[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4l-q1JWURhwJHFcmV8OYf80UB53PEZQy9WPL_s4Vfmw":3,"$fcH7OGH6z7j2D15f1o7niF5qaJ6CAf1Fs8rXUNNlxcY0":241,"$fjlqx0bm3FzfPWeqgvVgQVgF3VnOWzBuEuEmzXVPG9iU":245},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":22,"download_link":23,"security_score":24,"vuln_count":25,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":48,"crawl_stats":35,"alternatives":55,"analysis":164,"fingerprints":226},"caret-country-access-limit","Caret Country Access Limit","1.0.4","caret","https:\u002F\u002Fprofiles.wordpress.org\u002Fcaret\u002F","\u003Ch3>APNICなどの機関で公開されているIPアドレスの一覧を自動取得し、.htaccessによるアクセス制限を国単位で行います。\u003C\u002Fh3>\n\u003Cp>紹介ページ\u003Cbr \u002F>\nhttp:\u002F\u002Fwww.ca-ret.co.jp\u002F?p=1172\u003C\u002Fp>\n\u003Cp>アクセス元の国を制限することにより、総当たり攻撃などの防止策になります。\u003Cbr \u002F>\nよろしければお試しください。\u003C\u002Fp>\n\u003Ch3>Arbitrary section\u003C\u002Fh3>\n\u003Ch3>■免責事項\u003C\u002Fh3>\n\u003Cp>本プラグインは無料でご利用いただけますが、ご自身の責任においてご利用ください。\u003Cbr \u002F>\n利用の結果生じた損害について、一切責任を負いません。予めご了承ください。\u003C\u002Fp>\n\u003Cp>お問い合わせ、ご意見、ご要望、不具合等は、以下お問い合わせフォームよりご連絡ください。\u003Cbr \u002F>\nhttp:\u002F\u002Fwww.ca-ret.co.jp\u002Fcontact\u003C\u002Fp>\n\u003Ch4>■関連事項\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>ISO 3166-1 wikipedia\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cblockquote>\n\u003Cp>http:\u002F\u002Fja.wikipedia.org\u002Fwiki\u002FISO_3166-1\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cul>\n\u003Cli>IPアドレスの管理について\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cblockquote>\n\u003Cp>https:\u002F\u002Fwww.nic.ad.jp\u002Fja\u002Fip\u002Fadmin.html\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>このプラグインは、国別のIPアドレスの取得の際に、インターネットレジストリを使用しています。\u003Cbr \u002F>\nThis plugin uses the internet registery in order to validate IP addresses.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Regional Internet Registry(RIR) database\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cblockquote>\n\u003Cp>ftp:\u002F\u002Fftp.arin.net\u002Fpub\u002Fstats\u002Farin\u002Fdelegated-arin-extended-latest\u003Cbr \u002F>\n  ftp:\u002F\u002Fftp.ripe.net\u002Fpub\u002Fstats\u002Fripencc\u002Fdelegated-ripencc-extended-latest\u003Cbr \u002F>\n  ftp:\u002F\u002Fftp.apnic.net\u002Fpub\u002Fstats\u002Fapnic\u002Fdelegated-apnic-extended-latest\u003Cbr \u002F>\n  ftp:\u002F\u002Fftp.lacnic.net\u002Fpub\u002Fstats\u002Flacnic\u002Fdelegated-lacnic-extended-latest\u003Cbr \u002F>\n  ftp:\u002F\u002Fftp.afrinic.net\u002Fpub\u002Fstats\u002Fafrinic\u002Fdelegated-afrinic-extended-latest\u003C\u002Fp>\n\u003C\u002Fblockquote>\n","国単位アクセス制限プラグイン - Caret Country Access Limit",10,2242,0,"2024-03-15T04:36:00.000Z","6.4.8","3.0.0","",[19,7,20,21],"admin","security","spam","http:\u002F\u002Fwww.ca-ret.co.jp\u002FWordPress\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcaret-country-access-limit.1.0.4.zip",85,1,"2023-10-12 00:00:00","2026-07-22T17:31:50.256Z","no_bundle",[30],{"id":31,"url_slug":32,"title":33,"description":34,"plugin_slug":4,"theme_slug":35,"affected_versions":36,"patched_in_version":37,"severity":38,"cvss_score":39,"cvss_vector":40,"vuln_type":41,"published_date":26,"updated_date":42,"references":43,"days_to_patch":45,"patch_diff_files":46,"patch_trac_url":35,"research_status":35,"research_verified":47,"research_rounds_completed":13,"research_plan":35,"research_summary":35,"research_vulnerable_code":35,"research_fix_diff":35,"research_exploit_outline":35,"research_model_used":35,"research_started_at":35,"research_completed_at":35,"research_error":35,"poc_status":35,"poc_video_id":35,"poc_summary":35,"poc_steps":35,"poc_tested_at":35,"poc_wp_version":35,"poc_php_version":35,"poc_playwright_script":35,"poc_exploit_code":35,"poc_has_trace":47,"poc_model_used":35,"poc_verification_depth":35},"CVE-2023-45641","caret-country-access-limit-cross-site-request-forgery","Caret Country Access Limit \u003C= 1.0.2 - Cross-Site Request Forgery","The Caret Country Access Limit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the 'start' function. