F. H. Shezan, Zihao Su, Ming-Zhi Kang, Nicholas Phair, Patrick William Thomas, Michelangelo van Dam, Yinzhi Cao, Yuan Tian
{"title":"CHKPLUG: Checking GDPR Compliance of WordPress Plugins via Cross-language Code Property Graph","authors":"F. H. Shezan, Zihao Su, Ming-Zhi Kang, Nicholas Phair, Patrick William Thomas, Michelangelo van Dam, Yinzhi Cao, Yuan Tian","doi":"10.14722/ndss.2023.24610","DOIUrl":null,"url":null,"abstract":"plugins. Our evaluation shows that C HK P LUG achieves good performance with 98.8% TNR (True Negative Rate) and 89.3% TPR (True Positive Rate) in checking whether a certain WordPress plugin complies with GDPR. To investigate the current surface of the marketplace, we perform a measurement analysis which shows that 368 plugins violate data deletion regulations, meaning plugins do not provide any functionalities to erase user information from the website.","PeriodicalId":199733,"journal":{"name":"Proceedings 2023 Network and Distributed System Security Symposium","volume":"124 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings 2023 Network and Distributed System Security Symposium","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.14722/ndss.2023.24610","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
plugins. Our evaluation shows that C HK P LUG achieves good performance with 98.8% TNR (True Negative Rate) and 89.3% TPR (True Positive Rate) in checking whether a certain WordPress plugin complies with GDPR. To investigate the current surface of the marketplace, we perform a measurement analysis which shows that 368 plugins violate data deletion regulations, meaning plugins do not provide any functionalities to erase user information from the website.
插件。我们的评估显示,C HK P LUG在检查某个WordPress插件是否符合GDPR时,达到了98.8%的TNR (True Negative Rate)和89.3%的TPR (True Positive Rate)。为了调查当前市场的表面,我们进行了一项测量分析,结果显示368个插件违反了数据删除规定,这意味着插件不提供任何从网站上删除用户信息的功能。