[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fD7r6neVhFdJ3NSVll3ki6mPNjL2xRDRgIZvEu0AejWk":3,"$faStnag4vkFUk2JOxUrOEdPc1YQ161GF8P6I3I5ujN9E":280,"$fQ2qRQM0OXNa4fa5RqxPtPxjqT3bWrhlROJIkL6O0Eu4":285},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29,"discovery_status":30,"vulnerabilities":31,"developer":32,"crawl_stats":28,"alternatives":36,"analysis":118,"fingerprints":261},"12-step-meeting-pdf-generator","12 Step Meeting PDF","1.0.4","cdtoews","https:\u002F\u002Fprofiles.wordpress.org\u002Fcdtoews\u002F","\u003Cp>If you use the ’12 Step Meeting List’ plugin, this plugin will help with printing\u003Cbr \u002F>\nmeeting lists. I created this plugin to help my own group, and decided to\u003Cbr \u002F>\nmake the plugin publicly available. You can choose the page size and orientation.\u003Cbr \u002F>\nYou can use the column layout that we use, or I have added the nyintergroup\u003Cbr \u002F>\nformat that meeting-guide made: https:\u002F\u002Fgithub.com\u002Fmeeting-guide\u002Fnyintergroup\u003Cbr \u002F>\nEventually other formats will become available. Let me know if you have\u003Cbr \u002F>\nspecific format requests.\u003C\u002Fp>\n\u003Cp>Source Code: https:\u002F\u002Fgithub.com\u002Fcdtoews\u002F12-step-meeting-pdf\u003C\u002Fp>\n","This plugin requires '12 Step Meeting List', and allows creation of meeting list PDF",100,9408,1,"2023-08-30T17:23:00.000Z","6.3.8","4.7","",[19,20,21,22,23],"12-step-meeting","12-step-meeting-list","12-step-meetings","12-step","meeting-list","https:\u002F\u002Fgithub.com\u002Fcdtoews\u002F12-step-meeting-pdf","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.zip",85,0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":13,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},30,84,"2026-08-29T13:45:55.763Z",[37,57,70,86,103],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":27,"num_ratings":27,"last_updated":47,"tested_up_to":48,"requires_at_least":49,"requires_php":50,"tags":51,"homepage":55,"download_link":56,"security_score":11,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"bread","Bread","2.10.4","radius314","https:\u002F\u002Fprofiles.wordpress.org\u002Fradius314\u002F","\u003Cp>“bread” is a fork of the BMLT meeting list generator.  It allows for the creation of a meeting schedule from a BMLT server.\u003C\u002Fp>\n","A web-based tool that creates, maintains and generates a PDF meeting list from BMLT.",300,20462,"2026-07-11T16:11:00.000Z","7.0.2","6.2","8.1",[52,23,53,54],"bmlt","na","narcotics-anonymous","https:\u002F\u002Fbmlt.app","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbread.2.10.4.zip",{"slug":58,"name":58,"version":59,"author":41,"author_profile":42,"description":60,"short_description":61,"active_installs":45,"downloaded":62,"rating":11,"num_ratings":13,"last_updated":63,"tested_up_to":48,"requires_at_least":64,"requires_php":65,"tags":66,"homepage":68,"download_link":69,"security_score":11,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"crouton","4.2.0","\u003Cp>Crouton provides a UI for viewing recovery meetings stored in a Basic Meeting List Toolbox (BMLT) database.  Simply put a shortcode on a WordPress page to get an interactive display list of meetings.\u003Cbr \u002F>\nThis plugin provides shortcodes to view the meetings as a table, a map or insert the number of meetings and groups in specified service bodies.  Configure Crouton from the WordPress backend, using attributes in the shortcode or using query string parameters.  The admin UI contains detailed instructions.\u003C\u002Fp>\n","crouton provides a UI and more for view recovery meetings as stored in a Basic Meeting List Toolbox (BMLT) database.",37511,"2026-07-17T12:29:00.000Z","4.0","8.0",[52,23,54,67],"recovery","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcrouton\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcrouton.4.2.0.zip",{"slug":71,"name":72,"version":73,"author":74,"author_profile":75,"description":76,"short_description":77,"active_installs":11,"downloaded":78,"rating":11,"num_ratings":13,"last_updated":79,"tested_up_to":80,"requires_at_least":49,"requires_php":50,"tags":81,"homepage":55,"download_link":83,"security_score":84,"vuln_count":13,"unpatched_count":27,"last_vuln_date":85,"fetched_at":29},"bmlt-wordpress-satellite-plugin","BMLT WordPress Satellite","3.11.6","BMLTGuy","https:\u002F\u002Fprofiles.wordpress.org\u002Fmagblogapi\u002F","\u003Cp>The \u003Ca href=\"https:\u002F\u002Fbmlt.app\" rel=\"nofollow ugc\">Basic Meeting List Toolbox (BMLT)\u003C\u002Fa> is a powerful client\u002Fserver system for locating NA meetings.