← All projects
Independent researchOngoing research

WAL Research

Independent WordPress and AI security research, from initial hypotheses to reproducible evidence and coordinated disclosure.

Open WAL Research app →

Evidence before publication

WAL Research brings together hands-on vulnerability investigation, AI-assisted code review, triage, and validation. The emphasis is on understanding a failure well enough to explain and reproduce it.

Areas of work

  • WordPress access control and authorization boundaries.
  • Application behavior across users, roles, and object ownership.
  • AI-assisted investigation and the reliability of generated hypotheses.
  • Clear reporting that separates observations, assumptions, and verified impact.

From lead to reviewed finding

StageEvidence required to move forward
HypothesisA bounded question, affected feature, and reason to investigate
Source reviewRelevant entry point, code path, permissions, and assumptions
Lab reproductionExact version, environment, account role, and observed behavior
Human reviewSupported impact, repeatability, and alternate explanations
Remediation reviewProposed change and comparison with the original behavior
Disclosure decisionConfirmed publication status and an appropriate report audience

Rejected and inconclusive leads belong in the record too. They explain false positives and prevent unsupported claims from repeatedly entering the queue.

A reproducible report

  1. Scope and provenance: component, exact version, source origin, and test environment.
  2. Prerequisites: account role, configuration, and required application state.
  3. Expected versus observed behavior: a precise description of the boundary and result.
  4. Reproduction: ordered steps and relevant evidence from the controlled lab.
  5. Impact: what was demonstrated, with assumptions and limits made explicit.
  6. Remediation and retest: proposed correction and behavior after a fix.
What distinguishes a lead from a finding?

A lead suggests behavior worth investigating. A finding has evidence supporting a specific claim. An AI review, pattern match, or unusual response alone does not establish reproducibility or impact.

The connected workflow

AnchorScope focuses the research queue. WAL-0.1 assists investigation. WAL Research decides what the evidence supports and how to communicate it. Discovery rankings and model confidence do not replace human review.

Responsible disclosure

Detailed vulnerability write-ups are published only when disclosure is authorized. Unreleased findings, affected targets, and reserved identifiers are intentionally excluded from this overview.

Read the field notes

The WAL Research app provides private reports with scope, prerequisites, observed behavior, reproduction, evidence, impact, remediation, and disclosure notes. Create a report directly or from a WAL-0.1 lead, edit its review stage, archive and restore it, and export Markdown or JSON backups. Saving does not send or publicly publish a disclosure.

The research archive includes the site’s existing notes on agent security, model evaluations, and untrusted context. These educational notes are separate from vulnerability advisories.

Next research outputs

Useful next public artifacts include a documented methodology, a reviewed reference dataset, comparative evaluation results, and disclosure-ready case studies when available. Performance numbers should include their sample, method, and limitations. No verified advisory count is claimed by this portfolio.