Detecting Incorrect Wordpress Plugin Function Usage

Studenteropgave: Kandidatspeciale og HD afgangsprojekt

  • Jens Thomas Vejlby Nielsen
4. semester, Datalogi, Kandidat (Kandidatuddannelse)
This thesis presents the problem of incorrectly using either PHP build-in or homemade functions for WordPress plugin development. WordPress itself is created in a secure way, and vulnerabilities are quickly corrected. This is not the case for plugins, where there can be a multitude of vulnerabilities. WordPress supplies functions for correctly sanitisation of data, along with connecting to databases. WordPress allows the core functionality to be changed by using filters and actions, and if a developer forgets to close a filter this can have security and correctness implications.

A proof-of-concept solution using the nuXmv Model Checker on a WordPress plugin model for finding incorrect function usage and open filters is presented. Tests of the tool show that it is still clear that this is a proof-of-concept solution.
Udgivelsesdato3 jun. 2015
Antal sider28
ID: 213517445