[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0Cdpo5Q4gXE5XS_Hqq4VLmtf504B3ViXQcATKzB-o1c":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"vulnerabilities":31,"developer":32,"crawl_stats":29,"alternatives":40,"analysis":132,"fingerprints":422},"bangla-date-display","Bangla Date Display","9.4.2","ALI IMRAN","https:\u002F\u002Fprofiles.wordpress.org\u002Fimran2w\u002F","\u003Cp>Displays Bangla, Gregorian and Hijri date, Archive Calendar, time, name of the day, name of the current season of Bangladesh etc in Bangla language! Options available for displaying post\u002Fpage’s default (english) time, date, comment count, numbers etc in bangla language!\u003C\u002Fp>\n\u003Ch3>নতুন বাংলা বর্ষপঞ্জি (১৭ অক্টোবর ২০১৯)\u003C\u002Fh3>\n\u003Cp>পুরনো নিয়মে বৈশাখ থেকে ভাদ্র- এই পাঁচ মাস গণনা করা হতো ৩১ দিনে। আর আশ্বিন থেকে চৈত্র- সাত মাস হতো ৩০ দিনে। তবে ইংরেজি লিপইয়ারে ফাল্গুন মাস ৩১ দিনে হতো। এখন নতুন নিয়মে বৈশাখ থেকে আশ্বিন- প্রথম ছয় মাস ৩১ দিনে হবে। কার্তিক, অগ্রহায়ণ, পৌষ, মাঘ ও চৈত্র- এই ৫ মাস হিসাব করা হবে ৩০ দিনে। আর ফাল্গুন মাস হিসাব করা হবে ২৯ দিনে। ইংরেজি লিপইয়ারের বছর এক দিন বেড়ে ফাল্গুন হবে ৩০ দিনের মাস।\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Install and activate the plugin.\u003C\u002Fli>\n\u003Cli>Navigate to: Settings -> Bangla Date Display.\u003C\u002Fli>\n\u003Cli>Use widgets or shortcodes.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Features:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Bangla date.\u003C\u002Fli>\n\u003Cli>Hijri Date.\u003C\u002Fli>\n\u003Cli>Gregorian date.\u003C\u002Fli>\n\u003Cli>Bangla day and time.\u003C\u002Fli>\n\u003Cli>Name of the current season of Bangladesh.\u003C\u002Fli>\n\u003Cli>Advanced bangla archive calendar widget.\u003C\u002Fli>\n\u003Cli>Options for displaying post\u002Fpage’s default (english) time, date, comment count etc in bangla language.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Speciality\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Its free!\u003C\u002Fli>\n\u003Cli>Very simple.\u003C\u002Fli>\n\u003Cli>Easy admin panel.\u003C\u002Fli>\n\u003Cli>Fully customizable.\u003C\u002Fli>\n\u003Cli>Built-in functionality.\u003C\u002Fli>\n\u003Cli>Wide-range compatibility.\u003C\u002Fli>\n\u003Cli>Easy to use widgets and shortcodes!\u003C\u002Fli>\n\u003Cli>All date\u002Ftime output in Bangla Language!\u003C\u002Fli>\n\u003Cli>No special configuration or, knowledge required!\u003C\u002Fli>\n\u003Cli>Automatic GMT+6 (Dhaka, Bangladesh) time and date.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Credits\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Developer: \u003Ca href=\"https:\u002F\u002Ffacebook.com\u002Fimran2w\" rel=\"nofollow ugc\">ALI IMRAN\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>E-Mail: imran4dev@gmail.com\u003C\u002Fli>\n\u003Cli>Website: \u003Ca href=\"https:\u002F\u002Fimran.link\" rel=\"nofollow ugc\">imran.link\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Thanks to\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002Fosmansorkar\u002F\" rel=\"nofollow ugc\">osman sorkar\u003C\u002Fa> for Ajax Archive Calendar\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cpre>\u003Ccode>This program is free software; you can redistribute it and\u002For modify\nit under the terms of the GNU General Public License as published by\nthe Free Software Foundation; either version 2 of the License, or\n(at your option) any later version.\n\nThis program is distributed in the hope that it will be useful,\nbut WITHOUT ANY WARRANTY; without even the implied warranty of\nMERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the\nGNU General Public License for more details.