[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5HKaVjgJa30sUNW_I4WtzpUz5wwot9-yfLBWsw_TTxg":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":10,"trust_score":11,"computed_at":12,"plugins":13},"kodlo","Kodlo","https:\u002F\u002Fprofiles.wordpress.org\u002Fkodlo\u002F",2,10,100,30,94,"2026-08-28T23:45:48.418Z",[14,36],{"slug":15,"name":16,"version":17,"author":5,"author_profile":6,"description":18,"short_description":19,"active_installs":8,"downloaded":20,"rating":21,"num_ratings":21,"last_updated":22,"tested_up_to":23,"requires_at_least":24,"requires_php":25,"tags":26,"homepage":32,"download_link":33,"security_score":9,"vuln_count":21,"unpatched_count":21,"last_vuln_date":34,"fetched_at":35},"kodlo-media-manager","Kodlo Media Manager","1.8.6","\u003Cp>\u003Cstrong>Turn your Media Library requirements into clear, consistent upload rules.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Kodlo Media Manager adds a focused rules builder to \u003Cstrong>Settings -> Media\u003C\u002Fstrong>. Define which formats WordPress may accept, where each format is allowed, how large an upload may be, which image dimensions are acceptable, and how filenames should be formatted.\u003C\u002Fp>\n\u003Cp>The plugin validates uploads on the server and provides early feedback in the standard WordPress media uploader. It uses native WordPress, PHP, and browser APIs and includes no third-party libraries or external services.\u003C\u002Fp>\n\u003Ch3>Why Use Kodlo Media Manager?\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Keep upload standards consistent:\u003C\u002Fstrong> Replace written instructions with rules WordPress can enforce for supported upload flows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Control each format separately:\u003C\u002Fstrong> Give SVG, WebP, AVIF, video, document, font, and archive formats their own policy and limits.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reduce duplicate filename clutter:\u003C\u002Fstrong> Optionally block an exact normalized filename when it already exists in the Media Library.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Normalize filenames:\u003C\u002Fstrong> Mirror WordPress locale-aware accent conversion, transliterate supported Cyrillic characters, apply a predictable separator, and validate the final name.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Handle SVG locally:\u003C\u002Fstrong> Sanitize canonical \u003Ccode>.svg\u003C\u002Fcode> uploads with an internal allowlist before WordPress stores them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stay inside familiar WordPress screens:\u003C\u002Fstrong> Configure everything on the native Media Settings page and use the standard media uploader.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Upload Rules\u003C\u002Fh3>\n\u003Cp>Each rule combines a file extension and MIME type with one of three policies:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Allowed (Media Library Only):\u003C\u002Fstrong> Accept the format in verified WordPress Media Library upload contexts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Allowed (Globally):\u003C\u002Fstrong> Allow the format in other WordPress upload contexts as well.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocked (Globally):\u003C\u002Fstrong> Reject the format throughout WordPress upload handling.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>An administrator can also set a per-format maximum file size and, for raster images, maximum width and height. Dangerous executable and active-content formats remain unavailable even if they are submitted through malformed settings data.\u003C\u002Fp>\n\u003Ch3>Filename and Duplicate Controls\u003C\u002Fh3>\n\u003Cp>The filename validator accepts a bounded regular-expression subset shared by PHP and JavaScript. Unsupported, malformed, or excessive patterns fall back to the plugin’s safe default. Optional auto-sanitization can reshape filenames for compatible positive character-class patterns before validation; safe validation-only patterns remain available without automatic rewriting.\u003C\u002Fp>\n\u003Cp>Duplicate Guard compares exact normalized basenames rather than image contents. Every distinct filename is checked directly against Media Library attachment metadata. Short-lived hashed upload locks prevent two plugin-managed requests from claiming the same available filename at the same time, without building a filename index or custom database table.\u003C\u002Fp>\n\u003Ch3>SVG Handling\u003C\u002Fh3>\n\u003Cp>The internal SVG sanitizer accepts a limited set of SVG elements and attributes, removes unsupported content, rejects document types and entities, and permits only safe internal fragment references. It also applies a fixed payload ceiling before DOM parsing. SVG content must use the canonical \u003Ccode>.svg\u003C\u002Fcode> extension and \u003Ccode>image\u002Fsvg+xml\u003C\u002Fcode> MIME pair.\u003C\u002Fp>\n\u003Cp>SVG sanitization is a focused upload safeguard. It does not replace appropriate WordPress capabilities, server hardening, backups, or review of untrusted content.