{"id":2714,"date":"2026-10-09T03:50:12","date_gmt":"2026-10-09T10:50:12","guid":{"rendered":"https:\/\/www.five.reviews\/?p=2714"},"modified":"2026-10-09T03:50:13","modified_gmt":"2026-10-09T10:50:13","slug":"anthropic-oss-scanner","status":"publish","type":"post","link":"https:\/\/www.five.reviews\/ai-tools\/anthropic-oss-scanner\/","title":{"rendered":"Anthropic OSS Scanner: How AI-Powered Code Security Works"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Open-source software runs under a large share of modern applications, from web servers to cryptographic libraries. The maintainers who keep these projects healthy often have limited time to find, verify, and patch security flaws. Anthropic OSS Scanner is a new opt-in service that uses Anthropic\u2019s strongest models to scan eligible open-source projects for vulnerabilities at no cost.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The service launched on October 8, 2026. Anthropic says its models have found far more candidate vulnerabilities than its human reviewers can triage, so it added an optional fast track for maintainers who want reports before human review.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This guide covers how the scanner works, what its reports contain, what Anthropic has reported about accuracy, who can enroll, how to set up a project, and where the service\u2019s limits lie.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Quick Summary: What You Need to Know<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>OSS Scanner is an opt-in service that periodically scans enrolled open-source projects using Anthropic\u2019s strongest models, including <a href=\"https:\/\/www.five.reviews\/ai-tools\/claude-mythos-5-1-vs-fable-5-1\/\" target=\"_blank\" rel=\"noreferrer noopener\">Claude Mythos<\/a>.<\/li>\n\n\n\n<li>It is designed for core maintainers of established projects with critical impact on infrastructure and user security.<\/li>\n\n\n\n<li>It is free for accepted projects, and Anthropic says it covers the full cost.<\/li>\n\n\n\n<li>Reports are fully model-generated and delivered without human review, so they can include false positives, duplicates, and inaccurate severity ratings.<\/li>\n\n\n\n<li>Maintainers enroll by submitting a pull request that adds a configuration file to Anthropic\u2019s GitHub repository. Anthropic manually verifies core maintainer status.<\/li>\n\n\n\n<li>The most important limitation is that every report must be validated before maintainers act on it.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What Is Anthropic OSS Scanner?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.anthropic.com\/research\/launching-opt-in-vuln-finding-service-for-open-source\" target=\"_blank\" rel=\"noreferrer noopener\">Anthropic OSS Scanner<\/a> is an opt-in vulnerability-scanning service for open-source software. Enrolled projects receive thorough, periodic security scans from Anthropic\u2019s strongest models at no cost. The service draws on Anthropic\u2019s experience using Claude to find vulnerabilities during Project Glasswing, its broader cybersecurity initiative.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic describes the service as inspired by Google\u2019s OSS-Fuzz, which uses fuzzers to scan open-source code. OSS Scanner relies on language-model agents instead. It is not a code editor or an <a href=\"https:\/\/www.five.reviews\/ai-tools\/best-ai-coding-assistants\/\" target=\"_blank\" rel=\"noreferrer noopener\">AI coding assistant<\/a>. Its purpose is to surface security issues before attackers find them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The fast track responds to a bottleneck Anthropic describes. Over six months, its models produced more than 29,000 candidate vulnerabilities, but its team had manually reviewed and triaged about 6,000. Some maintainers asked for unverified reports directly, so Anthropic created an optional path for them. Its standard coordinated vulnerability disclosure (CVD) process, which relies on human-verified reports, continues alongside it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How Does Anthropic OSS Scanner Work?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic describes a multi-stage pipeline. The steps below follow its published documentation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. Project Enrollment and Configuration<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A core maintainer opens a pull request to Anthropic\u2019s oss-scanner repository that adds a configuration file at projects\/&lt;project&gt;\/project.yaml. Anthropic manually verifies each applicant before enrolling a project.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. Build Environment Preparation<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The project\u2019s Dockerfile installs dependencies and builds the software before the audit begins. The Dockerfile itself is built with network access, but the audit runs without internet access. Anthropic recommends confirming that the project\u2019s tests pass inside the built container.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. AI-Powered Vulnerability Detection<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic\u2019s strongest models, including Claude Mythos, inspect the code as agents running in <a href=\"https:\/\/www.five.reviews\/ai-tools\/ai-sandbox-escape\/\" target=\"_blank\" rel=\"noreferrer noopener\">hardened sandboxes<\/a> with internet access disabled. Anthropic says it uses a variety of harnesses and techniques, including more resource-intensive experimental ones for deeper bugs. It has not published detailed implementation specifics, so those should not be assumed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4. Cross-Checking and Root-Cause Analysis<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">According to Anthropic, the pipeline includes agents that double-check suspected bugs, propose patches, and perform root-cause analysis. Where possible, reports also identify when a bug was introduced. This checking is automated. It does not mean a person has reviewed the finding.