wp-includes/class-wp-session-tokens.php:70Hashes the given session token for storage.
$tokenstringstring private function hash_token( $token ) { // If ext/hash is not present, use sha1() instead. if ( function_exists( 'hash' ) ) { return hash( 'sha256', $token ); } else { return sha1( $token ); } }Introduced in 4.0.0. Unchanged from 6.7.7 through 7.1.0.
Signature, return type and hooks compared across 5 parsed releases.
src/wp-includes/class-wp-session-tokens.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it.