
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
@vue-wordpress/core
Advanced tools
đź’« Wordpress REST API plugin for Vue.js with out-of-box routing and data handling đź’«
Vue.js module for WordPress, PWA ready, with full support for Vuex Store, Vue Router, Vue SSR and Nuxt.js https://vuewordpress.io/
npm install @vue-wordpress/core
or
yarn add @vue-wordpress/core
main.js / main.ts file, import the module catalog and register it:
import Vue from 'vue'
import Wordpress from '@vue-wordpress/core'
Vue.use(Wordpress, {
config: {
url: 'https://your-wordpress-url.com/',
lang: 'en' // Your site's default language – It will be added to the html lang attribute.
},
store,
router
// Injecting VueX Store and Router is obligatory
})
If you want to use this module with Nuxt.js, we have created a dedicated package available here: @vue-wordpress/nuxt
If you want to use this module with Vue Storefront, we have created a dedicated package available here:
@vue-wordpress/vsf
FAQs
đź’« Wordpress REST API plugin for Vue.js with out-of-box routing and data handling đź’«
We found that @vue-wordpress/core demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.