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>5. Vulnerability Reports and Candidate Patches<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Maintainers receive a bundle of bug reports by email. According to Anthropic, each report contains an explanation of the vulnerability, a self-contained reproducer, an introduction-point analysis where available, and a candidate patch when one is available. A candidate patch is a proposal, not a verified or production-ready fix. Anthropic says the delivery format may change later.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>6. Periodic Rescanning<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After the first scan, Anthropic regularly rescans enrolled projects for newly introduced vulnerabilities and issues earlier scans may have missed. It does not publish a fixed interval, saying frequency may depend on pipeline capacity, how widely a project is used, and other factors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The workflow runs as follows: Enroll project, prepare build environment, run AI security audit, generate findings, deliver reports, verify and remediate. Anthropic\u2019s pipeline ends at delivery. Verification and remediation remain the maintainer\u2019s responsibility.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How Accurate Is Anthropic OSS Scanner?<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Anthropic\u2019s Initial Validation Results<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic evaluated an early version of the scanner. Expert penetration testers who review its CVD findings checked 97 critical- and high-severity vulnerabilities across 48 projects. Of these, 85 (about 88%) met the bar for Anthropic\u2019s CVD process. Of the remaining 12, 11 were real but duplicated known issues or other findings from the same scan, and one was a false positive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic also reports that maintainers have seldom described high or critical findings as invalid. Some said severity ratings were inflated or that the scanner misread their threat model.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What the 88% Result Actually Means<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This figure comes from one company-run evaluation of an early version. It covers a selected set of critical and high-severity findings. It is not an independent benchmark, a universal accuracy rate, or a guarantee of future performance. Anthropic itself says it cannot guarantee the scanner will be perfect.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Maintainer feedback in the launch post is also self-reported. One maintainer, quoted by Anthropic, said that 74 reports were received, all but two were valid, and five became CVEs.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What Maintainers Should Verify<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Maintainers should reproduce the reported behavior in a controlled environment and confirm that it affects their actual version and configuration. They should assess exploitability and severity against their own threat model, check for duplicates and existing fixes, and review any candidate patch with regression tests before merging. A well-written report is not proof of a vulnerability, so engineering judgment still applies.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Who Can Use Anthropic OSS Scanner?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic says it uses criteria similar to OSS-Fuzz\u2019s. The service is intended for established projects with critical impact on infrastructure and user security. Its FAQ highlights two factors: exposure to remote attacks, such as libraries that process untrusted input, and the number of users and projects that depend on the software. Each application is reviewed case by case, and Anthropic may adjust the criteria over time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Enrollment is not guaranteed. Anthropic encourages applicants to explain in a short sentence why their project matters if that is not already obvious.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The service is not suited to every project. Anthropic says it is built for projects that can already keep up with verified high and critical vulnerability reports and want additional coverage. Maintainers who are already overwhelmed may prefer human-verified CVD reports.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Best for:<\/strong> established, security-critical projects with active core maintainers and a workable triage process.<br><strong>Less suitable for:<\/strong> projects that cannot review incoming findings promptly or do not meet the eligibility criteria.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How to Set Up Anthropic OSS Scanner<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">These steps follow Anthropic\u2019s current repository template and FAQ. Check both before submitting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Step 1: Review the repository.<\/strong> Start at github.com\/anthropics\/oss-scanner and copy the template at templates\/project.yaml to projects\/&lt;project&gt;\/project.yaml.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Step 2: Complete the required fields.<\/strong> The repo field is the git repository to clone, optionally pinned to a branch or tag. The primary_contact field is the email address that receives reports and project communication. The dockerfile field gives the repository-relative path to your Dockerfile. You can omit this field and instead place a Dockerfile next to your project.yaml in the OSS Scanner repository. The template uses the lowercase key dockerfile, while the FAQ prose writes \u201cDockerfile,\u201d so use the key exactly as the template shows it and confirm it with the validation script.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Step 3: Add optional fields as needed.<\/strong> These include auto_ccs for additional recipients, homepage, pgp for encrypted report emails (which cannot be combined with auto_ccs), and disabled. Anthropic strongly recommends a threat model file, which has no required format. It can describe the code in scope, which inputs are adversarial, what to ignore, a severity rubric, report formatting, patch preferences, and deduplication guidance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Step 4: Prepare and test the build.<\/strong> Write the Dockerfile so it installs all dependencies and builds the project. Confirm the test suite passes inside the container.