wp-includes/sodium_compat/src/Crypto32.php:405HMAC-SHA-512-256 validation. Constant-time via hash_equals().
$macstring$messagestring$keystringbool public static function auth_verify($mac, $message, $key) { return ParagonIE_Sodium_Core32_Util::hashEquals( $mac, self::auth($message, $key) ); }Unchanged from 6.7.7 through 7.1.0.
Signature, return type and hooks compared across 5 parsed releases.
src/wp-includes/sodium_compat/src/Crypto32.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it.