[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fssYF0b3hv2SwDTLo_ZaGrnDqtmy4cyUMhttpVa3RF14":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":18,"download_link":24,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28,"vulnerabilities":29,"developer":30,"crawl_stats":27,"alternatives":36,"analysis":127,"fingerprints":183},"bulk-plugin-installation","Bulk Plugin Installation","1.1","Cristian Beckerle","https:\u002F\u002Fprofiles.wordpress.org\u002Festudiobee\u002F","\u003Cp>This plugin is an improvement to the current WordPress plugin installation methods. It allows you to install one or more plugins simply by typing their names or download URLs in a textarea.\u003C\u002Fp>\n\u003Cp>All credit goes to \u003Cstrong>improvingtheweb\u003C\u002Fstrong>. This plugin is only a modification of \u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fimproved-plugin-installation\u002F\" rel=\"ugc\">Improved Plugin Installation\u003C\u002Fa>\u003C\u002Fstrong>. The idea was to run the original plugin in the newer versions of WordPress. That’s it. Also, we cut off the bookmarklet feature.\u003C\u002Fp>\n\u003Cp>Thank you very much for the contributions: \u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002Fdrewapicture\u002F\" rel=\"nofollow ugc\">drewapicture\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Example\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The installation form will accept any of these inputs:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Contact Form 7\u003C\u002Fli>\n\u003Cli>https:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fcontact-form-7\u002F\u003C\u002Fli>\n\u003Cli>https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcontact-form-7.3.3.2.zip\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Plugins don’t need to be hosted at wordpress.org. As long as you use the direct download URL, third party plugins will install without a problem.\u003C\u002Fp>\n","Allows you to install one or more plugins simply by typing their names or download URLs in a textarea.",300,23802,72,10,"2013-01-14T14:12:00.000Z","3.5.2","2.7","",[20,21,22,23],"admin","automation","install","plugins","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbulk-plugin-installation.1.1.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"estudiobee",1,30,84,"2026-04-04T05:24:31.339Z",[37,58,76,92,111],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":50,"requires_at_least":51,"requires_php":18,"tags":52,"homepage":55,"download_link":56,"security_score":57,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"wpcore","WPCore Plugin Manager","1.9.2","stueynet","https:\u002F\u002Fprofiles.wordpress.org\u002Fstueynet\u002F","\u003Cp>WPCore is a tool that allows you to manage collections of WordPress plugins and then quickly install them on any WordPress site. You can generate your collections at https:\u002F\u002Fwpcore.com and then import them to your WordPress site by copying and pasting your unique collection key in WordPress.\u003C\u002Fp>\n","Create plugin collections and install them in one click on any WordPress site.",10000,168565,96,32,"2025-05-20T17:15:00.000Z","6.8.5","3.5",[20,53,22,54,23],"administration","installation","https:\u002F\u002Fwpcore.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpcore.1.9.2.zip",100,{"slug":59,"name":60,"version":61,"author":62,"author_profile":63,"description":64,"short_description":65,"active_installs":66,"downloaded":67,"rating":13,"num_ratings":68,"last_updated":69,"tested_up_to":70,"requires_at_least":71,"requires_php":18,"tags":72,"homepage":74,"download_link":75,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"install-profiles","WP Install Profiles","3.4.1","rockgod100","https:\u002F\u002Fprofiles.wordpress.org\u002Frockgod100\u002F","\u003Cp>Save time setting up new sites by automatically downloading groups of plugins. Add new plugins by adding the slug from the plugin’s url in the WordPress plugin directory. For instance, the plugin “All In One SEO Pack” is listed here: \u003Ccode>https:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fall-in-one-seo-pack\u002F\u003C\u002Fcode>. Add “All In One SEO Pack” to an installation profile by adding \u003Ccode>all-in-one-seo-pack\u003C\u002Fcode> in the plugins field (one plugin per line).\u003C\u002Fp>\n\u003Cp>WP Install Profiles (WPIP) allows users to define groups of plugins, called profiles. Once a profile has been entered, WPIP calls to the WordPress Plugin Directory, downloads the plugin files and unzips them to the site’s plugins folder. Additionally, WPIP saves the profile in a downloadable format, so you can upload it to your next site and download the same plugins with a single click.