3 ms·
It doesn't appear to be parsing at all. It's just looking for patterns. If you look at languages.json in RulesEngine/Resources, files with the extension .html
by SloopJon 7y ago
It doesn't appear to be parsing at all. It's just looking for patterns.
If you look at languages.json in RulesEngine/Resources, files with the extension .html (and some others) are recognized as "html", with type "code":
{
"name": "html",
"extensions": [ ".html", ".htm", ".cshtml", ".tmpl" ],
"type": "code"
},
This sets the scope for the patterns in AppInspector/rules/default; e.g.,
{
"name": "Content Management Framework: Wordpress",
"id": "AI021200",
"description": "Development Framework: Wordpress",
"applies_to": [ "javascript", "html" ],
"tags": [ "Framework.CMS.Wordpress" ],
"severity": "moderate",
"patterns": [
{
"pattern": "wordpress",
"type": "string",
"scopes": [ "code", "comment" ],
"modifiers": [ "i" ],
"confidence": "high"
}
]
},
This seems like it would be prone to a lot of false positives, but I haven't tried the tool.