\u003Cbr \u002F>\nThe “root server” is a standalone Website, but “satellite servers” are set up to point to the “root.” This is a “satellite,” set up as a WordPress plugin.\u003Cbr \u002F>\nIt is very easy to install and use. It has an administration panel that lets you choose a map center, designate the root, set up the map zoom, and whether older browsers are supported.\u003C\u002Fp>\n","This is a \"satellite\" plugin for the Basic Meeting List Toolbox (BMLT).",13514,"2026-03-20T21:40:00.000Z","6.9.5",[52,82,23,53,67],"meeting-finder","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbmlt-wordpress-satellite-plugin.3.11.6.zip",99,"2025-12-11 14:28:25",{"slug":87,"name":88,"version":89,"author":90,"author_profile":91,"description":92,"short_description":93,"active_installs":94,"downloaded":95,"rating":27,"num_ratings":27,"last_updated":96,"tested_up_to":97,"requires_at_least":17,"requires_php":65,"tags":98,"homepage":101,"download_link":102,"security_score":11,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"list-locations-bmlt","List Locations BMLT","2.4.0","pjaudiomv","https:\u002F\u002Fprofiles.wordpress.org\u002Fpjaudiomv\u002F","\u003Cp>List Locations BMLT is a plugin that returns all unique towns or counties from your BMLT server for a given service body on your site.\u003C\u002Fp>\n\u003Cp>SHORTCODE\u003Cbr \u002F>\nBasic: [list_locations]\u003Cbr \u002F>\nAttributes: root_server, services, recursive, state, delimiter, list, state_skip, city_skip\u003C\u002Fp>\n\u003Cp>— Shortcode parameters can be combined\u003C\u002Fp>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Cp>A minimum of root_server and services attribute are required, which would return all towns for that service body seperated by a comma.\u003C\u002Fp>\n\u003Cp>Ex. [list_locations root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Recursive:\u003C\u002Fstrong> to recurse service bodies add recursive=\"1\"\u003Cbr \u002F>\nEx. [list_locations root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50\" recursive=\"1\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>State:\u003C\u002Fstrong> to remove appending of the state add state=\"0\"\u003Cbr \u002F>\nEx. [list_locations root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50\" state=\"0\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>State Skip:\u003C\u002Fstrong> to skip the inclusion of a state when using state=\"1\" add state_skip=\"NC\"\u003Cbr \u002F>\nEx. [list_locations root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50\" state=\"1\" state_skip=\"NC\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>City Skip\u003C\u002Fstrong> To skip the inclusion of a city add city_skip=\"Indianapolis\". This can be useful when mentioning a city out of order or in a different part of the text.\u003Cbr \u002F>\nEx. [list_locations root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50\" state=\"1\" city_skip=\"Indianapolis\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Services:\u003C\u002Fstrong> to add multiple service bodies just seperate by a comma.\u003Cbr \u002F>\nEx. [list_locations root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50,37,26\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Delimiter:\u003C\u002Fstrong> to change the delimiter to something besides a comma I would add delimiter=\" – \" or to create newlines between each I could do this delimiter=\"\u003Cbr>\", or delimiter=\"\u003Cp>\u003C\u002Fp>\"\u003Cbr \u002F>\nEx. [list_locations root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" delimiter=\"\u003Cbr>\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>List:\u003C\u002Fstrong> You can list by the following town, county, borough, neighborhood. The default is town.\u003Cbr \u002F>\nEx. [list_locations root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" list=\"town\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>custom_query\u003C\u002Fstrong> You can add a custom query from semantic api to filter results, for ex by format \u003Ccode>&formats=54\u003C\u002Fcode>.