| Slug | benchmark |
|---|---|
| Closed reason | author-request |
| Closed date | 2026-08-25 00:00:00 |
| Active installs | 70 |
View raw JSON
{
"slug": "benchmark",
"closed_reason": "author-request",
"closed_date": "2026-08-25 00:00:00",
"active_installs": 70
}| Slug | benchmark |
|---|---|
| Closed reason | author-request |
| Closed date | 2026-08-25 00:00:00 |
| Active installs | 70 |
{
"slug": "benchmark",
"closed_reason": "author-request",
"closed_date": "2026-08-25 00:00:00",
"active_installs": 70
}| Slug | wordfence | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Finding count | 37 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Findings |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Triage note 2026 05 03 | wordfence: 37 base64_decode hits, all in legitimate JWT decode (lib/wfJWT.php), activity-report parameters, URL hoover skip-list. Standard security-plugin internals. |
{
"slug": "wordfence",
"finding_count": 37,
"findings": [
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wfActivityReport.php",
"line": 592,
"snippet": "$paramKey = base64_decode($actionData['paramKey']);",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wfActivityReport.php",
"line": 593,
"snippet": "$paramValue = base64_decode($actionData['paramValue']);",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wfUtils.php",
"line": 3791,
"snippet": "$intermediate = base64_decode($intermediate);",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wfJWT.php",
"line": 21,
"snippet": "$decodedHeader = base64_decode($header);",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wfJWT.php",
"line": 32,
"snippet": "$decodedBody = base64_decode($body);",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wfJWT.php",
"line": 91,
"snippet": "$decodedHeader = base64_decode($header);",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wfJWT.php",
"line": 107,
"snippet": "$decodedBody = base64_decode($body);",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wfJWT.php",
"line": 179,
"snippet": "return base64_decode(strtr($data, '-_', '+/'));",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wordfenceURLHoover.php",
"line": 604,
"snippet": "$skipList = new wfBinaryList(base64_decode(wfConfig::get('wfsbskip', '')));",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wfLog.php",
"line": 1356,
"snippet": "$actionData[$key] = base64_decode($actionData[$key]);",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wordfenceClass.php",
"line": 1182,
"snippet": "$iwpRequest = json_decode(trim(base64_decode($iwpRequestDataArray[1])), true);",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wordfenceClass.php",
"line": 7588,
"snippet": "$waf->whitelistRuleForParam(base64_decode($_POST['path']), base64_decode($_POST['paramKey']),",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wordfenceClass.php",
"line": 8116,
"snippet": "$paramKey = base64_decode($actionData['paramKey']);",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wordfenceClass.php",
"line": 8117,
"snippet": "$paramValue = base64_decode($actionData['paramValue']);",
"confidence": "medium"
},
{
"pattern": "base64_decode",
"kind": "builtin",
"file": "lib/wordfenceClass.php",
"line": 8356,
"snippet": "$value['path'] = base64_decode($path);",
"confidence": "medium"
}
],
"triage_note_2026_05_03": "wordfence: 37 base64_decode hits, all in legitimate JWT decode (lib/wfJWT.php), activity-report parameters, URL hoover skip-list. Standard security-plugin internals."
}| Slug | wordfence |
|---|---|
| Committer slug | wfmatt |
| Committer display name | wfmatt |
| Committer employer | — |
| Committer member since | 2014-12-21 |
| Committer first commit | 2014-12-22 03:10:09 |
| Committer commit count | 28 |
| Plugin listed author | mmaunder |
| Earliest plugin commit | 2011-09-04 10:09:14 |
| Plugin age at join days | 1,204 |
| Committer age at join days | 1 |
| Active installs | 5,000,000 |
{
"slug": "wordfence",
"committer_slug": "wfmatt",
"committer_display_name": "wfmatt",
"committer_employer": null,
"committer_member_since": "2014-12-21",
"committer_first_commit": "2014-12-22 03:10:09",
"committer_commit_count": 28,
"plugin_listed_author": "mmaunder",
"earliest_plugin_commit": "2011-09-04 10:09:14",
"plugin_age_at_join_days": 1204,
"committer_age_at_join_days": 1,
"active_installs": 5000000
}| Plugin | Version | Installs | Last updated | Status |
|---|---|---|---|---|
Wordfence Security – Firewall, Malware Scan, and Login Security ·wordfence |
9.0.0 | 5M+ | 21d ago | Active |
Benchmark ·benchmark |
1.1 | 70 | — | Closed |
timthumb ·timthumb |
— | — | — | Closed |
Wordfence Assistant ·wordfence-assistant |
1.0.10 | — | — | Closed |
Plugins this account has pushed commits to, reconstructed from plugins.svn.wordpress.org. A new name showing up here on an established plugin is the strongest ownership-transfer signal.
| Plugin | Primary author | Installs | Commits | First | Latest | Status |
|---|---|---|---|---|---|---|
| Wordfence Security – Firewall, Malware Scan, and Login Security | mmaunder | 5M+ | 179 | 14y ago | 11y ago | Active |
| Benchmark | mmaunder | 70 | 2 | 13y ago | 13y ago | Closed |
| Wordfence Assistant | mmaunder | — | 2 | 12y ago | 12y ago | Closed |
Plugins where this account is listed in the readme contributors (distinct from SVN commit access).
| Plugin | Primary author | Version | Installs |
|---|---|---|---|
| Wordfence Login Security | wfryan | 1.1.18 | 60k+ |