[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fD75qixptrLBoAZ0rYUUPK84BtytdnkJa776SjJQ95Zk":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":18,"download_link":25,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29,"vulnerabilities":30,"developer":31,"crawl_stats":28,"alternatives":36,"analysis":137,"fingerprints":230},"admin-starred-posts","Admin Starred Posts","2.5.0","innocuo","https:\u002F\u002Fprofiles.wordpress.org\u002Finnocuo\u002F","\u003Cp>Admin Starred Posts lets you mark posts, pages and custom posts within the WordPress admin with stars.\u003Cbr \u002F>\nThis helps you highlight a post, or mark it so you remember is important.\u003C\u002Fp>\n\u003Cp>For example, you might have tons of pages, but are always editing one or two. In that case, star those pages,\u003Cbr \u002F>\nand they’ll be easily recognizable in your list of posts.\u003C\u002Fp>\n\u003Cp>If you’ve used Gmail before, you’re very familiar with this feature. Similar to that email client, this plugin\u003Cbr \u002F>\nlet’s you click on a star in your list of posts, pages and custom posts to ‘star’ it.\u003C\u002Fp>\n\u003Cp>The plugin works out of the box, but you also get some configuration options to help you customize it to your workflow.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Configuration Options\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Rotate between 12 different “stars”\u003C\u002Fli>\n\u003Cli>Drag and set the orders of your stars\u003C\u002Fli>\n\u003Cli>Enable\u002Fdisable this feature for any post type in your WordPress install\u003C\u002Fli>\n\u003Cli>Decide whether you want stars to be visible to every one, or in a per user basis.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Other Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>You can display only starred posts by using the “Stars” filter available at the top of the posts list.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>This plugin requires WordPress 3.8 or higher\u003C\u002Fstrong>\u003C\u002Fp>\n","Mark posts, pages and custom posts in your WordPress admin; pretty similar to the stars feature in Gmail.",400,4968,100,6,"2019-04-13T07:34:00.000Z","5.1.22","3.8","",[20,21,22,23,24],"admin","bookmarks","organize","posts","stars","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadmin-starred-posts.2.5.0.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},1,30,84,"2026-04-04T15:06:03.564Z",[37,55,79,99,118],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":13,"downloaded":45,"rating":13,"num_ratings":14,"last_updated":46,"tested_up_to":47,"requires_at_least":48,"requires_php":49,"tags":50,"homepage":53,"download_link":54,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"post-descriptions","Post Descriptions","1.3.0","Tom de Visser","https:\u002F\u002Fprofiles.wordpress.org\u002Ftomdevisser\u002F","\u003Ch4>What does it do?\u003C\u002Fh4>\n\u003Cp>Post Descriptions lets you attach short notes or descriptions to posts and pages — ideal for internal reminders, content planning, or small to-do’s. Use it solo or with your team to stay organized directly in the WordPress admin.\u003C\u002Fp>\n\u003Ch4>How does it work?\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Adding Post Descriptions\u003C\u002Fstrong>\u003Cbr \u002F>\nYou can add a description in two ways:\u003Cbr \u002F>\n1. From the full Edit screen\u003Cbr \u002F>\n2. From the Quick Edit option on the posts\u002Fpages overview\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Viewing Post Descriptions\u003C\u002Fstrong>\u003Cbr \u002F>\nDescriptions are visible:\u003Cbr \u002F>\n1. In a dedicated column on the posts or pages overview — with a customizable column title\u003Cbr \u002F>\n2. As a post state — the small bold label next to the post title\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Post State Toggle\u003C\u002Fstrong>\u003Cbr \u002F>\nBy default, post descriptions are not shown as post states (the bold label next to your post title). You can enable this in Settings > Post Descriptions. If enabled, longer descriptions might clutter your view — you can toggle it off again in the settings.