\n\nYou should have received a copy of the GNU General Public License\nalong with this program; if not, write to the Free Software\nFoundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA\n\u003C\u002Fcode>\u003C\u002Fpre>\n","Displays Bangla, Gregorian & Hijri date and Archive Calendar in bangla language via widgets and shortcodes!",4000,83967,92,11,"2026-02-17T15:30:00.000Z","6.9.4","3.0","5.6",[20,21,22,23,24],"bangla","bangla-archive","bangla-calendar","bangla-date","bengali","https:\u002F\u002Fimran.link","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbangla-date-display.9.4.2.zip",100,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":33,"display_name":7,"profile_url":8,"plugin_count":34,"total_installs":35,"avg_security_score":36,"avg_patch_time_days":37,"trust_score":38,"computed_at":39},"imran2w",5,6800,97,447,77,"2026-04-04T21:01:13.460Z",[41,59,79,96,114],{"slug":42,"name":43,"version":44,"author":45,"author_profile":46,"description":47,"short_description":48,"active_installs":49,"downloaded":50,"rating":27,"num_ratings":51,"last_updated":52,"tested_up_to":16,"requires_at_least":53,"requires_php":18,"tags":54,"homepage":57,"download_link":58,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"bangla-calendar-display","Bangla Calendar Display","1.0.10","Md Shorov Abedin","https:\u002F\u002Fprofiles.wordpress.org\u002Fiamovk\u002F","\u003Cp>Bangla Calendar Display shows the current Bengali (Bangla) date and time on your WordPress site. Version 1.0.10 embeds all required styles inline (no external CSS files) and extends the settings page with a border‑radius option alongside colour and font size controls. It also improves the shortcode copy functionality and ensures the live preview reflects all style choices. The admin page includes a live preview and a shortcode generator.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Calculates the Bangla date based on the Gregorian calendar and handles leap years and Pohela Boishakh (14 April) transitions.\u003C\u002Fli>\n\u003Cli>Multiple display templates: simple inline text, modern card, stacked grid and a dual calendar showing the equivalent Gregorian date.\u003C\u002Fli>\n\u003Cli>Customise which parts to show (time, weekday, date only) and adjust colours and font size using the built‑in colour pickers.\u003C\u002Fli>\n\u003Cli>Settings page in the WordPress dashboard (under \u003Cstrong>Bangla Calendar\u003C\u002Fstrong>) lets you choose the layout, timezone and colours and see a live preview of your selections.\u003C\u002Fli>\n\u003Cli>Automatically generates the shortcode for you — copy it with one click to embed the calendar anywhere on your site.\u003C\u002Fli>\n\u003Cli>Shortcode attributes allow per‑use overrides of any option.\u003C\u002Fli>\n\u003Cli>Fully translation‑ready (\u003Ccode>Text Domain: bangla-calendar-display\u003C\u002Fcode>) and supports any timezone.\u003C\u002Fli>\n\u003C\u002Ful>\n","Display the current Bengali (Bangla) date and time on your WordPress site with a choice of attractive layouts. Includes a live preview and shortcode g &hellip;",40,1047,1,"2025-12-02T15:40:00.000Z","5.0",[22,55,56],"bangla-date-time","bengali-date","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbangla-calendar-display\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbangla-calendar-display.zip",{"slug":60,"name":61,"version":62,"author":63,"author_profile":64,"description":65,"short_description":66,"active_installs":67,"downloaded":68,"rating":27,"num_ratings":51,"last_updated":69,"tested_up_to":70,"requires_at_least":71,"requires_php":72,"tags":73,"homepage":76,"download_link":77,"security_score":78,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"wp-bongabdo-date","WP Bongabdo Date","13.0","zakirdaq","https:\u002F\u002Fprofiles.wordpress.org\u002Fzakirdaq\u002F","\u003Cp>Converts post\u002Fpage and comments date from Gregorian Date to Bongabdo Date. It is based on Dr. Muhammed Shahidullah’s Bangla calendar approved by People’s Republic of Bangladesh. Once you activate the plugin, automatically date and time will be changed to Bongabdo date for all posts and comments. You can show it in both English and Bangla language.