\u003Cbr \u002F>\nEx. [list_locations root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" custom_query=\"&formats=54\"]\u003C\u002Fp>\n\u003Ch3>EXAMPLES\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.crna.org\u002Farea-service-committees\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fwww.crna.org\u002Farea-service-committees\u002F\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fheartoflongislandna.org\" rel=\"nofollow ugc\">https:\u002F\u002Fheartoflongislandna.org\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Feanaonline.org\" rel=\"nofollow ugc\">https:\u002F\u002Feanaonline.org\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>MORE INFORMATION\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fbmlt-enabled\u002Flist-locations-bmlt\" rel=\"nofollow ugc\">https:\u002F\u002Fgithub.com\u002Fbmlt-enabled\u002Flist-locations-bmlt\u003C\u002Fa>\u003C\u002Fp>\n","List Locations BMLT is a plugin that returns all unique towns or counties from your BMLT server for a given service body on your site.",80,3322,"2025-09-12T22:24:00.000Z","6.8.6",[99,52,100,87,54],"basic-meeting-list-toolbox","list-locations","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Flist-locations-bmlt\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flist-locations-bmlt.2.4.0.zip",{"slug":104,"name":105,"version":106,"author":90,"author_profile":91,"description":107,"short_description":108,"active_installs":109,"downloaded":110,"rating":27,"num_ratings":27,"last_updated":111,"tested_up_to":112,"requires_at_least":64,"requires_php":65,"tags":113,"homepage":115,"download_link":116,"security_score":11,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":117},"upcoming-meetings-bmlt","Upcoming Meetings BMLT","1.6.0","\u003Cp>Upcoming Meetings BMLT is a plugin that displays the next ‘N’ number of meetings from the current time on your page or in a widget using the upcoming_meetings shortcode.\u003C\u002Fp>\n\u003Cp>SHORTCODE\u003Cbr \u002F>\nBasic: [upcoming_meetings]\u003Cbr \u002F>\nAttributes: root_server, services, recursive, grace_period, num_results, display_type, timezone, location_text, time_format, weekday_language, limit_to_today, custom_query\u003C\u002Fp>\n\u003Cp>Meeting Formats: [meeting_formats]\u003Cbr \u002F>\nAttributes: root_server, display_type, show_description, language\u003C\u002Fp>\n\u003Cp>— Shortcode parameters can be combined\u003C\u002Fp>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Cp>A minimum of root_server, and services attributes are required, which would return the next 5 meetings in simple view with a 15minute grace period.\u003C\u002Fp>\n\u003Cp>Ex. [upcoming_meetings root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>recursive\u003C\u002Fstrong> to recurse service bodies add recursive=\"1\"\u003Cbr \u002F>\nEx. [upcoming_meetings root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50\" recursive=\"1\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>services\u003C\u002Fstrong> to add multiple service bodies just seperate by a comma.\u003Cbr \u002F>\nEx. [upcoming_meetings root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50,37,26\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>grace_period\u003C\u002Fstrong> To add a grace period to meeting lookup add grace_period=\"15\" this would add a 15 minute grace period.\u003Cbr \u002F>\nEx. [upcoming_meetings root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50\" grace_period=\"15\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>num_results\u003C\u002Fstrong> To limit the number of results add num_results=\"5\" this would limit results to 5.\u003Cbr \u002F>\nEx. [upcoming_meetings root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50\" state=\"1\" num_results=\"5\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>display_type\u003C\u002Fstrong> To change the display type add display_type=\"table\" there are three different types \u003Cstrong>simple\u003C\u002Fstrong>, \u003Cstrong>table\u003C\u002Fstrong>, \u003Cstrong>block\u003C\u002Fstrong>\u003Cbr \u002F>\nEx. [upcoming_meetings root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" display_type=\"table\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>timezone\u003C\u002Fstrong> By default we use your WordPress sites timezone setting, this will overwrite that. add timezone=\"America\u002FNew_York\" you can set this in the admin setting or short code. A complete list of timezones can be found here http:\u002F\u002Fphp.net\u002Fmanual\u002Fen\u002Ftimezones.php\u003Cbr \u002F>\nEx. [upcoming_meetings root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" timezone=\"America\u002FNew_York\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>location_text\u003C\u002Fstrong> to display the location nam,e using the simple display add location_text=\"1\"\u003Cbr \u002F>\nEx. [upcoming_meetings root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50\" location_text=\"1\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>show_header\u003C\u002Fstrong> to