\u003C\u002Fp>\n","A lightweight WordPress plugin that lets you add quick descriptions or personal notes to your posts and pages — perfect for reminders, to-do's, o &hellip;",3924,"2025-06-26T13:20:00.000Z","6.8.5","4.9","5.6",[20,22,51,23,52],"pages","ui","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fpost-descriptions\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpost-descriptions.1.3.0.zip",{"slug":56,"name":57,"version":58,"author":59,"author_profile":60,"description":61,"short_description":62,"active_installs":63,"downloaded":64,"rating":65,"num_ratings":66,"last_updated":67,"tested_up_to":68,"requires_at_least":69,"requires_php":18,"tags":70,"homepage":74,"download_link":75,"security_score":76,"vuln_count":77,"unpatched_count":27,"last_vuln_date":78,"fetched_at":29},"wp-admin-ui-customize","WP Admin UI Customize","1.5.14","gqevu6bsiz","https:\u002F\u002Fprofiles.wordpress.org\u002Fgqevu6bsiz\u002F","\u003Cul>\n\u003Cli>Dashboard\u003C\u002Fli>\n\u003Cli>Display options tab\u003C\u002Fli>\n\u003Cli>Output-meta site\u003C\u002Fli>\n\u003Cli>Admin bar (Toolbar)\u003C\u002Fli>\n\u003Cli>Admin menu (Side menu)\u003C\u002Fli>\n\u003Cli>Management of meta boxes\u003C\u002Fli>\n\u003Cli>Login screen\u003C\u002Fli>\n\u003Cli>Other features.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>These to Customization is possible.\u003C\u002Fp>\n\u003Ch3>日本語でのご説明\u003C\u002Fh3>\n\u003Cp>このプラグインは、管理画面UIのカスタマイズをするプラグインです。\u003Cbr \u002F>\n「ダッシュボード」「オプションタブ」「サイトのメタタグ管理」「管理バー」「管理メニュー」「メタボックス」「ログイン画面」\u003Cbr \u002F>\nこれらのカスタマイズを、このプラグインひとつで出来ます。\u003C\u002Fp>\n","Customize the management screen UI.",30000,390623,92,59,"2024-11-20T02:52:00.000Z","4.9.29","4.2",[20,71,72,73,23],"option","page","post","http:\u002F\u002Fwpadminuicustomize.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-admin-ui-customize.1.5.14.zip",91,2,"2024-11-26 00:00:00",{"slug":80,"name":81,"version":82,"author":83,"author_profile":84,"description":85,"short_description":86,"active_installs":87,"downloaded":88,"rating":89,"num_ratings":90,"last_updated":91,"tested_up_to":92,"requires_at_least":93,"requires_php":18,"tags":94,"homepage":97,"download_link":98,"security_score":65,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"lh-archived-post-status","LH Archived Post Status","3.11","shawfactor","https:\u002F\u002Fprofiles.wordpress.org\u002Fshawfactor\u002F","\u003Cp>This plugin allows you to archive your WordPress content similar to the way you archive your e-mail. Unlike other archiving solutions though this actually does it all and does it properly\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Makes a new post status available in the drop down called Archived\u003C\u002Fli>\n\u003Cli>Hides or removes your content without having to trash the content\u003C\u002Fli>\n\u003Cli>Content can either be hidden entirely from public view  or simply from the main loop and feed and pages, with other solutions you can only hide it from public view.\u003C\u002Fli>\n\u003Cli>Allows you to add a label to the title of those posts\u002Fpages etc that are archived\u003C\u002Fli>\n\u003Cli>Allows you to add a message to the top of the post\u002Fpage etc that the content is no longer up too date\u003C\u002Fli>\n\u003Cli>Allows you to set an archiving date after which content is automatically changed to having an archived status\u003C\u002Fli>\n\u003Cli>Compatible with posts, pages and custom post types\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin is ideal for sites where certain kinds of content is not meant to be evergreen\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Like this plugin? Please consider \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fview\u002Fplugin-reviews\u002Flh-archived-post-status\u002F\" rel=\"ugc\">leaving a 5-star review\u003C\u002Fa>.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Love this plugin or want to help the LocalHero Project? Please consider \u003Ca href=\"https:\u002F\u002Flhero.org\u002Fportfolio\u002Flh-archived-post-status\u002F\" rel=\"nofollow ugc\">making a donation\u003C\u002Fa>.