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Step 5: Validate and submit.<\/strong> Run the tools\/validate.py script on your configuration, build the Dockerfile locally, and open the pull request. Anthropic verifies core maintainer status, decides on enrollment, and attempts its own build after acceptance. It will email if the build fails.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Step 6: Manage participation.<\/strong> Reply to report emails to give feedback, or email oss-scanner-questions@anthropic.com if you are not enrolled. To pause reports, submit a pull request adding disabled: true. To leave entirely, submit a pull request deleting your projects\/&lt;project&gt;\/ directory. Anthropic also invites a commit-message credit with the report ID, though it is not required.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Signing up means agreeing to Anthropic\u2019s OSS Scanner terms and conditions, which you should read before enrolling. The official FAQ is at red.anthropic.com\/oss-scanner.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Anthropic OSS Scanner vs. Claude Security vs. OSS-Fuzz<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Feature<\/strong><\/td><td><strong>Anthropic OSS Scanner<\/strong><\/td><td><strong>Claude Security<\/strong><\/td><td><strong>OSS-Fuzz<\/strong><\/td><\/tr><tr><td>Primary purpose<\/td><td>AI-based vulnerability scanning for enrolled open-source projects<\/td><td>Finding and fixing vulnerabilities in source code<\/td><td>Automated fuzz testing for open-source software<\/td><\/tr><tr><td>Main audience<\/td><td>Eligible open-source core maintainers<\/td><td>Enterprise users<\/td><td>Eligible open-source projects<\/td><\/tr><tr><td>Cost<\/td><td>Free for accepted projects<\/td><td>Commercial product; check current terms<\/td><td>Verify current terms with the project<\/td><\/tr><tr><td>Main approach<\/td><td>Model-based agents producing reports and candidate patches<\/td><td>AI-assisted discovery and remediation<\/td><td>Fuzzing<\/td><\/tr><tr><td>Human review<\/td><td>Reports delivered without human review or triage<\/td><td>Not specified in the sources reviewed<\/td><td>Project maintainers triage findings<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">These approaches complement one another and are not interchangeable. AI analysis does not replace fuzz testing, manual security review, or a coordinated disclosure process.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Benefits and Limitations of Anthropic OSS Scanner<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Potential benefits:<\/strong> no-cost scanning for accepted projects, access to advanced Claude-based vulnerability research, reports with reproducers and sometimes candidate patches, faster access to findings, and periodic rescanning.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Important limitations:<\/strong> reports are not reviewed by humans before delivery, false positives and duplicates remain possible, severity ratings can be wrong, maintainers need capacity to investigate and fix issues, eligibility is selective, candidate patches require testing, and future service details may change. The scanner should complement a broader security program, not replace it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Security and Disclosure Considerations<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Unreviewed reports differ from Anthropic\u2019s standard CVD process, where findings are human-verified before disclosure. Anthropic states that it will not apply a 90-day coordinated disclosure period to unvalidated OSS Scanner findings. If a finding is later validated through its CVD program, disclosure may follow that program\u2019s timeline, starting 90 days after the maintainer is notified that a human has validated the report. Anthropic says it may impose disclosure periods on some high-severity reports in the future, with notice and an opt-out option.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic states that reports are held in an isolated, locked-down cloud project accessible only to security staff who need it, and that scanning agents run only in sandboxes with internet access disabled. Its documentation does not address other questions about data use, so review the terms before enrolling. Teams should limit access to vulnerability details and test any patch before deployment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Best Practices for Using AI-Generated Vulnerability Reports<\/strong><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Assign a security contact to receive and triage reports.<\/li>\n\n\n\n<li>Prioritize critical and high-severity findings, but validate their impact independently.<\/li>\n\n\n\n<li>Reproduce issues in a controlled development environment.<\/li>\n\n\n\n<li>Review candidate patches rather than merging them automatically.<\/li>\n\n\n\n<li>Run regression and relevant security tests.<\/li>\n\n\n\n<li>Track duplicates and confirmed findings in your issue or vulnerability system.<\/li>\n\n\n\n<li>Document remediation decisions and communicate responsibly with affected users.<\/li>\n\n\n\n<li>Keep complementary controls such as code review, dependency updates, and fuzz testing.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Consider a hypothetical maintainer who receives a report about a possible input-validation flaw in a parser. The maintainer reproduces the input in a test build, confirms that it crashes the affected version but not the latest release, checks the candidate patch against the existing test suite, and adds a regression test before releasing a fix. This scenario is illustrative, not a real OSS Scanner finding.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Final Verdict<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic OSS Scanner offers free, periodic AI-driven security scans for established open-source projects that meet its criteria. Its reports can include reproducers and candidate patches, which can speed up investigation. Its reports are unreviewed, however, so maintainers must reproduce, verify, and test every finding before acting. Maintainers with active triage capacity and security-critical projects are best positioned to benefit. Before enrolling, read the official FAQ, the eligibility criteria, the terms and conditions, and the repository template.