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",null,"\u003C=1.0.2","1.0.3","medium",4.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Cross-Site Request Forgery (CSRF)","2024-03-25 16:36:38",[44],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F9f8c5853-6e21-4a70-a547-e3f0f4b1d7d0?source=api-prod",166,[],false,{"slug":7,"display_name":49,"profile_url":8,"plugin_count":50,"total_installs":51,"avg_security_score":52,"avg_patch_time_days":45,"trust_score":53,"computed_at":54},"garantieticaret",4,220,93,74,"2026-08-30T00:02:25.335Z",[56,75,96,120,142],{"slug":57,"name":58,"version":59,"author":60,"author_profile":61,"description":62,"short_description":63,"active_installs":13,"downloaded":64,"rating":13,"num_ratings":13,"last_updated":65,"tested_up_to":66,"requires_at_least":67,"requires_php":17,"tags":68,"homepage":73,"download_link":74,"security_score":24,"vuln_count":13,"unpatched_count":13,"last_vuln_date":35,"fetched_at":27},"admin-allow-by-ip","Admin Allow by IP","1.0.2","Apsara Aruna","https:\u002F\u002Fprofiles.wordpress.org\u002Fapsaraaruna\u002F","\u003Cp>Protect your admin form hackers!. You can allow your wp-admin for specific IP(s).\u003C\u002Fp>\n\u003Cp>You can select redirect after blocked wp-admin to others. and also you can customize as you want. we provide sample landing page \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fapsaraaruna\u002Fmaintenance-landing\" title=\"Landing page\" rel=\"nofollow ugc\">here\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Also see my other plugins\u003Cbr \u002F>\n* \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwidget-youtube-subscribtion\u002F\" title=\"Easy Subscribe Button Widget\" rel=\"ugc\">Easy Subscribe Button Widget\u003C\u002Fa> \u003Cbr \u002F>\n* \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fembed-page-facebook\u002F\" title=\"Easy Embed Page Widget\" rel=\"ugc\">Easy Embed Page Widget\u003C\u002Fa>\u003C\u002Fp>\n","Protect your admin form hackers!. You can allow your wp-admin for specific IP(s).",1599,"2023-10-19T10:42:00.000Z","6.3.8","5.0",[69,21,70,71,72],"securityadmin","wp-admin-login","wp-security","wp-security-whitelist-ip","http:\u002F\u002Fadmin-allow-by-ip","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadmin-allow-by-ip.1.0.2.zip",{"slug":76,"name":77,"version":78,"author":79,"author_profile":80,"description":81,"short_description":82,"active_installs":13,"downloaded":83,"rating":13,"num_ratings":13,"last_updated":84,"tested_up_to":85,"requires_at_least":86,"requires_php":87,"tags":88,"homepage":92,"download_link":93,"security_score":94,"vuln_count":13,"unpatched_count":13,"last_vuln_date":35,"fetched_at":95},"visitorlog","VisitorLog","1.0.5","IT Augustine","https:\u002F\u002Fprofiles.wordpress.org\u002Fitaugustine\u002F","\u003Cp>The plugin implements four main directions:\u003Cbr \u002F>\n1. Site security.\u003Cbr \u002F>\n2. Statistics of visits.\u003Cbr \u002F>\n3. Tabular and graphical representation of the necessary information for the site administrator.\u003Cbr \u002F>\n4. Necessary and useful functions in the work of the administrator.\u003C\u002Fp>\n\u003Ch4>1. Site Security\u003C\u002Fh4>\n\u003Cp>  • Registration of DDoS attacks;\u003Cbr \u002F>\n  • Protection from 404 events;\u003Cbr \u002F>\n  • Protection of the administrative panel;\u003Cbr \u002F>\n  • Protection of the database;\u003Cbr \u002F>\n  • File system protection;\u003Cbr \u002F>\n  • Spam protection in comments;\u003Cbr \u002F>\n  • Spam protection in feedback forms;\u003Cbr \u002F>\n  • Bot recognition;\u003Cbr \u002F>\n  • Blocking bots with control instructions in the file .htaccess;\u003Cbr \u002F>\n  • Blocking bots by redirection;\u003Cbr \u002F>\n  • Creation of a database of unwanted IP addresses (blacklist);\u003Cbr \u002F>\n  • Firewall.