[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcl7bsu_V44bDe_dmDs6SWQau7fmSEQMS2MzJ9kfIJRA":3,"$fkmgF-LdiP043YmO98nzk-gRy45ACIq0dRdgimbc2k84":258,"$fz1EhSFTW3K3totAVY-Q521O_I9PH8lu2R4erUngEjOQ":263},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":16,"requires_php":16,"tags":17,"homepage":16,"download_link":21,"security_score":22,"vuln_count":23,"unpatched_count":23,"last_vuln_date":24,"fetched_at":25,"discovery_status":26,"vulnerabilities":27,"developer":28,"crawl_stats":24,"alternatives":34,"analysis":136,"fingerprints":236},"bbpress-direct-quotes","bbPress Direct Quotes","1.1","destroflyer","https:\u002F\u002Fprofiles.wordpress.org\u002Fdestroflyer\u002F","\u003Cp>Adds a “Quote” link to each post, which inserts its content (inside of a \u003Cblockquote>) to the reply textfield.\u003Cbr \u002F>\nDeveloped for: http:\u002F\u002Fjmonkeyengine.org\u003C\u002Fp>\n","Adds a \"Quote\" link to each post, which inserts its content (inside of a \u003Cblockquote>) to the reply textfield.",20,4381,96,4,"2013-01-20T02:31:00.000Z","",[18,19,20],"bbpress","post","quotes","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbbpress-direct-quotes.zip",85,0,null,"2026-04-06T09:54:40.288Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":29,"total_installs":30,"avg_security_score":22,"avg_patch_time_days":31,"trust_score":32,"computed_at":33},3,60,30,84,"2026-08-29T19:40:22.675Z",[35,56,76,98,118],{"slug":36,"name":36,"version":37,"author":38,"author_profile":39,"description":40,"short_description":41,"active_installs":42,"downloaded":43,"rating":44,"num_ratings":45,"last_updated":46,"tested_up_to":47,"requires_at_least":48,"requires_php":16,"tags":49,"homepage":53,"download_link":54,"security_score":44,"vuln_count":23,"unpatched_count":23,"last_vuln_date":24,"fetched_at":55},"wpuntexturize","2.3","Scott Reilly","https:\u002F\u002Fprofiles.wordpress.org\u002Fcoffee2code\u002F","\u003Cp>By default, WordPress converts single and double quotation marks into their curly alternatives. This plugin prevents that from happening, so you can enjoy your quotation marks in their non-curly glory. If your content happens to already have curly quotation marks in it, then this plugin can optionally also convert them to their non-curly alternatives.\u003C\u002Fp>\n\u003Cp>\u003Cem>Note:\u003C\u002Fem> Despite the unfortunately misleading name, this plugin is NOT the antithesis of WordPress’s \u003Ccode>wptexturize()\u003C\u002Fcode> function. This ONLY prevents WordPress from making HTML entity code substitutions of single and double quotation marks with their curly alternatives and does NOT prevent \u003Ccode>wptexturize()\u003C\u002Fcode> from making any other character and string substitutions. See the FAQ for details on the filters processed by the plugin.\u003C\u002Fp>\n\u003Cp>Links: \u003Ca href=\"https:\u002F\u002Fcoffee2code.com\u002Fwp-plugins\u002Fwpuntexturize\u002F\" rel=\"nofollow ugc\">Plugin Homepage\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwpuntexturize\u002F\" rel=\"ugc\">Plugin Directory Page\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fcoffee2code\u002Fwpuntexturize\u002F\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fcoffee2code.com\" rel=\"nofollow ugc\">Author Homepage\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Developer Documentation\u003C\u002Fh3>\n\u003Cp>Developer documentation can be found in \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fcoffee2code\u002Fwpuntexturize\u002Fblob\u002Fmaster\u002FDEVELOPER-DOCS.md\" rel=\"nofollow ugc\">DEVELOPER-DOCS.md\u003C\u002Fa>. That documentation covers the numerous hooks provided by the plugin. Those hooks are listed below to provide an overview of what’s available.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>c2c_wpuntexturize\u003C\u002Fcode> : An alternative approach to safely invoke \u003Ccode>c2c_wpuntexturize()\u003C\u002Fcode> in such a way that if the plugin were deactivated or deleted, then your calls to the function won’t cause errors in your site. This only applies if you use the function directly, which is not typical usage for most users.