\u003C\u002Fp>\n\u003Cp>Store your profiles online at http:\u002F\u002Fplugins.ancillaryfactory.com and import them easily into all of your WordPress installs. \u003Ca href=\"http:\u002F\u002Fplugins.ancillaryfactory.com\" rel=\"nofollow ugc\">Learn more and create an account\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>See Install Profiles in action: \u003Ca href=\"http:\u002F\u002Fwww.youtube.com\u002Fwatch?v=W-mBhPA1XGA\" rel=\"nofollow ugc\">http:\u002F\u002Fwww.youtube.com\u002Fwatch?v=W-mBhPA1XGA\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Troubleshooting\u003C\u002Fh3>\n\u003Ch4>Required PHP libraries\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>SimpleXML\u003C\u002Fli>\n\u003Cli>ZipArchive\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>These libraries are installed by default on most shared hosting accounts, but they may need to be installed manually if your site is hosted by certain providers, including Media Temple.\u003C\u002Fp>\n\u003Ch4>File Permissions\u003C\u002Fh4>\n\u003Cp>If you are unable to save or import profiles, you may need to set \u003Ccode>wp-content\u002Fplugins\u002Finstall-profiles\u002Fprofiles\u003C\u002Fcode> to 777.\u003C\u002Fp>\n","Download custom collections of plugins automatically from the WordPress plugin directory.",400,20134,9,"2013-05-22T01:17:00.000Z","3.6.1","3.1",[20,53,54,23,73],"wp","http:\u002F\u002Fplugins.ancillaryfactory.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finstall-profiles.zip",{"slug":77,"name":78,"version":79,"author":80,"author_profile":81,"description":82,"short_description":83,"active_installs":14,"downloaded":84,"rating":57,"num_ratings":32,"last_updated":85,"tested_up_to":86,"requires_at_least":87,"requires_php":18,"tags":88,"homepage":90,"download_link":91,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"plugin-installer-speedup","Plugin Installer Speedup","0.2.2","Viktor Szépe","https:\u002F\u002Fprofiles.wordpress.org\u002Fszepeviktor\u002F","\u003Cp>Speed up plugin installation.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Don’t load featured plugins.\u003C\u002Fli>\n\u003Cli>Make Search Plugins button visible.\u003C\u002Fli>\n\u003Cli>Set focus to search field.\u003C\u002Fli>\n\u003Cli>Skip plugin install confirmation.\u003C\u002Fli>\n\u003Cli>Add admin menu items under “Plugins” for Upload Plugin and Favorites.\u003C\u002Fli>\n\u003Cli>Add admin bar menu item under “+ New”.\u003C\u002Fli>\n\u003Cli>Remove “-master” from (mainly GitHub) ZIP archive names.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>No admin page for this plugin. Ready to go right after activation.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fszepeviktor\u002Fplugin-installer-speedup\" rel=\"nofollow ugc\">GitHub repository\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>The feature of plugin upload from URL has been moved to a\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fszepeviktor\u002Fwordpress-plugin-construction\u002Fblob\u002Fmaster\u002Fmu-plugin-upload-from-url\u002Fplugin-upload-from-url.php\" rel=\"nofollow ugc\">MU plugin\u003C\u002Fa>.\u003C\u002Fp>\n","Make plugin installation faster.",2140,"2017-01-12T18:52:00.000Z","4.7.32","4.0",[53,54,89],"upload-plugins","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fplugin-installer-speedup\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fplugin-installer-speedup.0.2.2.zip",{"slug":93,"name":94,"version":95,"author":96,"author_profile":97,"description":98,"short_description":99,"active_installs":14,"downloaded":100,"rating":26,"num_ratings":26,"last_updated":101,"tested_up_to":102,"requires_at_least":103,"requires_php":104,"tags":105,"homepage":109,"download_link":110,"security_score":57,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"za-my-favorite-plugins-installer","ZA My Favorite Plugins Installer","2.0","Zeeshan Arshad","https:\u002F\u002Fprofiles.wordpress.org\u002Fzeeshanarshad\u002F","\u003Cp>\u003Cstrong>ZA My Favorite Plugins Installer (ZAMFPI)\u003C\u002Fstrong> is a high-performance tool built for the modern WordPress development landscape. Whether you are a freelancer managing multiple client environments or an expert developer deploying your signature stack, this tool provides a high-speed “one-click” bridge to your favorite tools.\u003C\u002Fp>\n\u003Cp>This 2.0 update is a total refactor of the original engine, stripped of legacy code and rebuilt for modern WordPress (Core 6.7+).