← All projects
WordPress intelligenceActive development

AnchorScope

A discovery workspace for turning the WordPress plugin ecosystem into a focused security research queue.

Open AnchorScope app →

Start with a better question

AnchorScope helps organize plugin discovery before deeper investigation begins. Its purpose is to find useful research candidates, understand their context, and make the next review decision easier.

The research workflow

  1. Discover — explore WordPress plugins and narrow the ecosystem with research filters.
  2. Prioritize — consider maintenance signals, deployment footprint, and the surface exposed by each candidate.
  3. Investigate — move selected candidates into a separate review process, including WAL-0.1.

A discovery signal is a reason to investigate. It does not establish that a plugin is vulnerable.

Where it fits

AnchorScope is the discovery and intake layer of the WAL security research workflow. WAL-0.1 is the experimental investigation system; WAL Research covers human review and responsible disclosure.

Build a useful research queue

StepResearch decisionRecord to keep
DiscoverWhich plugins match the area of interest?Plugin identifier, directory link, retrieval date
ExamineWhat functionality and maintenance context matter?Exact version, update history, relevant features
PrioritizeWhy review this candidate now?An explicit research rationale
PrepareCan this version be reviewed and tested?Source origin and authorized scope
Hand offWhat should the investigation answer?A bounded hypothesis for WAL-0.1

Read signals in context

Maintenance history and deployment footprint help focus a queue, but neither establishes security quality. An old update date can describe an abandoned project or a stable one. Installation counts describe reach, not the existence or severity of a vulnerability.

Feature context supplies more specific research questions: user-submitted content, file handling, administrative actions, integrations, and custom permissions expose different behaviors for a reviewer to examine.

What belongs in a candidate brief?

Record the plugin identifier and exact version, source link, metadata collection date, feature being investigated, reason for selection, and next review question. Separate observations from assumptions.

Current stage

Open AnchorScope to search the live WordPress.org catalog, filter and sort returned results, save a research queue, record selection rationale, export the queue, and hand a candidate to WAL-0.1. Saved records belong to your signed-in workspace.

Catalog signals support discovery; AnchorScope does not scan or declare plugins vulnerable. Search filters and sorting apply to the current result page.