display header info for Table\u002FBlock display add show_header=\"1\"\u003Cbr \u002F>\nEx. [upcoming_meetings root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50\" show_header=\"1\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>time_format\u003C\u002Fstrong> This allows you to be able to switch between 12 and 24 hour. the default is 12. To switch to 24 hour add time_format=\"24\"\u003Cbr \u002F>\nEx. [upcoming_meetings root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" time_format=\"24\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>weekday_language\u003C\u002Fstrong> This allows you to change the language of the weekday names. To change language to danish set weekday_language=\"dk\". Currently supported languages are da,de,en,es,fa,fr,it,pl,pt,ru,sv, the default is English.\u003Cbr \u002F>\nEx. [upcoming_meetings root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" weekday_language=\"dk\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>limit_to_today\u003C\u002Fstrong> To limit results to only today’s meetings (will not show tomorrow’s meetings even if there aren’t enough results) add limit_to_today=\"1\"\u003Cbr \u002F>\nEx. [upcoming_meetings root_server=\"https:\u002F\u002Fwww.domain.org\u002Fmain_server\" services=\"50\" limit_to_today=\"1\"]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>custom_query\u003C\u002Fstrong> You can add a custom query from semantic api to filter results, for ex by format \u003Ccode>&formats=54\u003C\u002Fcode>.\u003Cbr \u002F>\nEx. [upcoming_meetings root_server=”https:\u002F\u002Fwww.domain.org\u002Fmain_server” custom_query=”&formats=54″]\u003C\u002Fp>\n\u003Ch3>Meeting Formats Shortcode\u003C\u002Fh3>\n\u003Cp>The meeting_formats shortcode displays all available meeting formats from a BMLT root server.\u003C\u002Fp>\n\u003Cp>Basic: [meeting_formats]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>root_server\u003C\u002Fstrong> (optional) The BMLT root server URL. Uses plugin settings if not specified.\u003Cbr \u002F>\nEx. [meeting_formats root_server=”https:\u002F\u002Fbmlt.sezf.org\u002Fmain_server”]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>display_type\u003C\u002Fstrong> (optional, default: “table”) Options: “table” or “list”\u003Cbr \u002F>\nEx. [meeting_formats display_type=”list”]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>show_description\u003C\u002Fstrong> (optional, default: “1”) Show format descriptions. Options: “1” or “0”\u003Cbr \u002F>\nEx. [meeting_formats show_description=”0″]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>language\u003C\u002Fstrong> (optional, default: “en”) Language code for format names (en, es, fr, de, etc.)\u003Cbr \u002F>\nEx. [meeting_formats language=”es”]\u003C\u002Fp>\n\u003Ch3>EXAMPLES\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.southcoastalna.org\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fwww.southcoastalna.org\u002F\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>MORE INFORMATION\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fbmlt-enabled\u002Fupcoming-meetings-bmlt\" rel=\"nofollow ugc\">https:\u002F\u002Fgithub.com\u002Fbmlt-enabled\u002Fupcoming-meetings-bmlt\u003C\u002Fa>\u003C\u002Fp>\n","Upcoming Meetings BMLT is a plugin that displays the next 'N' number of meetings from the current time on your page or in a widget using the &hellip;",50,3574,"2025-11-23T19:20:00.000Z","6.8.5",[99,52,54,114,104],"upcoming-meetings","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fupcoming-meetings-bmlt\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fupcoming-meetings-bmlt.1.6.0.zip","2026-04-16T10:56:18.058Z",{"attackSurface":119,"codeSignals":141,"taintFlows":245,"riskAssessment":246,"analyzedAt":260},{"hooks":120,"ajaxHandlers":131,"restRoutes":138,"shortcodes":139,"cronEvents":140,"entryPointCount":13,"unprotectedCount":13},[121,127],{"type":122,"name":123,"callback":124,"file":125,"line":126},"action","admin_menu","tsmp_admin_menu","includes\\admin-menu.php",3,{"type":122,"name":128,"callback":129,"file":125,"line":130},"admin_init","tsmp_options_init",6,[132],{"action":133,"nopriv":134,"callback":135,"hasNonce":134,"hasCapCheck":134,"file":136,"line":137},"step_pdf",false,"closure","pdf.php",4,[],[],[],{"dangerousFunctions":142,"sqlUsage":143,"outputEscaping":145,"fileOperations":27,"externalRequests":27,"nonceChecks":27,"capabilityChecks":126,"bundledLibraries":240},[],{"prepared":27,"raw":27,"locations":144},[],{"escaped":27,"rawEcho":146,"locations":147},45,[148,152,154,156,158,160,162,164,166,168,170,172,174,176,178,180,182,184,186,188,190,192,194,196,198,200,202,204,206,208,209,211,213,215,217,219,221,223,225,227,229,231,233,235,237],{"file":149,"line":150,"context":151},"includes\\admin-gen.php",26,"raw