\u003C\u002Fp>\n\u003Ch3>Media Uploader Experience\u003C\u002Fh3>\n\u003Cp>The browser-side guard mirrors format, filename, size, dimension, and duplicate checks to provide feedback before an upload begins. Asynchronous dimension probes and duplicate lookups share one validation barrier, use bounded batches, concurrency, and timeouts, and finish before a paused queue resumes. Invalid or unavailable duplicate responses stop affected files and explain the failure. Server-side validation remains authoritative for native uploads and sideload-based REST uploads.\u003C\u002Fp>\n\u003Cp>Warning dialogs use native button semantics, labelled dialog markup, Escape handling, managed keyboard focus, and focus restoration. Settings controls include accessible names and predictable focus movement when rules are added or removed.\u003C\u002Fp>\n\u003Ch3>Default Configuration\u003C\u002Fh3>\n\u003Cp>The initial rules allow ZIP globally so WordPress can upload plugin and theme packages. SVG, WebP, AVIF, MP4, WebM, PDF, DOCX, and WOFF2 start in Media Library contexts with format-specific limits, while JPG, JPEG, and PNG start blocked. These defaults are a starting point, not a universal recommendation; review them for your site’s editorial workflow and hosting limits.\u003C\u002Fp>\n\u003Cp>By default, verified uploads initiated by an administrator from WordPress General Settings bypass format, filename, duplicate, size, and dimension policies so core settings such as the site icon are not unexpectedly blocked. SVG files are still sanitized. Enable \u003Cstrong>General Settings Page Uploads\u003C\u002Fstrong> to apply the configured policies there as well.\u003C\u002Fp>\n\u003Ch3>Security\u003C\u002Fh3>\n\u003Cp>Report a suspected vulnerability privately through the \u003Cstrong>Contact\u003C\u002Fstrong> button at \u003Ca href=\"https:\u002F\u002Fkodlo.dev\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fkodlo.dev\u002F\u003C\u002Fa>. Please include the affected plugin version, WordPress and PHP environment details, observed impact, reproducible steps, required privileges, and a minimal proof of concept.\u003C\u002Fp>\n\u003Cp>Do not include passwords, API keys, customer data, or other credentials. Do not publish exploit details in a support topic before the report can be assessed. Use the public support forum only for non-sensitive support questions.\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>Kodlo Media Manager operates locally and does not send upload data, filenames, settings, telemetry, or analytics to Kodlo or any other external service.\u003C\u002Fp>\n\u003Cp>The plugin stores its configuration in WordPress options. Duplicate Guard does not create a filename index or custom table. During an upload it may store a short-lived site option containing a filename hash, ownership token, and timestamp; the original filename is not stored in that lock.\u003C\u002Fp>\n\u003Cp>Deactivation preserves the plugin settings. Successful upload locks are removed immediately; an abandoned expired lock is reclaimed when the same filename is checked again.\u003C\u002Fp>\n","Set upload rules for file types, sizes, image dimensions, filenames, duplicate names, and SVG content in the WordPress Media Library.",627,0,"2026-07-20T13:24:00.000Z","7.0.2","6.6","8.1",[27,28,29,30,31],"file-upload","filename","image-sizes","media-library","svg","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fkodlo-media-manager.1.8.6.zip",null,"2026-07-22T17:31:50.256Z",{"slug":37,"name":38,"version":39,"author":5,"author_profile":6,"description":40,"short_description":41,"active_installs":21,"downloaded":42,"rating":21,"num_ratings":21,"last_updated":43,"tested_up_to":23,"requires_at_least":24,"requires_php":25,"tags":44,"homepage":32,"download_link":50,"security_score":9,"vuln_count":21,"unpatched_count":21,"last_vuln_date":34,"fetched_at":35},"kodlo-product-gallery-for-elementor","Kodlo Product Gallery for Elementor","2.9.1","\u003Cp>\u003Cstrong>Kodlo Product Gallery for Elementor\u003C\u002Fstrong> adds a WooCommerce-aware Elementor widget that can replace the standard WooCommerce product gallery inside product pages and product templates.\u003C\u002Fp>\n\u003Cp>Requires WooCommerce 9.0 or newer and Elementor 3.22 or newer. Elementor Free and Pro are supported; Elementor Pro is required only for Elementor features such as Theme Builder templates.\u003C\u002Fp>\n\u003Cp>Create a structured multi-column desktop grid and switch to a touch-friendly mobile slider at the selected Elementor breakpoint. Product images, videos, variation-specific galleries, captions, links, lightboxes, sale badges, thumbnails, pagination, navigation, image effects, and optional image loading attributes are managed from one widget.\u003C\u002Fp>\n\u003Cp>Kodlo reads the current WooCommerce product context on the frontend and uses an editor preview fallback when editing in Elementor. Gallery interactions use lightweight Vanilla JavaScript, with jQuery retained only for WooCommerce variation events. Frontend assets load through the widget dependency system, so base assets are requested only where the widget is used and optional magnifier or edge-bleed assets load only when those features are active on the frontend.