PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 16.2-a.1
Jetpack – WP Security, Backup, Speed, & Growth v16.2-a.1
16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / jetpack_vendor / automattic / jetpack-protect-models / src / class-threat-model.php
jetpack / jetpack_vendor / automattic / jetpack-protect-models / src Last commit date
class-extension-model.php 1 year ago class-history-model.php 1 year ago class-protect-models.php 2 months ago class-status-model.php 1 year ago class-threat-model.php 8 months ago class-vulnerability-model.php 8 months ago
class-threat-model.php
273 lines
1 <?php
2 /**
3 * Model class for threat data.
4 *
5 * @package automattic/jetpack-protect-models
6 */
7
8 namespace Automattic\Jetpack\Protect_Models;
9
10 /**
11 * Model class for threat data.
12 */
13 class Threat_Model {
14
15 /**
16 * Threat ID.
17 *
18 * @var null|string
19 */
20 public $id;
21
22 /**
23 * Threat Signature.
24 *
25 * @var null|string
26 */
27 public $signature;
28
29 /**
30 * Threat Title.
31 *
32 * @var null|string
33 */
34 public $title;
35
36 /**
37 * Threat Description.
38 *
39 * @var null|string
40 */
41 public $description;
42
43 /**
44 * The data the threat was first detected.
45 *
46 * @var null|string
47 */
48 public $first_detected;
49
50 /**
51 * The version the threat is fixed in.
52 *
53 * @var null|string
54 */
55 public $fixed_in;
56
57 /**
58 * The date the threat is fixed on.
59 *
60 * @var null|string
61 */
62 public $fixed_on;
63
64 /**
65 * The severity of the threat between 1-5.
66 *
67 * @var null|int
68 */
69 public $severity;
70
71 /**
72 * Information about the auto-fix available for this threat. False when not auto-fixable.
73 *
74 * @var null|bool|object
75 */
76 public $fixable;
77
78 /**
79 * The current status of the threat.
80 *
81 * @var null|string
82 */
83 public $status;
84
85 /**
86 * The filename of the threat.
87 *
88 * @var null|string
89 */
90 public $filename;
91
92 /**
93 * The context of the threat.
94 *
95 * @var null|object
96 */
97 public $context;
98
99 /**
100 * The database table of the threat.
101 *
102 * @var null|string
103 */
104 public $table;
105
106 /**
107 * Additional details about the database threat.
108 *
109 * @var null|object
110 */
111 public $details;
112
113 /**
114 * The source URL of the threat.
115 *
116 * @var null|string
117 */
118 public $source;
119
120 /**
121 * The threat's extension information.
122 *
123 * @since 0.4.0
124 *
125 * @var null|Extension_Model
126 */
127 public $extension;
128
129 /**
130 * The threat's related vulnerabilities.
131 *
132 * @since 0.5.0
133 *
134 * @var null|Vulnerability_Model[]
135 */
136 public $vulnerabilities;
137
138 /**
139 * Threat Constructor
140 *
141 * @param array|object $threat Threat data to load into the class instance.
142 */
143 public function __construct( $threat ) {
144 if ( is_object( $threat ) ) {
145 $threat = (array) $threat;
146 }
147
148 foreach ( $threat as $property => $value ) {
149 if ( 'extension' === $property && ! empty( $value ) ) {
150 $this->extension = new Extension_Model( $value );
151 continue;
152 }
153 if ( property_exists( $this, $property ) ) {
154 $this->$property = $value;
155 }
156 }
157 }
158
159 /**
160 * Get the ID value of the threat based on its related extension and vulnerabilities.
161 *
162 * @since 0.5.0
163 *
164 * @param Extension_Model $extension The extension to get the ID from.
165 *
166 * @return string
167 */
168 private static function get_id_from_vulnerable_extension( Extension_Model $extension ) {
169 return "$extension->type-$extension->slug-$extension->version";
170 }
171
172 /**
173 * Get the title from a vulnerable extension.