output",{"file":149,"line":153,"context":151},64,{"file":149,"line":155,"context":151},65,{"file":149,"line":157,"context":151},66,{"file":149,"line":159,"context":151},191,{"file":149,"line":161,"context":151},196,{"file":149,"line":163,"context":151},201,{"file":149,"line":165,"context":151},202,{"file":149,"line":167,"context":151},203,{"file":149,"line":169,"context":151},322,{"file":149,"line":171,"context":151},332,{"file":149,"line":173,"context":151},358,{"file":149,"line":175,"context":151},361,{"file":149,"line":177,"context":151},366,{"file":149,"line":179,"context":151},369,{"file":149,"line":181,"context":151},378,{"file":149,"line":183,"context":151},387,{"file":149,"line":185,"context":151},419,{"file":149,"line":187,"context":151},428,{"file":149,"line":189,"context":151},431,{"file":149,"line":191,"context":151},441,{"file":149,"line":193,"context":151},480,{"file":149,"line":195,"context":151},483,{"file":149,"line":197,"context":151},488,{"file":149,"line":199,"context":151},496,{"file":149,"line":201,"context":151},499,{"file":149,"line":203,"context":151},502,{"file":149,"line":205,"context":151},508,{"file":149,"line":207,"context":151},530,{"file":149,"line":207,"context":151},{"file":149,"line":210,"context":151},609,{"file":149,"line":212,"context":151},610,{"file":149,"line":214,"context":151},611,{"file":149,"line":216,"context":151},612,{"file":149,"line":218,"context":151},613,{"file":149,"line":220,"context":151},614,{"file":149,"line":222,"context":151},615,{"file":149,"line":224,"context":151},626,{"file":149,"line":226,"context":151},628,{"file":149,"line":228,"context":151},632,{"file":149,"line":230,"context":151},642,{"file":149,"line":232,"context":151},652,{"file":149,"line":234,"context":151},670,{"file":149,"line":236,"context":151},681,{"file":238,"line":239,"context":151},"meeting.php",11,[241],{"name":242,"version":243,"knownCves":244},"TCPDF","1.0",[],[],{"summary":247,"deductions":248},"The \"12-step-meeting-pdf-generator\" plugin v1.0.4 exhibits a mixed security posture. On the positive side, there are no known critical vulnerabilities recorded historically, and the code does not appear to utilize dangerous functions or perform file operations. SQL queries are all prepared, which is a good practice for preventing SQL injection. However, significant concerns arise from the static analysis. A substantial portion of the identified attack surface, specifically an AJAX handler, lacks authentication checks. Furthermore, a critical finding is that none of the 45 outputs are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks on the AJAX entry point, coupled with the unescaped output, creates a dangerous combination that could allow attackers to inject malicious scripts executed with the privileges of logged-in users.\n\nThe vulnerability history being clean is a positive indicator, suggesting that past development might have been more robust or that the plugin hasn't been a significant target. However, the current static analysis reveals a pressing need for immediate attention to security practices. The presence of an unprotected AJAX endpoint and widespread unescaped output presents a clear and present danger. While the plugin avoids some common pitfalls like raw SQL queries and dangerous functions, the identified vulnerabilities are serious and could lead to account takeovers, unauthorized actions, or data breaches if exploited.\n\nIn conclusion, the plugin has strengths in its handling of SQL queries and lack of known historical CVEs. However, the current version suffers from a critical lack of output escaping and an unprotected AJAX endpoint, which significantly elevates its risk profile. Immediate remediation of these issues is strongly recommended to mitigate the substantial XSS and potential unauthorized action risks.",[249,252,255,258],{"reason":250,"points":251},"AJAX handler without auth checks",10,{"reason":253,"points":254},"All outputs unescaped",20,{"reason":256,"points":257},"Missing nonce checks",5,{"reason":259,"points":257},"Bundled outdated library (TCPDF