{"id":342906,"date":"2026-07-24T15:59:25","date_gmt":"2026-07-24T15:59:25","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/codemedic-supplyscope\/"},"modified":"2026-07-25T02:47:21","modified_gmt":"2026-07-25T02:47:21","slug":"codemedic-supplyscope","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/codemedic-supplyscope\/","author":23482379,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"trunk","tested":"7.0.2","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"CodeMedic SupplyScope","header_author":"Adrian M","header_description":"Scans WordPress plugins for vulnerable Composer dependencies and reports CVEs before they become breaches.","assets_banners_color":"1e1e1e","last_updated":"2026-07-25 02:47:21","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/codemedic-supplyscope\/","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":33,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":[],"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3622067,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3622067,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3622067,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3622067,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":[],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3622067,"resolution":"1","location":"assets","locale":"","width":1200,"height":900}},"screenshots":{"1":"The admin screen showing detected vulnerabilities with CVE details."}},"plugin_section":[],"plugin_tags":[1082,250388,23027,600,41325],"plugin_category":[54],"plugin_contributors":[270424],"plugin_business_model":[],"class_list":["post-342906","plugin","type-plugin","status-publish","hentry","plugin_tags-composer","plugin_tags-cve","plugin_tags-dependencies","plugin_tags-security","plugin_tags-vulnerabilities","plugin_category-security-and-spam-protection","plugin_contributors-adrianmikula","plugin_committers-adrianmikula"],"banners":{"banner":"https:\/\/ps.w.org\/codemedic-supplyscope\/assets\/banner-772x250.png?rev=3622067","banner_2x":"https:\/\/ps.w.org\/codemedic-supplyscope\/assets\/banner-1544x500.png?rev=3622067","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/codemedic-supplyscope\/assets\/icon-128x128.png?rev=3622067","icon_2x":"https:\/\/ps.w.org\/codemedic-supplyscope\/assets\/icon-256x256.png?rev=3622067","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/codemedic-supplyscope\/assets\/screenshot-1.png?rev=3622067","caption":"The admin screen showing detected vulnerabilities with CVE details."}],"raw_content":"<!--section=description-->\n<p>CodeMedic SupplyScope detects vulnerable Composer packages bundled within your WordPress plugins. Every hour, it scans your active plugins against a continuously updated CVE intelligence feed and displays the results in a clear admin dashboard.<\/p>\n\n<p>Stop guessing which plugins have unpatched vulnerabilities. Get visibility into the hidden dependency chain of every plugin on your site.<\/p>\n\n<h4>How It Works<\/h4>\n\n<ol>\n<li><strong>Discovery<\/strong> \u2014 Every hour, the plugin scans all active WordPress plugins for bundled Composer dependencies and checks them against our cloud CVE API.<\/li>\n<li><strong>Review<\/strong> \u2014 Detected vulnerabilities are listed in the admin screen with CVE details, severity, and affected library information.<\/li>\n<li><strong>Act<\/strong> \u2014 The plugin reports what's vulnerable so you can take action \u2014 whether that means updating the plugin, replacing it, or applying patches manually.<\/li>\n<\/ol>\n\n<h4>Why Dependency Scanning?<\/h4>\n\n<p>WordPress plugins often bundle Composer dependencies (Guzzle, Monolog, PHPUnit, etc.) directly in their vendor directory. Plugin authors may not update these dependencies promptly after a CVE is disclosed. Without a scanner, you have no visibility into these hidden risks.<\/p>\n\n<p>Patchstack and Wordfence block exploit attempts at the perimeter. This plugin tells you what's vulnerable so you can take action \u2014 whether that means updating the plugin, replacing it, or applying patches manually.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin queries several third-party vulnerability databases to detect known CVEs in Composer dependencies bundled by your WordPress plugins. No personally identifiable information is transmitted. Each service is described below.<\/p>\n\n<h3>OSV.dev<\/h3>\n\n<p>What it is: OSV.dev is an open-source vulnerability database maintained by Google. It is used to look up known vulnerabilities in Composer (Packagist) packages.