\u003C\u002Fp>\n\u003Ch3>Built for Responsive Product Presentation\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Desktop Product Grid\u003C\u002Fstrong> – Choose from 1 to 10 columns, control gaps and image limits, hide the featured image, randomize image order, or stretch the first or last unmatched grid item across all columns.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Mobile Swiper Gallery\u003C\u002Fstrong> – Use a main image slider, optional thumbnail carousel, infinite loop, configurable thumbnail count and gap, navigation arrows, and a limited sliding pagination window.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Optional Swipe Edge Bleed\u003C\u002Fstrong> – Preserve the mobile content gutter at rest, reveal slides through that gutter while dragging, and clip them at the screen edge. Configure the gutter and anchor navigation arrows to either the content edge or screen edge.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stable Thumbnail First Paint\u003C\u002Fstrong> – The initial thumbnail row is laid out before Swiper initializes, reducing the full-width thumbnail flash and associated layout movement on mobile devices.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Product Media That Goes Beyond Images\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>YouTube, Vimeo, and MP4 Video\u003C\u002Fstrong> – Add a Video URL directly to an image in the WordPress Media Library. The image remains the poster and thumbnail while the gallery provides inline playback.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Focused Video Playback\u003C\u002Fstrong> – Configure desktop\u002Fmobile autoplay, mute and loop behavior while keeping playback centered on the custom Elementor Play button. Native and provider control bars stay hidden; non-loop videos restore the poster and Play button when playback ends.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zoom and Magnifier Effects\u003C\u002Fstrong> – Select None, Zoom, or Magnifier independently for desktop and mobile. Configure zoom strength, lens size, border, radius, and the accessible mobile magnifier toggle.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Captions, Links, and Lightbox\u003C\u002Fstrong> – Display attachment captions, link images to media files or attachment pages, and use Elementor lightbox behavior.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sale Flash\u003C\u002Fstrong> – Display the WooCommerce sale badge in a preset or custom-styled position, with an optional link.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Variation Galleries Inside WooCommerce\u003C\u002Fh3>\n\u003Cp>Assign an ordered image gallery to each product variation from the standard WooCommerce variation editor. Images can be added, removed, reordered by drag and drop, or moved with accessible ordering controls.\u003C\u002Fp>\n\u003Cp>On the storefront, Kodlo supports both complete and partial variation matching. The gallery can respond as soon as a meaningful attribute such as color is selected. Payload fingerprints prevent unnecessary DOM and Swiper rebuilds when the effective visible gallery has not changed, reducing flicker between equivalent variations.\u003C\u002Fp>\n\u003Cp>Variation galleries can be enabled or disabled for the widget as a whole, while desktop and mobile views each keep their own maximum image limit.\u003C\u002Fp>\n\u003Ch3>Styling in Elementor\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Independent desktop, mobile, thumbnail, pagination, navigation, caption, sale badge, video, zoom, and magnifier controls.\u003C\u002Fli>\n\u003Cli>Aspect-ratio and object-fit presets for desktop images, mobile images, thumbnails, and stretched grid items.\u003C\u002Fli>\n\u003Cli>Normal, hover, and active states for borders, colors, backgrounds, opacity, and radius where applicable.\u003C\u002Fli>\n\u003Cli>Elementor icon library support for navigation, video, and mobile magnifier controls.\u003C\u002Fli>\n\u003Cli>Elementor Global Color-compatible color controls.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Performance and Accessibility Foundations\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Uses native image dimensions, \u003Ccode>srcset\u003C\u002Fcode>, and \u003Ccode>sizes\u003C\u002Fcode> attachment data to reserve media space.\u003C\u002Fli>\n\u003Cli>Includes an optional Image Loading Optimization control, disabled by default, for setting per-context priority image counts in the desktop grid, mobile slider, and mobile thumbnails.\u003C\u002Fli>\n\u003Cli>When enabled, priority images receive \u003Ccode>fetchpriority=\"high\"\u003C\u002Fcode> and \u003Ccode>decoding=\"async\"\u003C\u002Fcode>; remaining rendered images receive \u003Ccode>loading=\"lazy\"\u003C\u002Fcode> and \u003Ccode>decoding=\"async\"\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>Skips variation gallery rebuilds when the visible image payload is unchanged.\u003C\u002Fli>\n\u003Cli>Deduplicates variation media metadata in the page payload and primes attachment caches before validation.\u003C\u002Fli>\n\u003Cli>Cleans up disconnected Swiper instances and scopes runtime state to each widget.\u003C\u002Fli>\n\u003Cli>Loads Swiper only when the mobile gallery is enabled and limits Media Views assets to relevant admin screens.