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wpuntexturize_filters\u003C\u002Fcode> : customize what filters to hook to be filtered with wpuntexturize. See the Description section for a complete list of all filters that are filtered by default.\u003C\u002Fli>\n\u003Cli>\u003Ccode>c2c_wpuntexturize_replacements\u003C\u002Fcode> : Customize the character replacements handled by the plugin.\u003C\u002Fli>\n\u003Cli>\u003Ccode>c2c_wpuntexturize_convert_curly_quotes\u003C\u002Fcode> : Enable conversion of preexisting curly quotes into their non-curly alternatives.\u003C\u002Fli>\n\u003C\u002Ful>\n","Prevent WordPress from converting single and double quotation marks into their curly alternatives.",900,26453,92,12,"2025-04-08T22:17:00.000Z","6.8.6","5.5",[50,19,20,51,52],"formatting","substitutions","wptexturize","https:\u002F\u002Fcoffee2code.com\u002Fwp-plugins\u002Fwpuntexturize\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpuntexturize.2.3.zip","2026-07-22T17:31:50.256Z",{"slug":57,"name":58,"version":59,"author":60,"author_profile":61,"description":62,"short_description":63,"active_installs":64,"downloaded":65,"rating":66,"num_ratings":67,"last_updated":68,"tested_up_to":69,"requires_at_least":16,"requires_php":16,"tags":70,"homepage":74,"download_link":75,"security_score":66,"vuln_count":23,"unpatched_count":23,"last_vuln_date":24,"fetched_at":55},"bbp-last-post","bbp last post","1.7","Robin W","https:\u002F\u002Fprofiles.wordpress.org\u002Frobin-w\u002F","\u003Cp>This Plugin changes the ‘freshness ‘ that bbPress displays on topic and forum lists (eg 4 hours ago) to the date of the last post to that forum or topic (eg 17th January 2014 at 5.15pm).\u003C\u002Fp>\n\u003Cp>It also allows you to set the heading for this new date format.\u003C\u002Fp>\n\u003Cp>The existing (bbpress) Recent Topics widget works with date, but a revised Recent Replies Widget to display the date format called (Last Post) Recent Replies is included.\u003C\u002Fp>\n","For bbPress - changes the freshness displays to date",200,14150,100,10,"2026-06-11T15:59:00.000Z","7.0.2",[71,18,72,73,19],"bbp","forum","last","http:\u002F\u002Fwww.rewweb.co.uk\u002Fbbp-last-post-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbbp-last-post.1.7.zip",{"slug":77,"name":78,"version":79,"author":80,"author_profile":81,"description":82,"short_description":83,"active_installs":66,"downloaded":84,"rating":13,"num_ratings":85,"last_updated":86,"tested_up_to":87,"requires_at_least":88,"requires_php":16,"tags":89,"homepage":92,"download_link":93,"security_score":94,"vuln_count":29,"unpatched_count":95,"last_vuln_date":96,"fetched_at":97},"bbp-move-topics","bbPress Move Topics","1.1.6","Pascal Casier","https:\u002F\u002Fprofiles.wordpress.org\u002Fcasiepa\u002F","\u003Cp>Discussions start as comments on a post but you want them to continue on your forum? bbPress topics are not always created in the correct forum by users?\u003Cbr \u002F>\nThen use this tool to deal with it!\u003C\u002Fp>\n\u003Ch4>Move topics to another forum\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Move topic to another forum\u003C\u002Fli>\n\u003Cli>Hide topics so you do not need to deal with them again\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Convert (custom) post or page comments to topic with replies\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Delete comments after conversion to replies\u003C\u002Fli>\n\u003Cli>Add a new comment with the link to the forum\u003C\u002Fli>\n\u003Cli>Convert unapproved comments into unapproved replies\u003C\u002Fli>\n\u003Cli>Deal with anonymous user comments\u003C\u002Fli>\n\u003Cli>Cut topic or replies after a certain number of words\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Using\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Start from your dashboard on “Forum > Move Topics”\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>PS. Check out other plugins like \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbbp-toolkit\u002F\" rel=\"ugc\">bbP Toolkit\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002Fcasiepa#content-plugins\" rel=\"nofollow ugc\">more from me\u003C\u002Fa> to complete