<\/p>\n\n<p>Data sent: Composer package names and version numbers are sent as JSON in a batch query.<\/p>\n\n<p>When: On every scheduled scan and when a manual scan is triggered from the admin dashboard.<\/p>\n\n<p>Terms of Service: https:\/\/google.github.io\/osv.dev\/\nPrivacy Policy:   https:\/\/policies.google.com\/privacy<\/p>\n\n<h3>National Vulnerability Database (NVD)<\/h3>\n\n<p>What it is: The NVD is a public vulnerability database maintained by NIST (U.S. National Institute of Standards and Technology). It is used to search for CVEs related to WordPress plugins by keyword.<\/p>\n\n<p>Data sent: The WordPress plugin name is sent as a keyword search query parameter. No personal data is transmitted.<\/p>\n\n<p>When: On every scheduled scan and when a manual scan is triggered from the admin dashboard.<\/p>\n\n<p>Terms of Service: https:\/\/nvd.nist.gov\/developers\/terms-of-use\nPrivacy Policy:   https:\/\/www.nist.gov\/privacy-policy<\/p>\n\n<p>Note: This product uses data from the NVD API but is not endorsed or certified by the NVD.<\/p>\n\n<h3>WPVulnerability.net<\/h3>\n\n<p>What it is: WPVulnerability.net is an open-source WordPress vulnerability database. It provides aggregated vulnerability data for WordPress core, plugins, and themes.<\/p>\n\n<p>Data sent: The WordPress plugin slug is sent as part of the API URL path. No personal data is transmitted.<\/p>\n\n<p>When: On every scheduled scan and when a manual scan is triggered from the admin dashboard.<\/p>\n\n<p>Terms of Service: https:\/\/www.wpvulnerability.com\/license\/\nPrivacy Policy:   https:\/\/www.wpvulnerability.com\/privacy\/<\/p>\n\n<h3>WordPress.org Plugin API<\/h3>\n\n<p>What it is: The official WordPress.org plugin information API. It is used to retrieve plugin metadata (such as the current stable version and last updated date) to calculate patch velocity metrics.<\/p>\n\n<p>Data sent: The WordPress plugin slug is sent as a query parameter. No personal data is transmitted.<\/p>\n\n<p>When: On every scheduled scan and when a manual scan is triggered from the admin dashboard.<\/p>\n\n<p>Terms of Service: https:\/\/wordpress.org\/about\/privacy\/\nPrivacy Policy:   https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>codemedic-supplyscope<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory.<\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress.<\/li>\n<li>The plugin begins scanning hourly for vulnerable dependencies. Review findings from Tools &gt; Dep Scanner.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20modify%20my%20files%3F\"><h3>Does this plugin modify my files?<\/h3><\/dt>\n<dd><p>No. The free version is read-only \u2014 it scans and reports vulnerabilities but never modifies any files.<\/p><\/dd>\n<dt id=\"how%20do%20i%20fix%20the%20vulnerabilities%20this%20plugin%20finds%3F\"><h3>How do I fix the vulnerabilities this plugin finds?<\/h3><\/dt>\n<dd><p>Update the affected plugin if a newer version is available, replace it with an alternative, or use the patch history to manually apply fixes.<\/p><\/dd>\n<dt id=\"can%20i%20use%20this%20alongside%20other%20security%20plugins%3F\"><h3>Can I use this alongside other security plugins?<\/h3><\/dt>\n<dd><p>Yes. This plugin is complementary to firewalls and WAFs. It focuses on visibility into bundled Composer dependencies that other tools don't inspect.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Hourly scanning of active plugins for bundled Composer dependencies.<\/li>\n<li>Cloud-based CVE intelligence feed.<\/li>\n<li>Read-only vulnerability dashboard with CVE details and severity.<\/li>\n<li>Patch history log.<\/li>\n<li>Patch history log for audit and manual remediation.<\/li>\n<\/ul>","raw_excerpt":"Scans WordPress plugins for vulnerable Composer dependencies and reports CVEs before they become breaches.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/342906","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=342906"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/adrianmikula"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=342906"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=342906"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=342906"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=342906"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=342906"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=342906"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}