\u003C\u002Fp>\n","Professional-grade automation. Download, install, and activate custom plugin collections with a single click.",1716,"2025-12-21T06:17:00.000Z","6.9.4","6.0","7.4",[21,106,107,108,23],"custom","installer","oneclick","https:\u002F\u002Fgithub.com\u002Fzeeshanarshad","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fza-my-favorite-plugins-installer.2.0.3.zip",{"slug":112,"name":113,"version":114,"author":115,"author_profile":116,"description":117,"short_description":118,"active_installs":26,"downloaded":119,"rating":26,"num_ratings":26,"last_updated":18,"tested_up_to":102,"requires_at_least":103,"requires_php":104,"tags":120,"homepage":18,"download_link":125,"security_score":57,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":126},"dazestack-bulk-plugin-manager","DazeStack Bulk Plugin Manager","0.0.1","Ashish Dung Dung","https:\u002F\u002Fprofiles.wordpress.org\u002Fashishdungdung\u002F","\u003Cp>Welcome to the \u003Cstrong>DazeStack Bulk Plugin Manager (DSBPM)\u003C\u002Fstrong>, the ultimate utility for WordPress professionals who demand both power and aesthetics. Say goodbye to the tedious, one-by-one plugin installation process and hello to a streamlined, beautifully designed bulk management workspace.\u003C\u002Fp>\n\u003Cp>Crafted by Ashish Dungdung under the DazeStack brand, this tool is designed from the ground up to bring a premium, native modern app experience directly to your WordPress admin dashboard. It’s fast, elegant, and designed to save you hours of repetitive work.\u003C\u002Fp>\n\u003Ch3>🌟 Why Choose DazeStack Bulk Plugin Manager?\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Lightning Fast Provisioning\u003C\u002Fstrong>: Install, activate, deactivate, or delete multiple plugins simultaneously with a single click.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Premium Mac-Style UI\u003C\u002Fstrong>: Experience a WordPress dashboard like never before. DSBPM features a stunning, glassmorphic UI inspired by modern macOS design. It’s dark-mode ready, visually clean, and a joy to use.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-Click Import & Export\u003C\u002Fstrong>: Found the perfect stack of plugins? Export your list and import it into any other site in seconds using JSON, CSV, or raw text.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pre-Flight Safety Checks\u003C\u002Fstrong>: Real-time validation checks ensure the plugins you are bulk installing are available and safe before you commit changes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No Coding Required\u003C\u002Fstrong>: Forget complex WP-CLI commands. Everything is handled through an intuitive, fluid visual interface.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🚀 Key Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Bulk Actions\u003C\u002Fstrong>: Install, Activate, Deactivate, and Delete.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stack Imports\u003C\u002Fstrong>: Paste a comma-separated list of plugin slugs, or upload a JSON\u002FCSV file.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Instant Export\u003C\u002Fstrong>: Backup your currently active plugin stack to re-use on client sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Scanning (Optional)\u003C\u002Fstrong>: Integration with WPScan API to ensure your plugin stack is secure.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Non-Intrusive\u003C\u002Fstrong>: Leaves zero footprint on your website’s frontend. 100% focused on wp-admin optimization.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>💼 Who is this for?\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Freelancers & Agencies\u003C\u002Fstrong>: Standardize your “base recipe” of plugins across all new client projects.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developers\u003C\u002Fstrong>: Quickly spin up testing environments with your required toolsets.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Power Users\u003C\u002Fstrong>: Keep your site’s backend organized and efficiently manage heavy plugin loads.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin interacts with the following external services to provide plugin information, metrics, and security checks:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>WordPress.org Plugins API\u003C\u002Fstrong>: Used to fetch plugin metadata (title, version, last updated, active installs) and download links for bulk installation.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Data sent: Plugin slugs.