[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGJdFa3y4oM3DorKzlyGmkSTTy7RI0AtWXWaUJKLxmbg":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":16,"download_link":18,"security_score":19,"vuln_count":11,"unpatched_count":11,"last_vuln_date":20,"fetched_at":21,"vulnerabilities":22,"developer":23,"crawl_stats":20,"alternatives":29,"analysis":30,"fingerprints":70},"addressbar-meta-theme-color","Addressbar Meta Theme Color","1.0","williampatton","https:\u002F\u002Fprofiles.wordpress.org\u002Fwilliampatton\u002F","\u003Cp>Use this plugin to output the required meta tag to change the address bar color in various mobile browsers.\u003C\u002Fp>\n","Changes the address bar colour for users with mobile browsers (works in Chrome and Opera).",0,1675,"2017-08-18T08:55:00.000Z","4.9.29","3.0.1","",[],"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faddressbar-meta-theme-color.zip",85,null,"2026-03-15T15:16:48.613Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":24,"total_installs":25,"avg_security_score":19,"avg_patch_time_days":26,"trust_score":27,"computed_at":28},4,210,30,84,"2026-04-04T14:44:37.865Z",[],{"attackSurface":31,"codeSignals":46,"taintFlows":57,"riskAssessment":58,"analyzedAt":69},{"hooks":32,"ajaxHandlers":42,"restRoutes":43,"shortcodes":44,"cronEvents":45,"entryPointCount":11,"unprotectedCount":11},[33,39],{"type":34,"name":35,"callback":36,"file":37,"line":38},"action","customize_register","add_customizer_options","class-amtc-meta-theme-color.php",28,{"type":34,"name":40,"callback":41,"file":37,"line":26},"wp_head","output_meta_theme_color",[],[],[],[],{"dangerousFunctions":47,"sqlUsage":48,"outputEscaping":50,"fileOperations":11,"externalRequests":11,"nonceChecks":11,"capabilityChecks":11,"bundledLibraries":56},[],{"prepared":11,"raw":11,"locations":49},[],{"escaped":11,"rawEcho":51,"locations":52},1,[53],{"file":37,"line":54,"context":55},53,"raw output",[],[],{"summary":59,"deductions":60},"The \"addressbar-meta-theme-color\" plugin v1.0 demonstrates a generally strong security posture in several key areas. The static analysis reveals a complete absence of direct attack surface vectors like AJAX handlers, REST API routes, shortcodes, and cron events that are not protected by authentication checks. Furthermore, the plugin does not utilize any dangerous functions, avoids SQL queries entirely by using prepared statements (though it has none in this version), and makes no external HTTP requests. The lack of known vulnerabilities in its history is also a positive indicator.\n\nHowever, a significant concern arises from the output escaping. With one total output identified and 0% being properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed to users that is not properly escaped can be exploited by attackers to inject malicious scripts. The absence of nonce and capability checks, while not directly exploitable given the lack of other attack vectors, indicates a potential for future vulnerabilities if new entry points are introduced without adequate security measures.\n\nIn conclusion, while the plugin avoids many common pitfalls and boasts a clean vulnerability history, the lack of output escaping is a critical oversight that significantly weakens its overall security. Addressing this single issue would dramatically improve its security profile, but until then, a notable risk remains.",[61,64,67],{"reason":62,"points":63},"No output escaping",6,{"reason":65,"points":66},"No nonce checks",3,{"reason":68,"points":66},"No capability checks","2026-03-17T06:44:15.816Z",{"wat":71,"direct":76},{"assetPaths":72,"generatorPatterns":73,"scriptPaths":74,"versionParams":75},[],[],[],[],{"cssClasses":77,"htmlComments":78,"htmlAttributes":79,"restEndpoints":80,"jsGlobals":81,"shortcodeOutput":82},[],[],[],[],[],[]]