\u003C\u002Fp>\n","Converts posts and comments date from Gregorian Date to Bongabdo Date.",10,1321,"2015-04-21T09:38:00.000Z","4.1.42","3.1.1","",[20,23,24,74,75],"bongabdo","bongabdo-date","http:\u002F\u002Fwebnitpark.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-bongabdo-date.zip",85,{"slug":80,"name":81,"version":82,"author":7,"author_profile":8,"description":83,"short_description":84,"active_installs":85,"downloaded":86,"rating":87,"num_ratings":88,"last_updated":89,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":90,"homepage":94,"download_link":95,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"bangla-web-fonts","Bangla Web Fonts","1.4","\u003Cp>Embeds Bangla web fonts in your site for a beautiful view of Bangla text. This plugin is able to show the fonts as we usually see and use in text books irrespectible of all devices & browsers.\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Simply install and activate the plugin it will try to embed bangla web font automatically.\u003C\u002Fli>\n\u003Cli>\n\u003Cp>If it doesen’t work then manually edit your theme’s css and change font-family like this:\u003C\u002Fp>\n\u003Cp>body {\u003Cbr \u002F>\n    font-family: ‘SolaimanLipi’, Arial, sans-serif !important;\u003Cbr \u002F>\n}\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Credits\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Developer: \u003Ca href=\"http:\u002F\u002Ffacebook.com\u002Fimran2w\" rel=\"nofollow ugc\">ALI IMRAN\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>E-Mail: imran4dev@gmail.com\u003C\u002Fli>\n\u003Cli>Website: \u003Ca href=\"https:\u002F\u002Fimran.link\" rel=\"nofollow ugc\">imran.link\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cpre>\u003Ccode>This program is free software; you can redistribute it and\u002For modify\nit under the terms of the GNU General Public License as published by\nthe Free Software Foundation; either version 2 of the License, or\n(at your option) any later version.\n\nThis program is distributed in the hope that it will be useful,\nbut WITHOUT ANY WARRANTY; without even the implied warranty of\nMERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the\nGNU General Public License for more details.\n\nYou should have received a copy of the GNU General Public License\nalong with this program; if not, write to the Free Software\nFoundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA\n\u003C\u002Fcode>\u003C\u002Fpre>\n","Enables Bangla web fonts for wordpress site.",2000,41246,96,6,"2025-11-28T13:52:00.000Z",[20,91,92,24,93],"bangla-font","bangla-web-font","solaimanlipi","http:\u002F\u002Fxhostbd.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbangla-web-fonts.1.4.zip",{"slug":97,"name":98,"version":99,"author":100,"author_profile":101,"description":102,"short_description":103,"active_installs":104,"downloaded":105,"rating":27,"num_ratings":106,"last_updated":107,"tested_up_to":108,"requires_at_least":53,"requires_php":109,"tags":110,"homepage":72,"download_link":113,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"bangla-font-cdn","Bangla Font CDN","1.0","Bytes Vibe","https:\u002F\u002Fprofiles.wordpress.org\u002Fbytesvibe\u002F","\u003Cp>Bangla Font CDN is a user-friendly WordPress plugin that allows you to enhance your website with beautiful Bangla (Bengali) fonts. The plugin includes 12 fonts, such as Noto Serif Bengali, Siyam Rupali, SolaimanLipi, Kalpurush, and more, sourced from various providers and bundled locally within the plugin. With a modern settings interface, you can preview fonts in real-time, set fallback fonts, and adjust typography settings like font size, line height, and letter spacing.