\u003C\u002Fli>\n\u003Cli>Includes semantic buttons, localized keyboard-operable navigation controls, visible \u003Ccode>:focus-visible\u003C\u002Fcode> styles, descriptive video titles, active-thumbnail state, and hidden-state handling for limited pagination dots.\u003C\u002Fli>\n\u003Cli>Respects \u003Ccode>prefers-reduced-motion\u003C\u002Fcode> by disabling gallery transitions and automatic video playback where appropriate.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Accessibility depends on the complete page, theme, content, colors, and configuration. Kodlo provides accessibility-focused foundations but does not claim automatic compliance for every implementation.\u003C\u002Fp>\n\u003Ch3>WooGallery Compatibility\u003C\u002Fh3>\n\u003Cp>Kodlo includes an optional compatibility layer for WooGallery metadata. Activation safely revokes the previous notice generation, preserves any completed or interrupted progress, and checks only the exact \u003Ccode>wcgs_video\u003C\u002Fcode> and \u003Ccode>woo_gallery_slider\u003C\u002Fcode> keys on an authorized administrator request. If supported legacy data is available, Kodlo asks whether it should be migrated. Nothing is copied until a WooCommerce administrator explicitly selects \u003Cstrong>Migrate legacy data\u003C\u002Fstrong>. The migration freezes a per-key metadata snapshot and immediately processes protected 50-row AJAX batches on the current administration page while a progress notice remains visible. Public product views stay read-only. Every destination write is tied to the exact selected legacy row and shares an internal per-object lock with normal Kodlo metadata saves, so a newer or explicitly empty Kodlo value remains authoritative.\u003C\u002Fp>\n\u003Cp>During migration, the notice shows exact processed-row progress and asks the administrator not to reload or leave the page. Failed or repeatedly stalled batches stop automatic requests and expose a Retry button. When both jobs finish, the page automatically loads a completion notice with \u003Cstrong>Keep legacy data\u003C\u002Fstrong> as the safest default and \u003Cstrong>Delete safely migrated legacy data\u003C\u002Fstrong> as a separate explicit action. Both controls share one native WordPress action row. Safe cleanup uses the same visible protected batch runner, keeps an independent snapshot and cursor for each legacy key, and never crosses the corresponding completed migration boundary. It removes an unchanged legacy row only while its exact Kodlo destination still exists with the migrated value. Unsupported, unmatched, unmigrated, later-created, concurrently changed, or subsequently changed rows remain untouched.\u003C\u002Fp>\n\u003Ch3>SVG Safety\u003C\u002Fh3>\n\u003Cp>SVG attachments accepted by the standard WordPress and Elementor media workflow are supported like other image attachments, without an additional Kodlo-specific approval layer.\u003C\u002Fp>\n\u003Ch3>Security\u003C\u002Fh3>\n\u003Cp>Kodlo welcomes responsible security reports. If you believe you have found a vulnerability, report it privately through the \u003Cstrong>Contact\u003C\u002Fstrong> button at \u003Ca href=\"https:\u002F\u002Fkodlo.dev\u002F\" rel=\"nofollow ugc\">kodlo.dev\u003C\u002Fa>. Include every affected version you reproduced, WordPress\u002FPHP\u002FWooCommerce\u002FElementor and browser details, potential impact, reproducible steps, the required user role or privileges, and a minimal proof of concept. Do not send credentials, access tokens, customer data, or other personal data; redact sensitive values from logs and screenshots. Please avoid public disclosure until the report has been reviewed and coordinated disclosure can be arranged.\u003C\u002Fp>\n\u003Cp>Security fixes target the latest published version, so keeping the plugin up to date is recommended.\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>Kodlo Product Gallery for Elementor does not send gallery settings, product data, telemetry, or analytics to Kodlo. Attachment Video URLs and variation gallery image IDs are stored in WordPress post metadata, while Elementor stores the widget configuration in its normal document data.\u003C\u002Fp>\n\u003Cp>The optional WooGallery compatibility workflow stores consent, progress, and temporary lock state in WordPress options. It reads only the documented legacy metadata keys and does not copy or delete legacy values without the administrator actions described above.\u003C\u002Fp>\n\u003Cp>When a visitor starts a YouTube or Vimeo video, the browser loads the corresponding provider player. A direct MP4 URL is requested from the host named in that URL. Those external services may process visitor data under their own policies; site owners are responsible for selecting providers and configuring any required privacy notice or consent mechanism.\u003C\u002Fp>\n","Build WooCommerce product galleries in Elementor with desktop grids, mobile sliders, variation galleries, videos, zoom, and magnifier.",160,"2026-07-19T18:49:00.000Z",[45,46,47,48,49],"elementor","grid","product-gallery","slider","woocommerce","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fkodlo-product-gallery-for-elementor.2.9.1.zip"]