\u003C\u002Fstrong>\u003C\u002Fp>\n","Allows posts and pages to be archived so you can remove content from the main loop and feed without having to trash it.",4000,50462,82,18,"2024-10-16T05:00:00.000Z","6.6.5","5.0",[20,51,23,95,96],"status","workflow","https:\u002F\u002Flhero.org\u002Fportfolio\u002Flh-archived-post-status\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flh-archived-post-status.zip",{"slug":100,"name":101,"version":102,"author":103,"author_profile":104,"description":105,"short_description":106,"active_installs":107,"downloaded":108,"rating":109,"num_ratings":110,"last_updated":111,"tested_up_to":112,"requires_at_least":113,"requires_php":18,"tags":114,"homepage":116,"download_link":117,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"hifi","HiFi (Head Injection, Foot Injection)","1.0.1","farinspace","https:\u002F\u002Fprofiles.wordpress.org\u002Ffarinspace\u002F","\u003Cp>HiFi is a head injection and foot injection plugin (or head include, foot include, head insert, foot insert, what ever you want to call it). It basically allows you to inject \u003Ccode>\u003Cscript>\u003C\u002Fcode>, \u003Ccode>\u003Cstyle>\u003C\u002Fcode>, \u003Ccode>\u003Cmeta>\u003C\u002Fcode> and any other code you want into the head and foot areas of your posts and pages. The code injected is page-specific, this means that only the pages you want code inserted into will be affected.\u003C\u002Fp>\n\u003Cp>This plugin is most useful when you have specific functionality that needs to be added on a per-post\u002Fpage basis.\u003C\u002Fp>\n","HiFi is a head and foot injection plugin. It allows you to inject code into the head and foot areas of your posts and pages on a per-page basis.",2000,29744,96,5,"2010-12-01T20:47:00.000Z","3.0.5","2.9.2",[20,115,72,73,23],"head","http:\u002F\u002Ffarinspace.com\u002F2010\u002F03\u002Fwordpress-hifi-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhifi.1.0.1.zip",{"slug":119,"name":120,"version":121,"author":122,"author_profile":123,"description":124,"short_description":125,"active_installs":107,"downloaded":126,"rating":127,"num_ratings":128,"last_updated":129,"tested_up_to":130,"requires_at_least":131,"requires_php":49,"tags":132,"homepage":135,"download_link":136,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"sortable-word-count-reloaded","Sortable Word Count Reloaded","1.0.3","apasionados","https:\u002F\u002Fprofiles.wordpress.org\u002Fapasionados\u002F","\u003Cp>Adds a sortable column to the posts and pages admin list with the word count of each page\u002Fpost.\u003C\u002Fp>\n\u003Cp>With this plugin you can see the word count for the posts and pages in the list view and sort them.\u003C\u002Fp>\n\u003Cp>This plugin is an enhanced version of the plugin \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsortable-word-count\u002F\" rel=\"ugc\">Sortable Word Count\u003C\u002Fa>. We decided to create this reloaded version of the plugin, because we wanted to be able to translate it and change the word count function so that it gets the correct word count by filtering comments and other page builder code.\u003C\u002Fp>\n\u003Ch4>What can I do with this plugin?\u003C\u002Fh4>\n\u003Cp>The plugin adds a sortable column to the posts and pages admin list with the word count of each page\u002Fpost.\u003C\u002Fp>\n\u003Ch4>System requirements\u003C\u002Fh4>\n\u003Cp>PHP version 5.6 or greater.\u003C\u002Fp>\n\u003Ch4>Sortable Word Count Reloaded Plugin in your Language!\u003C\u002Fh4>\n\u003Cp>This first release is avaliable in English and Spanish. In the “languages” folder we have included the necessary files to translate this plugin.\u003C\u002Fp>\n\u003Cp>If you would like the plugin in your language and you’re good at translating, please drop us a line at \u003Ca href=\"https:\u002F\u002Fapasionados.es\u002Fcontacto\u002Findex.php?desde=wordpress-org-sortable-word-count-reloaded-home\" rel=\"nofollow ugc\">Contact us\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Further Reading\u003C\u002Fh4>\n\u003Cp>You can access the description of the plugin in Spanish at: \u003Ca href=\"https:\u002F\u002Fapasionados.es\u002Fblog\u002F\" rel=\"nofollow ugc\">Columna palabras ordenable | WordPress Plugin\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Contact\u003C\u002Fh3>\n\u003Cp>For further information please send us an \u003Ca href=\"https:\u002F\u002Fapasionados.es\u002Fcontacto\u002Findex.php?desde=wordpress-org-sortable-word-count-reloaded\" rel=\"nofollow ugc\">email\u003C\u002Fa>.