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features\u003C\u002Fstrong>:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Choose from 12 Bangla fonts with a live preview.\u003C\u002Fli>\n\u003Cli>Set fallback fonts for compatibility.\u003C\u002Fli>\n\u003Cli>Adjust typography settings (font size, line height, letter spacing) with real-time preview.\u003C\u002Fli>\n\u003Cli>Option to override theme font size or use theme settings.\u003C\u002Fli>\n\u003Cli>Reset all settings to defaults with a single click.\u003C\u002Fli>\n\u003Cli>Dedicated disclaimer page outlining font licensing responsibilities.\u003C\u002Fli>\n\u003Cli>Modern, accessible admin interface with card-based design.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Important Note:\u003C\u002Fstrong> Each font included in this plugin is bundled locally and has its own license (e.g., SIL Open Font License, GNU GPL, or others). Some fonts are free for personal and commercial use, while others may have restrictions. You are responsible for verifying the license of each font before using it in commercial projects. Review the Disclaimer page in the plugin settings and the \u003Ccode>fonts\u002FLICENSE.txt\u003C\u002Fcode> file for more details.\u003C\u002Fp>\n\u003Ch3>Disclaimer\u003C\u002Fh3>\n\u003Cp>The Bangla Font CDN plugin includes Bangla fonts from various providers, bundled locally within the plugin. Each font has its own license (e.g., SIL Open Font License, GNU GPL), included in the \u003Ccode>fonts\u002FLICENSE.txt\u003C\u002Fcode> file. Users are responsible for verifying the license of each font before using it in commercial projects. The plugin author and BytesVibe are not liable for any legal or financial consequences arising from font misuse. Review the Disclaimer page in the plugin settings for full details.\u003C\u002Fp>\n","A powerful and easy-to-use plugin to use 10+ beautiful Bangla fonts on website with live preview, fallback font options, and advanced typography.",200,1146,2,"2025-06-12T07:39:00.000Z","6.8.5","7.0",[20,24,111,112],"fonts","typography","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbangla-font-cdn.1.0.zip",{"slug":115,"name":116,"version":117,"author":118,"author_profile":119,"description":120,"short_description":121,"active_installs":27,"downloaded":122,"rating":27,"num_ratings":51,"last_updated":123,"tested_up_to":124,"requires_at_least":125,"requires_php":126,"tags":127,"homepage":130,"download_link":131,"security_score":78,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"bangla-number-converter","Bangla Number Converter","1.1","Jesmin Juthi","https:\u002F\u002Fprofiles.wordpress.org\u002Fjesminjuthi\u002F","\u003Cp>Bangla Number Converter plugin will help you to Converts English numbers to Bangla numbers of your WordPress website.\u003C\u002Fp>\n\u003Cp>Plugin Documentation: \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbangla-number-converter\u002F\" rel=\"ugc\">https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbangla-number-converter\u002F\u003C\u002Fa>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fjesminjuthi\" rel=\"nofollow ugc\">About Author\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>⚡ You can changes settings\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>No setup needed.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>You can make my day by submitting a positive review on \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbangla-number-converter\" rel=\"ugc\">\u003Cstrong>WordPress.org!