
siteId (path) | Uuid | Sim | Site ID (UUIDv7). |
Resposta
| Nome | Tipo | Obrigatório | O que é |
|---|---|---|---|
data | WordPressComponentRisk[] | Sim | — |
worst | string | Sim | The worst severity found across the site, or `""`. |
unchecked | integer | Sim | How many components could not be assessed. ⛔ The number that says how much of the estate this screen cannot speak for. |
checked_components | integer | Sim | How many components were assessed. |
advisories | integer | Sim | How many advisories were found in total. |
truncated | boolean | Sim | True when the site has more components than one request will look up. |
Erros que este endpoint pode retornar
401 · 403 · 404 · 429 · 503