your bbPress experience\u003C\u002Fp>\n","Move topics from one forum to another, convert post\u002Fcomments into topic\u002Freplies in the same site. For the admin backend.",6705,6,"2018-03-11T13:09:00.000Z","4.9.29","3.9",[77,18,90,91],"comments-to-replies","post-to-topic","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbbp-move-topics\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbbp-move-topics.1.1.6.zip",58,1,"2025-07-16 00:00:00","2026-04-16T10:56:18.058Z",{"slug":99,"name":100,"version":101,"author":102,"author_profile":103,"description":104,"short_description":105,"active_installs":106,"downloaded":107,"rating":66,"num_ratings":29,"last_updated":108,"tested_up_to":109,"requires_at_least":110,"requires_php":16,"tags":111,"homepage":116,"download_link":117,"security_score":22,"vuln_count":23,"unpatched_count":23,"last_vuln_date":24,"fetched_at":55},"french-slugs","French Slugs","1.0","Residence mixte","https:\u002F\u002Fprofiles.wordpress.org\u002Fresidence-mixte\u002F","\u003Cp>Useful in french, with this plugin simple quotes (apostrophes) will be changed to dashes (-) to keep slugs readable and SEO friendly.\u003C\u002Fp>\n\u003Cp>Before :\u003C\u002Fp>\n\u003Cul>\n\u003Cli>“L’équipe” > lequipe\u003C\u002Fli>\n\u003Cli>“L’histoire de France” > lhistoire-de-france\u003C\u002Fli>\n\u003Cli>“Suzy’s Place” > suzys-place\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>With this plugin :\u003C\u002Fp>\n\u003Cul>\n\u003Cli>“L’équipe” > l-equipe\u003C\u002Fli>\n\u003Cli>“L’histoire de France” > l-histoire-de-france\u003C\u002Fli>\n\u003Cli>“Suzy’s Place” > suzy-s-place\u003C\u002Fli>\n\u003C\u002Ful>\n","Changes simple quotes (apostrophes) to dashes (-) to keep slugs readable and SEO friendly, mostly in French.",70,2397,"2013-05-23T12:02:00.000Z","3.5.2","3.2",[112,113,20,114,115],"apostrophe","french","slug","url","http:\u002F\u002Fresidence-mixte.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffrench-slugs.1.0.zip",{"slug":119,"name":120,"version":121,"author":122,"author_profile":123,"description":124,"short_description":125,"active_installs":106,"downloaded":126,"rating":13,"num_ratings":127,"last_updated":128,"tested_up_to":16,"requires_at_least":16,"requires_php":16,"tags":129,"homepage":134,"download_link":135,"security_score":22,"vuln_count":23,"unpatched_count":23,"last_vuln_date":24,"fetched_at":55},"hashbuddy","HashBuddy","1.5.2","modemlooper","https:\u002F\u002Fprofiles.wordpress.org\u002Fmodemlooper\u002F","\u003Cp>Hashtags for WordPress, BuddyPress and bbPress. Adds hashtag links to BuddyPress activity and bbPress topics. Hashtags turn into links that are used to search items based on topics.\u003C\u002Fp>\n\u003Cp>demo: http:\u002F\u002Fdemo.taptappress.com\u003C\u002Fp>\n","Hashtags for WordPress, BuddyPress and bbPress. Adds hashtag links to BuddyPress activity and bbPress topics. Hashtags turn into links that are used t &hellip;",14156,5,"2014-12-28T19:33:00.000Z",[130,18,131,132,133],"activity","buddypress","hashtags","posts","http:\u002F\u002Ftaptappress.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhashbuddy.1.5.2.zip",{"attackSurface":137,"codeSignals":157,"taintFlows":176,"riskAssessment":222,"analyzedAt":235},{"hooks":138,"ajaxHandlers":149,"restRoutes":154,"shortcodes":155,"cronEvents":156,"entryPointCount":95,"unprotectedCount":95},[139,145],{"type":140,"name":141,"callback":142,"file":143,"line":144},"action","init","bbpress_direct_quotes_Initialize","plugin.php",9,{"type":140,"name":146,"callback":147,"file":143,"line":148},"bbp_theme_before_reply_admin_links","bbpress_direct_quotes_AddQuoteLinkToReply",16,[150],{"action":151,"nopriv":152,"callback":151,"hasNonce":152,"hasCapCheck":152,"file":143,"line":153},"bbpress_direct_quotes_GetPostContent",false,15,[],[],[],{"dangerousFunctions":158,"sqlUsage":159,"outputEscaping":168,"fileOperations":23,"externalRequests":23,"nonceChecks":23,"capabilityChecks":23,"bundledLibraries":175},[],{"prepared":23,"raw":160,"locations":161},2,[162,165],{"file":143,"line":163,"context":164},23,"$wpdb->get_row() with variable interpolation",{"file":143,"line":166,"context":167},24,"$wpdb->get_var() with