\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>⚡ Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Ready to use without any setup\u003C\u002Fli>\n\u003Cli>Very easy installation\u003C\u002Fli>\n\u003Cli>Flexible and easy to use\u003C\u002Fli>\n\u003Cli>Lightweight and fast\u003C\u002Fli>\n\u003C\u002Ful>\n","Bangla Number Converter plugin will help you to Converts English numbers to Bangla numbers of your WordPress website.",5140,"2024-02-06T20:14:00.000Z","6.4.8","5.7","7.4",[128,115,129],"bangla-date-and-time","english-to-bangla-date","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbangla-number-converter\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbangla-number-converter.zip",{"attackSurface":133,"codeSignals":223,"taintFlows":367,"riskAssessment":406,"analyzedAt":421},{"hooks":134,"ajaxHandlers":185,"restRoutes":194,"shortcodes":195,"cronEvents":221,"entryPointCount":222,"unprotectedCount":106},[135,140,144,149,153,158,162,167,169,172,175,178,182],{"type":136,"name":137,"callback":138,"file":139,"line":88},"action","wp_enqueue_scripts","bddp_ac_enqueue_scripts","ajax-archive-calendar.php",{"type":136,"name":141,"callback":142,"file":139,"line":143},"widgets_init","bddp_ac_int",19,{"type":145,"name":146,"callback":147,"file":139,"line":148},"filter","wp_head","bddp_ac_head",560,{"type":145,"name":150,"callback":151,"file":139,"line":152},"day_link","bddp_ac_permalinks",572,{"type":136,"name":154,"callback":155,"file":156,"line":157},"admin_menu","bddp_admin","bddp_admin.php",333,{"type":136,"name":159,"callback":160,"file":156,"line":161},"admin_init","register_bddp_settings",340,{"type":145,"name":163,"callback":164,"priority":67,"file":165,"line":166},"wp_date","en_to_bn","translator.php",9,{"type":145,"name":168,"callback":164,"priority":67,"file":165,"line":14},"date_i18n",{"type":145,"name":170,"callback":164,"file":165,"line":171},"comments_number",16,{"type":145,"name":173,"callback":164,"file":165,"line":174},"get_comment_count",17,{"type":145,"name":176,"callback":164,"priority":67,"file":165,"line":177},"number_format_i18n",22,{"type":136,"name":141,"callback":179,"file":180,"line":181},"closure","widgets copy.php",4,{"type":136,"name":141,"callback":183,"file":184,"line":171},"bddp_register_widgets","widgets.php",[186,191],{"action":187,"nopriv":188,"callback":189,"hasNonce":188,"hasCapCheck":188,"file":139,"line":190},"bddp_ac",false,"bddp_ac_callback",235,{"action":187,"nopriv":192,"callback":189,"hasNonce":188,"hasCapCheck":188,"file":139,"line":193},true,236,[],[196,201,205,209,213,217],{"tag":197,"callback":198,"file":199,"line":200},"bangla_time","render_bangla_clock","bangla-date-display.php",38,{"tag":202,"callback":203,"file":199,"line":204},"bangla_day","render_bangla_day",69,{"tag":206,"callback":207,"file":199,"line":208},"bangla_date","render_bangla_date",84,{"tag":210,"callback":211,"file":199,"line":212},"bangla_season","bddp_bn_season",119,{"tag":214,"callback":215,"file":199,"line":216},"english_date","render_gregorian_date",151,{"tag":218,"callback":219,"file":199,"line":220},"hijri_date","render_hijri_date",184,[],8,{"dangerousFunctions":224,"sqlUsage":225,"outputEscaping":232,"fileOperations":28,"externalRequests":28,"nonceChecks":28,"capabilityChecks":28,"bundledLibraries":366},[],{"prepared":28,"raw":106,"locations":226},[227,230],{"file":139,"line":228,"context":229},268,"$wpdb->get_var() with variable interpolation",{"file":139,"line":231,"context":229},290,{"escaped":233,"rawEcho":234,"locations":235},65,79,[236,239,241,243,245,247,249,251,253,255,257,259,260,261,263,265,266,268,270,271,272,274,276,278,280,281,283,285,287,289,290,292,294,296,297,299,301,302,304,306,307,309,311,313,315,317,319,321,323,324,326,327,328,330,331,332,334,335,336,338,339,340,342,343,344,346,347,348,350,351,352,353,355,357,358,360,361,363,364],{"file":139,"line":237,"context":238},53,"raw