174 *
175 * @since 0.5.0
176 *
177 * @param Extension_Model $extension The extension to get the title from.
178 *
179 * @return string|null
180 */
181 private static function get_title_from_vulnerable_extension( Extension_Model $extension ) {
182 $titles = array(
183 'plugins' => sprintf(
184 /* translators: placeholders are the theme name and version number. Example: "Vulnerable theme: Jetpack (version 1.2.3)" */
185 __( 'Vulnerable plugin: %1$s (version %2$s)', 'jetpack-protect-models' ),
186 $extension->name,
187 $extension->version
188 ),
189 'themes' => sprintf(
190 /* translators: placeholders are the theme name and version number. Example: "Vulnerable theme: Jetpack (version 1.2.3)" */
191 __( 'Vulnerable theme: %1$s (version %2$s)', 'jetpack-protect-models' ),
192 $extension->name,
193 $extension->version
194 ),
195 'core' => sprintf(
196 /* translators: placeholder is the version number. Example: "Vulnerable WordPress (version 1.2.3)" */
197 __( 'Vulnerable WordPress (version %s)', 'jetpack-protect-models' ),
198 $extension->version
199 ),
200 );
201
202 return $titles[ $extension->type ] ?? null;
203 }
204
205 /**
206 * Get the description from a vulnerable extension.
207 *
208 * @since 0.5.0
209 *
210 * @param Extension_Model $extension The extension to get the description from.
211 * @param array $vulnerabilities The vulnerabilities to get the description from.
212 *
213 * @return string
214 */
215 private static function get_description_from_vulnerable_extension( Extension_Model $extension, array $vulnerabilities ) {
216 return sprintf(
217 /* translators: placeholders are the theme name and version number. Example: "The installed version of Jetpack (1.2.3) has a known security vulnerability." */
218 _n( 'The installed version of %1$s (%2$s) has a known security vulnerability.', 'The installed version of %1$s (%2$s) has known security vulnerabilities.', count( $vulnerabilities ), 'jetpack-protect-models' ),
219 $extension->name,
220 $extension->version
221 );
222 }
223
224 /**
225 * Get the latest fixed_in version from a list of vulnerabilities.
226 *
227 * @since 0.5.0
228 *
229 * @param array $vulnerabilities The vulnerabilities to get the fixed_in version from.
230 *
231 * @return string|bool|null The latest fixed_in version, or false if any of the vulnerabilities are not fixed.
232 */
233 private static function get_fixed_in_from_vulnerabilities( array $vulnerabilities ) {
234 $fixed_in = null;
235
236 foreach ( $vulnerabilities as $vulnerability ) {
237 // If any of the vulnerabilities are not fixed, the threat is not fixed.
238 if ( ! $vulnerability->fixed_in ) {
239 break;
240 }
241
242 // Use the latest available fixed_in version.
243 if ( ! $fixed_in || ( $fixed_in && version_compare( $vulnerability->fixed_in, $fixed_in, '>' ) ) ) {
244 $fixed_in = $vulnerability->fixed_in;
245 }
246 }
247
248 return $fixed_in;
249 }
250
251 /**
252 * Generate a threat from extension vulnerabilities.
253 *
254 * @since 0.5.0
255 *
256 * @param Extension_Model $extension The extension to generate the threat for.
257 * @param Vulnerability_Model[] $vulnerabilities The vulnerabilities to generate the threat from.
258 *
259 * @return Threat_Model
260 */
261 public static function generate_from_extension_vulnerabilities( Extension_Model $extension, array $vulnerabilities ) {
262 return new Threat_Model(
263 array(
264 'id' => self::get_id_from_vulnerable_extension( $extension ),
265 'title' => self::get_title_from_vulnerable_extension( $extension ),
266 'description' => self::get_description_from_vulnerable_extension( $extension, $vulnerabilities ),
267 'fixed_in' => self::get_fixed_in_from_vulnerabilities( $vulnerabilities ),
268 'vulnerabilities' => $vulnerabilities,
269 )
270 );
271 }
272 }
273