\u003C\u002Fp>\n","Adds a sortable column to the posts and pages admin list with the word count of each page\u002Fpost.",12999,74,10,"2026-01-27T14:07:00.000Z","6.9.4","4.0.1",[20,133,51,23,134],"column","word-count","https:\u002F\u002Fapasionados.es\u002Fblog\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsortable-word-count-reloaded.zip",{"attackSurface":138,"codeSignals":190,"taintFlows":216,"riskAssessment":217,"analyzedAt":229},{"hooks":139,"ajaxHandlers":181,"restRoutes":187,"shortcodes":188,"cronEvents":189,"entryPointCount":32,"unprotectedCount":32},[140,146,150,154,157,162,165,168,170,173,178],{"type":141,"name":142,"callback":143,"file":144,"line":145},"action","admin_enqueue_scripts","register_scripts","includes\\class-ino-starred-posts.php",25,{"type":141,"name":147,"callback":148,"file":144,"line":149},"admin_init","define_hooks_for_ajax",33,{"type":141,"name":151,"callback":152,"file":144,"line":153},"current_screen","define_hooks_for_screen",34,{"type":141,"name":155,"callback":156,"priority":128,"file":144,"line":26},"manage_pages_custom_column","display_admin_column",{"type":158,"name":159,"callback":160,"priority":128,"file":144,"line":161},"filter","page_row_actions","add_quick_actions",86,{"type":158,"name":163,"callback":160,"priority":128,"file":144,"line":164},"post_row_actions",90,{"type":141,"name":142,"callback":166,"file":144,"line":167},"enqueue_scripts",93,{"type":141,"name":169,"callback":169,"file":144,"line":109},"restrict_manage_posts",{"type":158,"name":171,"callback":171,"file":144,"line":172},"parse_query",97,{"type":141,"name":174,"callback":175,"file":176,"line":177},"admin_menu","set_admin_menu","includes\\class-ino-starred-settings.php",16,{"type":141,"name":147,"callback":179,"file":176,"line":180},"page_init",17,[182],{"action":183,"nopriv":184,"callback":185,"hasNonce":184,"hasCapCheck":184,"file":144,"line":186},"ino_set_star",false,"set_star",28,[],[],[],{"dangerousFunctions":191,"sqlUsage":192,"outputEscaping":194,"fileOperations":27,"externalRequests":27,"nonceChecks":27,"capabilityChecks":27,"bundledLibraries":215},[],{"prepared":27,"raw":27,"locations":193},[],{"escaped":195,"rawEcho":196,"locations":197},3,8,[198,201,203,205,207,209,211,213],{"file":144,"line":199,"context":200},202,"raw output",{"file":144,"line":202,"context":200},240,{"file":144,"line":204,"context":200},263,{"file":176,"line":206,"context":200},153,{"file":176,"line":208,"context":200},160,{"file":176,"line":210,"context":200},194,{"file":176,"line":212,"context":200},204,{"file":176,"line":214,"context":200},252,[],[],{"summary":218,"deductions":219},"The \"admin-starred-posts\" plugin v2.5.0 exhibits a concerning security posture due to a significant lack of authorization checks on its entry points. While the plugin does not appear to contain inherently dangerous functions, perform file operations, or make external HTTP requests, its single AJAX handler lacks any form of authentication or capability check. This means any user, even unauthenticated ones, can potentially trigger this handler, creating a substantial attack surface.  Furthermore, the static analysis indicates a low percentage of properly escaped output, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care. The absence of any recorded vulnerabilities in its history is positive, suggesting a lack of exploitable flaws to date. However, this does not mitigate the immediate risks presented by the unprotected AJAX endpoint and the potentially unescaped output, which are significant weaknesses that require immediate attention.",[220,222,224,227],{"reason":221,"points":196},"Unprotected AJAX handler",{"reason":223,"points":110},"Low percentage of properly escaped output",{"reason":225,"points":226},"No nonce checks on entry points",7,{"reason":228,"points":226},"No capability checks on entry points","2026-03-16T19:50:04.726Z",{"wat":231,"direct":242},{"assetPaths":232,"generatorPatterns":236,"scriptPaths":237,"versionParams":238},[233,234,235],"\u002Fwp-content\u002Fplugins\u002Fadmin-starred-posts\u002Fjs\u002Fstarred-posts.js","\u002Fwp-content\u002Fplugins\u002Fadmin-starred-posts\u002Fjs\u002Fsettings.js","\u002Fwp-content\u002Fplugins\u002Fadmin-starred-posts\u002Fcss\u002Fmain.css",[],[233,234],[239,240,241],"admin-starred-posts\u002Fjs\u002Fstarred-posts.js?ver=","admin-starred-posts\u002Fjs\u002Fsettings.js?ver=","admin-starred-posts\u002Fcss\u002Fmain.css?ver=",{"cssClasses":243,"htmlComments":249,"htmlAttributes":250,"restEndpoints":254,"jsGlobals":255,"shortcodeOutput":256},[244,245,246,247,248],"ino-starred-column-header","ino-star-clickable","ino-star","c%d","ino-star-postid-%d",[],[251,252,253],"data-stars_ids","data-star_id","data-post_id",[],[],[]]