output",{"file":139,"line":240,"context":238},58,{"file":139,"line":242,"context":238},108,{"file":139,"line":244,"context":238},110,{"file":139,"line":246,"context":238},137,{"file":139,"line":248,"context":238},139,{"file":139,"line":250,"context":238},149,{"file":139,"line":252,"context":238},158,{"file":139,"line":254,"context":238},187,{"file":139,"line":256,"context":238},207,{"file":139,"line":258,"context":238},208,{"file":139,"line":258,"context":238},{"file":139,"line":258,"context":238},{"file":139,"line":262,"context":238},212,{"file":139,"line":264,"context":238},213,{"file":139,"line":264,"context":238},{"file":139,"line":267,"context":238},220,{"file":139,"line":269,"context":238},221,{"file":139,"line":269,"context":238},{"file":139,"line":269,"context":238},{"file":139,"line":273,"context":238},256,{"file":139,"line":275,"context":238},494,{"file":139,"line":277,"context":238},502,{"file":199,"line":279,"context":238},62,{"file":199,"line":38,"context":238},{"file":199,"line":282,"context":238},112,{"file":199,"line":284,"context":238},144,{"file":199,"line":286,"context":238},177,{"file":199,"line":288,"context":238},219,{"file":156,"line":282,"context":238},{"file":156,"line":291,"context":238},114,{"file":156,"line":293,"context":238},128,{"file":156,"line":295,"context":238},130,{"file":156,"line":284,"context":238},{"file":156,"line":298,"context":238},146,{"file":156,"line":300,"context":238},185,{"file":156,"line":254,"context":238},{"file":156,"line":303,"context":238},316,{"file":180,"line":305,"context":238},36,{"file":180,"line":200,"context":238},{"file":180,"line":308,"context":238},47,{"file":180,"line":310,"context":238},51,{"file":180,"line":312,"context":238},59,{"file":180,"line":314,"context":238},64,{"file":180,"line":316,"context":238},71,{"file":180,"line":318,"context":238},75,{"file":180,"line":320,"context":238},83,{"file":180,"line":322,"context":238},116,{"file":180,"line":322,"context":238},{"file":180,"line":325,"context":238},117,{"file":180,"line":325,"context":238},{"file":180,"line":325,"context":238},{"file":180,"line":329,"context":238},120,{"file":180,"line":329,"context":238},{"file":180,"line":329,"context":238},{"file":180,"line":333,"context":238},123,{"file":180,"line":333,"context":238},{"file":180,"line":333,"context":238},{"file":180,"line":337,"context":238},126,{"file":180,"line":337,"context":238},{"file":180,"line":337,"context":238},{"file":180,"line":341,"context":238},129,{"file":180,"line":341,"context":238},{"file":180,"line":341,"context":238},{"file":180,"line":345,"context":238},132,{"file":180,"line":345,"context":238},{"file":180,"line":345,"context":238},{"file":180,"line":349,"context":238},135,{"file":180,"line":349,"context":238},{"file":180,"line":349,"context":238},{"file":184,"line":314,"context":238},{"file":184,"line":354,"context":238},67,{"file":184,"line":356,"context":238},78,{"file":184,"line":320,"context":238},{"file":184,"line":359,"context":238},93,{"file":184,"line":27,"context":238},{"file":184,"line":362,"context":238},109,{"file":184,"line":291,"context":238},{"file":184,"line":365,"context":238},124,[],[368,390],{"entryPoint":369,"graph":370,"unsanitizedCount":51,"severity":389},"bddp_ac_callback (ajax-archive-calendar.php:238)",{"nodes":371,"edges":386},[372,377,381],{"id":373,"type":374,"label":375,"file":139,"line":376},"n0","source","$_GET",241,{"id":378,"type":379,"label":380,"file":139,"line":376},"n1","transform","→ bddp_ac_calendar()",{"id":382,"type":383,"label":384,"file":139,"line":275,"wp_function":385},"n2","sink","echo() [XSS]","echo",[387,388],{"from":373,"to":378,"sanitized":188},{"from":378,"to":382,"sanitized":188},"medium",{"entryPoint":391,"graph":392,"unsanitizedCount":106,"severity":389},"\u003Cajax-archive-calendar> (ajax-archive-calendar.php:0)",{"nodes":393,"edges":402},[394,396,397,398,400],{"id":373,"type":374,"label":375,"file":139,"line":395},239,{"id":378,"type":383,"label":384,"file":139,"line":275,"wp_function":385},{"id":382,"type":374,"label":375,"file":139,"line":376},{"id":399,"type":379,"label":380,"file":139,"line":376},"n3",{"id":401,"type":383,"label":384,"file":139,"line":275,"wp_function":385},"n4",[403,404,405],{"from":373,"to":378,"sanitized":188},{"from":382,"to":399,"sanitized":188},{"from":399,"to":401,"sanitized":188},{"summary":407,"deductions":408},"The \"bangla-date-display\" v9.4.2 plugin exhibits several concerning security practices, despite a clean vulnerability history. The static analysis reveals a significant attack surface with 2 out of 8 total entry points lacking authentication checks. This is a primary concern as it exposes these functions to potential unauthorized access and manipulation.\n\nFurthermore, the plugin's handling of SQL queries is a major weakness. All 2 SQL queries are executed without prepared statements, introducing a high risk of SQL injection vulnerabilities. The taint analysis also flagged 2 flows with unsanitized paths, indicating potential issues with how external data is handled, although no critical or high severity vulnerabilities were identified in this specific analysis.\n\nWhile the plugin has no recorded CVEs, this does not negate the inherent risks present in the code. The lack of capability checks and nonce checks on entry points, coupled with the significant portion of improperly escaped output (55%), further amplifies the potential for cross-site scripting (XSS) and other injection attacks. The plugin's security posture is therefore considered weak due to these critical coding flaws.",[409,411,413,415,417,419],{"reason":410,"points":67},"Unprotected AJAX handlers",{"reason":412,"points":67},"Raw SQL queries without prepared statements",{"reason":414,"points":34},"Flows with unsanitized paths detected",{"reason":416,"points":34},"Lack of nonce checks on entry points",{"reason":418,"points":34},"Lack of capability checks",{"reason":420,"points":222},"Significant portion of output not properly escaped","2026-03-16T18:13:29.721Z",{"wat":423,"direct":440},{"assetPaths":424,"generatorPatterns":431,"scriptPaths":432,"versionParams":433},[425,426,427,428,429,430],"\u002Fwp-content\u002Fplugins\u002Fbangla-date-display\u002Fcss\u002Farchive-calendar.css","\u002Fwp-content\u002Fplugins\u002Fbangla-date-display\u002Fcss\u002Fbootstrap.min.css","\u002Fwp-content\u002Fplugins\u002Fbangla-date-display\u002Fcss\u002Fjquery-ui.css","\u002Fwp-content\u002Fplugins\u002Fbangla-date-display\u002Fjs\u002Farchive-calendar.js","\u002Fwp-content\u002Fplugins\u002Fbangla-date-display\u002Fjs\u002Fmoment-with-locales.js","\u002Fwp-content\u002Fplugins\u002Fbangla-date-display\u002Fjs\u002Fmoment.min.js",[],[428,429,430],[434,435,436,437,438,439],"bangla-date-display\u002Fcss\u002Farchive-calendar.css?ver=","bangla-date-display\u002Fcss\u002Fbootstrap.min.css?ver=","bangla-date-display\u002Fcss\u002Fjquery-ui.css?ver=","bangla-date-display\u002Fjs\u002Farchive-calendar.js?ver=","bangla-date-display\u002Fjs\u002Fmoment-with-locales.js?ver=","bangla-date-display\u002Fjs\u002Fmoment.min.js?ver=",{"cssClasses":441,"htmlComments":443,"htmlAttributes":444,"restEndpoints":445,"jsGlobals":446,"shortcodeOutput":448},[442],"bangla-date-display-shortcode",[],[],[],[447],"moment",[449,450,451,452,449],"{{day}} {{month_year}}{{last_word}}","{{event}}{{hour}}","{{day}}","{{seasons[$month]}}"]