variable interpolation",{"escaped":160,"rawEcho":160,"locations":169},[170,173],{"file":143,"line":171,"context":172},25,"raw output",{"file":143,"line":174,"context":172},37,[],[177,208],{"entryPoint":178,"graph":179,"unsanitizedCount":29,"severity":207},"bbpress_direct_quotes_GetPostContent (plugin.php:20)",{"nodes":180,"edges":203},[181,185,190,193,197,199],{"id":182,"type":183,"label":184,"file":143,"line":163},"n0","source","$_POST['postID']",{"id":186,"type":187,"label":188,"file":143,"line":163,"wp_function":189},"n1","sink","get_row() [SQLi]","get_row",{"id":191,"type":183,"label":192,"file":143,"line":163},"n2","$_POST",{"id":194,"type":187,"label":195,"file":143,"line":166,"wp_function":196},"n3","get_var() [SQLi]","get_var",{"id":198,"type":183,"label":192,"file":143,"line":163},"n4",{"id":200,"type":187,"label":201,"file":143,"line":171,"wp_function":202},"n5","echo() [XSS]","echo",[204,205,206],{"from":182,"to":186,"sanitized":152},{"from":191,"to":194,"sanitized":152},{"from":198,"to":200,"sanitized":152},"high",{"entryPoint":209,"graph":210,"unsanitizedCount":29,"severity":207},"\u003Cplugin> (plugin.php:0)",{"nodes":211,"edges":218},[212,213,214,215,216,217],{"id":182,"type":183,"label":184,"file":143,"line":163},{"id":186,"type":187,"label":188,"file":143,"line":163,"wp_function":189},{"id":191,"type":183,"label":192,"file":143,"line":163},{"id":194,"type":187,"label":195,"file":143,"line":166,"wp_function":196},{"id":198,"type":183,"label":192,"file":143,"line":163},{"id":200,"type":187,"label":201,"file":143,"line":171,"wp_function":202},[219,220,221],{"from":182,"to":186,"sanitized":152},{"from":191,"to":194,"sanitized":152},{"from":198,"to":200,"sanitized":152},{"summary":223,"deductions":224},"The \"bbpress-direct-quotes\" plugin v1.1 presents a notable security risk due to its unprotected AJAX handler and raw SQL queries. The static analysis reveals one AJAX handler that lacks authentication checks, immediately exposing it as a potential entry point for unauthorized actions. Furthermore, all identified SQL queries are executed without prepared statements, a common vulnerability vector for SQL injection attacks.  The taint analysis confirms two high-severity flows with unsanitized paths, indicating that user-supplied data is being processed in a way that could lead to malicious execution or data compromise. The absence of any recorded vulnerability history might suggest a lack of prior exploitation or discovery, but this should not be interpreted as a sign of inherent security. The plugin's strengths lie in its lack of dangerous functions, external HTTP requests, and file operations. However, the identified weaknesses in input validation and database query sanitization are significant concerns that require immediate attention.",[225,227,229,231,233],{"reason":226,"points":67},"AJAX handler without auth checks",{"reason":228,"points":67},"SQL queries without prepared statements",{"reason":230,"points":153},"High severity taint flows with unsanitized paths",{"reason":232,"points":127},"Missing nonce checks",{"reason":234,"points":127},"Missing capability checks","2026-03-16T22:43:33.679Z",{"wat":237,"direct":245},{"assetPaths":238,"generatorPatterns":241,"scriptPaths":242,"versionParams":244},[239,240],"\u002Fwp-content\u002Fplugins\u002Fbbpress-direct-quotes\u002Fstyle.css","\u002Fwp-content\u002Fplugins\u002Fbbpress-direct-quotes\u002Fimages\u002Floader.gif",[],[243],"\u002Fwp-content\u002Fplugins\u002Fbbpress-direct-quotes\u002Fquotes.js",[],{"cssClasses":246,"htmlComments":248,"htmlAttributes":249,"restEndpoints":251,"jsGlobals":252,"shortcodeOutput":253},[247],"bbpress_direct_quotes_loader",[],[250],"onclick",[],[],[254,255,256,257],"\u003Ca href=\"#\" onclick=\"bbpress_direct_quotes_quotePost(","\"); return false;\">Quote\u003C\u002Fa>","\u003Cimg id=\"bbpress_direct_quotes_loader_","\" class=\"bbpress_direct_quotes_loader\" src=\"",{"error":259,"url":260,"statusCode":261,"statusMessage":262,"message":262},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fbbpress-direct-quotes\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":23,"versions":264},[]]