v1.0)","2026-03-16T20:31:36.193Z",{"wat":262,"direct":271},{"assetPaths":263,"generatorPatterns":265,"scriptPaths":266,"versionParams":268},[264],"\u002Fwp-content\u002Fplugins\u002F12-step-meeting-pdf-generator\u002Fcss\u002Fstyles.css",[],[267],"\u002Fwp-content\u002Fplugins\u002F12-step-meeting-pdf-generator\u002Fjs\u002Fscripts.js",[269,270],"12-step-meeting-pdf-generator\u002Fcss\u002Fstyles.css?ver=","12-step-meeting-pdf-generator\u002Fjs\u002Fscripts.js?ver=",{"cssClasses":272,"htmlComments":273,"htmlAttributes":274,"restEndpoints":275,"jsGlobals":276,"shortcodeOutput":279},[],[],[],[],[277,278],"tsml_programs","tsml_program",[],{"error":281,"url":282,"statusCode":283,"statusMessage":284,"message":284},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002F12-step-meeting-pdf-generator\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":254,"versions":286},[287,293,300,307,314,321,328,335,342,349,356,363,370,377,384,391,398,405,412,419],{"version":6,"download_url":288,"svn_tag_url":289,"released_at":28,"has_diff":134,"diff_files_changed":290,"diff_lines":28,"trac_diff_url":291,"vulnerabilities":292,"is_current":281},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.1.0.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F1.0.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F1.0.3&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F1.0.4",[],{"version":294,"download_url":295,"svn_tag_url":296,"released_at":28,"has_diff":134,"diff_files_changed":297,"diff_lines":28,"trac_diff_url":298,"vulnerabilities":299,"is_current":134},"1.0.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.1.0.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F1.0.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F1.0.2&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F1.0.3",[],{"version":301,"download_url":302,"svn_tag_url":303,"released_at":28,"has_diff":134,"diff_files_changed":304,"diff_lines":28,"trac_diff_url":305,"vulnerabilities":306,"is_current":134},"1.0.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.1.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F1.0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.3.1&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F1.0.2",[],{"version":308,"download_url":309,"svn_tag_url":310,"released_at":28,"has_diff":134,"diff_files_changed":311,"diff_lines":28,"trac_diff_url":312,"vulnerabilities":313,"is_current":134},"0.3.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.3.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.3.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.3.0&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.3.1",[],{"version":315,"download_url":316,"svn_tag_url":317,"released_at":28,"has_diff":134,"diff_files_changed":318,"diff_lines":28,"trac_diff_url":319,"vulnerabilities":320,"is_current":134},"0.3.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.3.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.3.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.2.4&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.3.0",[],{"version":322,"download_url":323,"svn_tag_url":324,"released_at":28,"has_diff":134,"diff_files_changed":325,"diff_lines":28,"trac_diff_url":326,"vulnerabilities":327,"is_current":134},"0.2.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.2.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.2.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.2.3&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.2.4",[],{"version":329,"download_url":330,"svn_tag_url":331,"released_at":28,"has_diff":134,"diff_files_changed":332,"diff_lines":28,"trac_diff_url":333,"vulnerabilities":334,"is_current":134},"0.2.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.2.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.2.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.2.2&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.2.3",[],{"version":336,"download_url":337,"svn_tag_url":338,"released_at":28,"has_diff":134,"diff_files_changed":339,"diff_lines":28,"trac_diff_url":340,"vulnerabilities":341,"is_current":134},"0.2.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.2.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.2.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.2.1&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.2.2",[],{"version":343,"download_url":344,"svn_tag_url":345,"released_at":28,"has_diff":134,"diff_files_changed":346,"diff_lines":28,"trac_diff_url":347,"vulnerabilities":348,"is_current":134},"0.2.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.2.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.2.