\u003C\u002Fli>\n\u003Cli>Purpose: Core functionality for plugin discovery and provisioning.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>WPScan API\u003C\u002Fstrong>: Used (optionally) to check for known vulnerabilities in queued plugins.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Data sent: Plugin slugs and (if provided by user) a WPScan API key.\u003C\u002Fli>\n\u003Cli>Purpose: Security auditing of the plugin stack.\u003C\u002Fli>\n\u003Cli>Terms: \u003Ca href=\"https:\u002F\u002Fwpscan.com\u002Fterms\" rel=\"nofollow ugc\">WPScan Terms of Service\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fwpscan.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Google Sheets (CSV Export)\u003C\u002Fstrong>: Used to fetch curated partner recommendations.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Data sent: None (read-only fetch).\u003C\u002Fli>\n\u003Cli>Purpose: Providing relevant toolkit suggestions.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Fol>\n","The most beautiful, native Mac-like bulk plugin manager for WordPress. Import, export, and provision plugin stacks in one streamlined workspace.",207,[121,21,122,123,124],"admin-tools","bulk-install","migration","plugin-management","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdazestack-bulk-plugin-manager.0.0.1.zip","2026-03-15T10:48:56.248Z",{"attackSurface":128,"codeSignals":148,"taintFlows":175,"riskAssessment":176,"analyzedAt":182},{"hooks":129,"ajaxHandlers":144,"restRoutes":145,"shortcodes":146,"cronEvents":147,"entryPointCount":26,"unprotectedCount":26},[130,136,140],{"type":131,"name":132,"callback":133,"file":134,"line":135},"filter","install_plugins_nonmenu_tabs","extra_tabs","bulk-plugin-installation.php",33,{"type":137,"name":138,"callback":138,"file":134,"line":139},"action","install_plugins_dashboard",34,{"type":137,"name":141,"callback":142,"file":134,"line":143},"install_plugins_bpi","bpi",35,[],[],[],[],{"dangerousFunctions":149,"sqlUsage":150,"outputEscaping":152,"fileOperations":26,"externalRequests":26,"nonceChecks":32,"capabilityChecks":32,"bundledLibraries":174},[],{"prepared":26,"raw":26,"locations":151},[],{"escaped":153,"rawEcho":68,"locations":154},2,[155,158,160,162,164,166,168,170,172],{"file":134,"line":156,"context":157},58,"raw output",{"file":134,"line":159,"context":157},146,{"file":134,"line":161,"context":157},148,{"file":134,"line":163,"context":157},152,{"file":134,"line":165,"context":157},155,{"file":134,"line":167,"context":157},157,{"file":134,"line":169,"context":157},168,{"file":134,"line":171,"context":157},177,{"file":134,"line":173,"context":157},185,[],[],{"summary":177,"deductions":178},"The plugin 'bulk-plugin-installation' v1.1 exhibits a strong security posture based on the provided static analysis and vulnerability history.  The absence of any detected attack surface, dangerous functions, direct SQL queries, file operations, or external HTTP requests is highly commendable.  The presence of a nonce check and capability check further bolsters its security by ensuring proper authorization and integrity for its operations.  The vulnerability history being completely clean also indicates a mature and secure development lifecycle for this plugin.\n\nHowever, a significant concern arises from the low percentage of properly escaped output (18%). This suggests that user-supplied data or dynamic content displayed by the plugin might be susceptible to Cross-Site Scripting (XSS) vulnerabilities. While taint analysis did not reveal any specific unsanitized flows, this output escaping deficiency is a common vector for client-side attacks.  A more thorough review of how the plugin handles and displays dynamic data would be prudent.\n\nIn conclusion, the plugin is generally well-secured with a minimal attack surface and no known historical vulnerabilities. The primary weakness lies in the inadequate output escaping, which presents a potential risk for XSS attacks. Addressing this specific area would significantly improve the plugin's overall security.",[179],{"reason":180,"points":181},"Low percentage of properly escaped output",7,"2026-03-16T19:54:02.211Z",{"wat":184,"direct":191},{"assetPaths":185,"generatorPatterns":186,"scriptPaths":187,"versionParams":189},[],[],[188],"\u002Fwp-content\u002Fplugins\u002Fbulk-plugin-installation\u002Fjs\u002Fbpi.js",[190],"bulk-plugin-installation\u002Fjs\u002Fbpi.js?ver=",{"cssClasses":192,"htmlComments":193,"htmlAttributes":194,"restEndpoints":195,"jsGlobals":196,"shortcodeOutput":197},[],[],[],[],[],[]]