Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
gha-lab-a7f6217d26 — Security-research reproduction of CVE-2026-27938 / GHSA-4q9f-mjxf-rx7x (GitHub Actions expression injection in release workflows) — snapshot of wp-graphql/wp-graphql at b216fe22f3a119f256511ec7353f536fee6886ac | Kitploit
Tools/GitHubGitHub/pvharmo2/gha-lab-a7f6217d26
Vulnerability AnalysisExploitationLearning & EducationCurated Resources
GitHubpvharmo2/gha-lab-a7f6217d26

gha-lab-a7f6217d26

Security-research reproduction of CVE-2026-27938 / GHSA-4q9f-mjxf-rx7x (GitHub Actions expression injection in release workflows) — snapshot of wp-graphql/wp-graphql at b216fe22f3a119f256511ec7353f536fee6886ac

View Repository
3h 56m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Automated research artifact — not the upstream project.

This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of wp-graphql/wp-graphql at commit b216fe22f3a119f256511ec7353f536fee6886ac (2026-02-20), redistributed under that project's own licence, whose file is included unchanged in this snapshot.

The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2026-02-20; see pinning.md in the harness output for every change made to the snapshot.

Questions or objections: [email protected]


WPGraphQL Logo

WPGraphQL Monorepo

Total Downloads

Monthly Downloads
Daily Downloads
Latest Stable Version
Testing Integration
WordPress Coding Standards
Schema Linter
GraphiQL E2E Tests
Code Quality
codecov

Unlock the power of WordPress data with GraphQL

WPGraphQL provides an extendable GraphQL API for any WordPress site, unlocking modern development workflows.

Whether you're a WordPress developer exploring GraphQL or a GraphQL expert diving into WordPress, WPGraphQL simplifies data interaction and empowers your development workflow.


📁 Repository Structure

This is a monorepo containing the WPGraphQL ecosystem of plugins and websites:

root@kitploit:~
wp-graphql/
├── plugins/
│   ├── wp-graphql/          # WPGraphQL core plugin
│   ├── wp-graphql-ide/      # IDE extension plugin
│   └── wp-graphql-smart-cache/ # Smart Cache extension plugin
├── websites/
│   └── wpgraphql.com/        # WPGraphQL.com Next.js website
├── .wp-env.json             # Shared WordPress environment config
├── package.json             # Root workspace configuration
└── turbo.json               # Turborepo build orchestration

For end users: Nothing changes! Install WPGraphQL from WordPress.org, Composer, or download the release zip.

For contributors: Clone the repo and run:

root@kitploit:~
npm install           # Install dependencies (uses workspaces)
npm run wp-env start  # Start WordPress environment with all plugins

📚 See the Development Guide for detailed setup instructions.


🎯 Vision

WPGraphQL aims to be the canonical GraphQL API for WordPress, providing:

  • A complete, flexible GraphQL schema for accessing WordPress data
  • Standards-based implementation following GraphQL and WordPress best practices
  • An extensible foundation for plugins to build upon
  • Production-ready performance suitable for high-traffic sites
  • Long-term stability with semantic versioning and backward compatibility

What Belongs in WPGraphQL Core?

In scope:

  • GraphQL schema for WordPress core features (posts, pages, users, taxonomies, etc.)
  • Performance optimizations that benefit all users
  • Developer APIs for extending the schema
  • Standards and patterns for the WPGraphQL ecosystem

Candidates for core (via Experiments):

  • Proposed features that need real-world validation before committing
  • Breaking changes that require community feedback
  • Performance improvements that need testing at scale
  • Learn more about Experiments →

Better as extensions:

  • Plugin-specific integrations (ACF, Yoast, WooCommerce, etc.)
  • Opinionated workflows or conventions
  • Features specific to particular frameworks or use cases

The difference: Experiments are potential core features being validated. Extensions are intentionally separate functionality that should remain as plugins. Experiments may graduate to core or be removed; extensions live independently forever.

This focus keeps WPGraphQL maintainable while enabling a rich ecosystem of extensions.


🚀 Get Started

  1. 📦 Install WPGraphQL: wp plugin install wp-graphql --activate
  2. 👩‍💻 Try it out: Live Demo
  3. 📖 Read the Quick Start Guide.
  4. 💬 Join the Community on Discord
  5. ⭐ Star the Repo on GitHub 😉

🌟 Key Features

  • Flexible API: Access posts, pages, custom post types, taxonomies, users, and more.
  • Extendable Schema: Easily add functionality with functions like register_graphql_field and register_graphql_connection.
    • Plugins like WPGraphQL Smart Cache, WPGraphQL for ACF and other extension plugins demonstrate the power of extendability.
  • Modern Framework Integration: Works seamlessly with Next.js, Svelte, Astro and other frameworks.
  • Optimized Performance: Query only the data you need. Collect multiple resources in one request, reducing round-trips. Use WPGraphQL Smart Cache for enhanced performance and network-level caching and cache-invalidation.
  • Developer Tools: Explore the schema with tools like the GraphiQL IDE and WordPress Playground.

graphiql-ide-example.gif


📖 Documentation

For Users:

  • Quick Start
  • Intro to GraphQL
  • Intro to WordPress
  • Extensions
  • Advanced Topics

For Contributors:

  • Development Setup - Local environment setup
  • Contributing Guide - How to contribute
  • Testing Guide - Running tests
  • Architecture - Codebase overview

🤝 Community Support

WPGraphQL is powered by a passionate community of contributors, backers, and sponsors.

Backers on Open Collective Sponsors on Open Collective

Want to help maintain and grow WPGraphQL?

  • Support the project on Open Collective
  • Join the Community on Discord
  • Contribute to the project on GitHub

🙌 Shout Outs

We extend our gratitude to the following projects and organizations for their contributions to the WordPress and GraphQL ecosystems:

  • Webonyx: For the amazing graphql-php library that powers WPGraphQL's core functionality.
  • Ivome: For the graphql-relay-php library used in relay connections.
  • Automattic: For supporting WPGraphQL's ongoing development as a canonical WordPress plugin.
  • Gatsby: For their contributions to the WPGraphQL ecosystem and support for headless WordPress development.
  • WPEngine: For funding early development of WPGraphQL and supporting its growth.
  • Facebook: For open-sourcing the GraphQL spec, GraphiQL, and maintaining the JavaScript reference implementation.
  • Apollo: For pushing GraphQL forward and inspiring schema design best practices.
  • The WordPress REST API Contributors: For paving the way with the WP-API project, inspiring WPGraphQL's architecture.

Thank you to all these organizations and individuals for their efforts in shaping the tools we rely on today.


🔌 Canonical Plugin

WPGraphQL is becoming a Canonical Plugin on WordPress.org, ensuring long-term support and a growing community of users and contributors.


🛠 Privacy & Telemetry

WPGraphQL uses the Appsero SDK to collect telemetry data only after user consent, helping us improve the plugin responsibly.

Download Tool