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.2.1a&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.2.1",[],{"version":350,"download_url":351,"svn_tag_url":352,"released_at":28,"has_diff":134,"diff_files_changed":353,"diff_lines":28,"trac_diff_url":354,"vulnerabilities":355,"is_current":134},"0.2.1a","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.2.1a.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.2.1a\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.2.0&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.2.1a",[],{"version":357,"download_url":358,"svn_tag_url":359,"released_at":28,"has_diff":134,"diff_files_changed":360,"diff_lines":28,"trac_diff_url":361,"vulnerabilities":362,"is_current":134},"0.2.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.2.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.2.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.8&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.2.0",[],{"version":364,"download_url":365,"svn_tag_url":366,"released_at":28,"has_diff":134,"diff_files_changed":367,"diff_lines":28,"trac_diff_url":368,"vulnerabilities":369,"is_current":134},"0.1.8","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.1.8.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.1.8\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.7&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.8",[],{"version":371,"download_url":372,"svn_tag_url":373,"released_at":28,"has_diff":134,"diff_files_changed":374,"diff_lines":28,"trac_diff_url":375,"vulnerabilities":376,"is_current":134},"0.1.7","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.1.7.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.1.7\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.6&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.7",[],{"version":378,"download_url":379,"svn_tag_url":380,"released_at":28,"has_diff":134,"diff_files_changed":381,"diff_lines":28,"trac_diff_url":382,"vulnerabilities":383,"is_current":134},"0.1.6","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.1.6.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.1.6\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.5&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.6",[],{"version":385,"download_url":386,"svn_tag_url":387,"released_at":28,"has_diff":134,"diff_files_changed":388,"diff_lines":28,"trac_diff_url":389,"vulnerabilities":390,"is_current":134},"0.1.5","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.1.5.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.1.5\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.4&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.5",[],{"version":392,"download_url":393,"svn_tag_url":394,"released_at":28,"has_diff":134,"diff_files_changed":395,"diff_lines":28,"trac_diff_url":396,"vulnerabilities":397,"is_current":134},"0.1.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.1.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.1.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.3&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.4",[],{"version":399,"download_url":400,"svn_tag_url":401,"released_at":28,"has_diff":134,"diff_files_changed":402,"diff_lines":28,"trac_diff_url":403,"vulnerabilities":404,"is_current":134},"0.1.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.1.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.1.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.2&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.3",[],{"version":406,"download_url":407,"svn_tag_url":408,"released_at":28,"has_diff":134,"diff_files_changed":409,"diff_lines":28,"trac_diff_url":410,"vulnerabilities":411,"is_current":134},"0.1.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.1.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.1.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.1&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.2",[],{"version":413,"download_url":414,"svn_tag_url":415,"released_at":28,"has_diff":134,"diff_files_changed":416,"diff_lines":28,"trac_diff_url":417,"vulnerabilities":418,"is_current":134},"0.1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.1.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.0&new_path=%2F12-step-meeting-pdf-generator%2Ftags%2F0.1.1",[],{"version":420,"download_url":421,"svn_tag_url":422,"released_at":28,"has_diff":134,"diff_files_changed":423,"diff_lines":28,"trac_diff_url":28,"vulnerabilities":424,"is_current":134},"0.1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F12-step-meeting-pdf-generator.0.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002F12-step-meeting-pdf-generator\u002Ftags\u002F0.1.0\u002F",[],[]]