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Frequently Asked Questions<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What is Anthropic OSS Scanner?<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic OSS Scanner is an opt-in service that scans enrolled open-source projects for security vulnerabilities using Anthropic\u2019s strongest models. Accepted projects receive periodic scans and reports at no cost. Reports are generated without human triage before delivery.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Is Anthropic OSS Scanner free?<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Yes, for accepted projects. Anthropic says it covers the full cost. Enrollment is selective and decided case by case.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How does Anthropic OSS Scanner work?<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Maintainers enroll through a pull request, and Anthropic prepares the project\u2019s build environment. Model-based agents then audit the code offline, cross-check suspected bugs, and deliver reports with reproducers and sometimes candidate patches.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How can I enroll a project in Anthropic OSS Scanner?<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Core maintainers open a pull request to Anthropic\u2019s oss-scanner repository adding a project.YAML file based on the template. The file requires a repository, a primary contact, and a Dockerfile path. Anthropic verifies maintainer status before accepting.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Which Claude models power OSS Scanner?<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic says the service uses its strongest models, and that its reports are generated by them, including Claude Mythos. Anthropic does not publish a more specific model breakdown.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Does Anthropic OSS Scanner automatically fix vulnerabilities?<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. It can provide candidate patches, but those are proposals. Maintainers must review, test, and decide whether to merge them.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Are Anthropic OSS Scanner reports reviewed by humans?<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. Anthropic states that the outputs are fully model-generated and delivered without human review or triage. Maintainers must validate every report before acting on it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How often does Anthropic OSS Scanner scan a project?<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After the first scan, Anthropic rescans projects periodically. It does not publish a fixed interval, and frequency may depend on pipeline capacity and other factors.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Can every open-source project use Anthropic OSS Scanner?<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. Projects must be established, have critical impact on infrastructure or user security, and have a core maintainer who is verified. Anthropic decides each application case by case.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How is OSS Scanner different from Claude Security and OSS-Fuzz?<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">OSS Scanner is a free, model-based scanning service for eligible open-source projects. Claude Security is a commercial enterprise product for finding and fixing code vulnerabilities. OSS-Fuzz is Google\u2019s fuzz-testing project for open-source software.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Open-source software runs under a large share of modern applications, from web servers to cryptographic libraries. The maintainers who keep these projects healthy often [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":2716,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2],"tags":[1142,511,156,1145,1151,1147,1143,1152,1150,1141,1146,1149,1148,1144,1140],"content_cluster":[3],"content_type":[18],"search_intent":[24],"tool_category":[28],"class_list":["post-2714","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-tools","tag-ai-code-security","tag-ai-cybersecurity","tag-anthropic","tag-anthropic-oss-scanner","tag-application-security","tag-claude-mythos","tag-claude-security","tag-coordinated-vulnerability-disclosure","tag-devsecops","tag-open-source-security","tag-oss-fuzz","tag-security-vulnerability-reports","tag-software-security","tag-vulnerability-detection","tag-vulnerability-scanning","content_cluster-ai-tools","content_type-in-depth-review","search_intent-informational","tool_category-ai-writing"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.five.reviews\/?rest_route=\/wp\/v2\/posts\/2714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.five.reviews\/?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.five.reviews\/?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.five.reviews\/?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.five.reviews\/?rest_route=%2Fwp%2Fv2%2Fcomments&post=2714"}],"version-history":[{"count":1,"href":"https:\/\/www.five.reviews\/?rest_route=\/wp\/v2\/posts\/2714\/revisions"}],"predecessor-version":[{"id":2717,"href":"https:\/\/www.five.reviews\/?rest_route=\/wp\/v2\/posts\/2714\/revisions\/2717"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.five.reviews\/?rest_route=\/wp\/v2\/media\/2716"}],"wp:attachment":[{"href":"https:\/\/www.five.reviews\/?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.five.reviews\/?rest_route=%2Fwp%2Fv2%2Fcategories&post=2714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.five.reviews\/?rest_route=%2Fwp%2Fv2%2Ftags&post=2714"},{"taxonomy":"content_cluster","embeddable":true,"href":"https:\/\/www.five.reviews\/?rest_route=%2Fwp%2Fv2%2Fcontent_cluster&post=2714"},{"taxonomy":"content_type","embeddable":true,"href":"https:\/\/www.five.reviews\/?rest_route=%2Fwp%2Fv2%2Fcontent_type&post=2714"},{"taxonomy":"search_intent","embeddable":true,"href":"https:\/\/www.five.reviews\/?rest_route=%2Fwp%2Fv2%2Fsearch_intent&post=2714"},{"taxonomy":"tool_category","embeddable":true,"href":"https:\/\/www.five.reviews\/?rest_route=%2Fwp%2Fv2%2Ftool_category&post=2714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}