wp-coding-standards/wpcs
PHP_CodeSniffer rules (sniffs) to enforce WordPress coding conventions
Activity
- Latest release
- 1mo ago
- Total releases
- 33
- Cadence
- ~3 months
- Last 12 months
- 3
Reach
- Stars
- 2.8k
Details
- License
- MIT
- First release
- Dec 11, 2014
| Version | Released | |
|---|---|---|
3.4.1
patch
| ||
3.4.0
minor
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
3.3.0
minor
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
3.2.0
minor
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
3.1.0
minor
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
3.0.1
patch
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev |
3.0.1
patch
Dependencies (3)
Changelog
Compare changes
|
|
3.0.0
major
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.2.1
patch
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.0.0-RC1
pre
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.2.1
patch
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
0.14.1
patch
1 CVE
CVE-2026-45293
GHSA-3pwp-g2mj-5p3v
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
8.6
/ 10
High
Local
Low
None
Required
Changed
High
High
High
ImpactWordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the This affects users of the The vulnerability happens when the sniff checks whether the PatchesThis issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later. WorkaroundUsers of the
To verify that the sniff has been disabled, run PHPCS with the
CreditsMany thanks to @FORIMOC for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the WPCS repository. Affected versions
0.14.1
1.0.0
1.1.0
1.2.0
1.2.1
2.0.0
2.0.0-RC1
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
+ 6 more Show less
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
0.14.0
minor
| ||
0.13.1
patch
| ||
0.13.0
minor
| ||
0.12.0
minor
| ||
0.11.0
minor
| ||
0.10.0
minor
| ||
0.9.0
minor
| ||
0.8.0
minor
| ||
0.7.1
patch
| ||
0.7.0
minor
| ||
0.6.0
minor
| ||
0.5.0
minor
| ||
0.4.0
minor
| ||
0.3.0
initial
|