\u003C\u002Fp>\n\u003Ch4>2. Statistics of site visits\u003C\u002Fh4>\n\u003Cp>  • generating statistics of site visits by categories of visitors: visitors, administrators, bots;\u003Cbr \u002F>\n  • maintaining statistics of site visits by the hour;\u003Cbr \u002F>\n  • display statistics on the screen in the form of tables and graphs;\u003Cbr \u002F>\n  • statistics on IP addresses are stored in the database;\u003C\u002Fp>\n\u003Ch4>3. Reports, Tables, Logs\u003C\u002Fh4>\n\u003Cp>3.1 Reports\u003Cbr \u002F>\n    • Database backup report;\u003Cbr \u002F>\n    • system information (server, WordPress, PHP, MySQL, plugins, …);\u003Cbr \u002F>\n    • file and folder access report;\u003Cbr \u002F>\n    • Plugin update report.\u003Cbr \u002F>\n  3.2 Tables\u003Cbr \u002F>\n    • blacklist of unwanted IP addresses;\u003Cbr \u002F>\n    • address table when login to the admin panel fails;\u003Cbr \u002F>\n    • spam address table;\u003Cbr \u002F>\n    • address table at event 404;\u003Cbr \u002F>\n    • a table of unwanted IP addresses that the administrator creates independently;\u003Cbr \u002F>\n    • IP addresses can be entered into tables automatically or the administrator can enter them manually.\u003Cbr \u002F>\n    • IP addresses in the tables are blocked automatically or the administrator does it manually.\u003Cbr \u002F>\n  3.3 Logs\u003Cbr \u002F>\n    • visitor log (all site visitors, admins, bots are registered);\u003Cbr \u002F>\n    • Log with administrators’ IP addresses (all dynamic and static addresses are stored);\u003Cbr \u002F>\n    • account activity log, duration of sessions in the system;\u003Cbr \u002F>\n    • Action Log;\u003Cbr \u002F>\n    • Error log.\u003C\u002Fp>\n\u003Ch4>4. Other useful functions\u003C\u002Fh4>\n\u003Cp>  • site maintenance mode, blocking access to the site except for administrators;\u003Cbr \u002F>\n  • deleting all comments from the database;\u003Cbr \u002F>\n  • Cron, a log of scheduled tasks.\u003C\u002Fp>\n\u003Ch4>Documentation\u003C\u002Fh4>\n\u003Cp>  You can find a more detailed description in the documentation for the plugin or on our website.\u003Cbr \u002F>\n  Dev IT-Augustine\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>= https:\u002F\u002Fwww.google.com\u002Frecaptcha\u002Fapi.js\u003Cbr \u002F>\n  \u002F* PLEASE DO NOT COPY AND PASTE THIS CODE. *\u002F Google asks you not to insert this code into your scripts.\u003Cbr \u002F>\n  The plugin uses this to protect against spam in comments, as well as to protect against intruders when logging into the WordPress admin panel.\u003Cbr \u002F>\n  This service is provided by Google.\u003Cbr \u002F>\n  Link to privacy policy – wp-admin\u002Fadmin.php?page=visitorlog_privacy_policy\u003C\u002Fp>\n\u003Cp>= https:\u002F\u002Fwww.google.com\u002Frecaptcha\u002Fapi\u002Fsiteverify\u003Cbr \u002F>\n  Using this link, the plugin connects to the Google API to receive recaptcha.\u003Cbr \u002F>\n  The plugin uses this feature to protect against spam in comments, as well as to protect against intruders when logging into the admin panel of your WordPress site.\u003Cbr \u002F>\n  This service is provided by Google.\u003Cbr \u002F>\n  Link to privacy policy – wp-admin\u002Fadmin.php?page=visitorlog_privacy_policy\u003C\u002Fp>\n\u003Cp>= smtp.google.com\u003Cbr \u002F>\n  The plugin uses this link to the google SMTP mail resource to send messages from the site.\u003Cbr \u002F>\n  Link to privacy policy – wp-admin\u002Fadmin.php?page=visitorlog_privacy_policy\u003C\u002Fp>\n\u003Cp>= http:\u002F\u002F127.0.0.1\u003Cbr \u002F>\n  Using this link, the plugin redirects unwanted visitors, identified intruders who carry out attacks on the admin panel and pages of the WordPress site.\u003Cbr \u002F>\n  Link to privacy policy – wp-admin\u002Fadmin.php?page=visitorlog_privacy_policy\u003C\u002Fp>\n\u003Cp>= www.w3.org\u003Cbr \u002F>\n  The plugin uses this link in the bootstrap.css and maintenance.css style libraries, which are used to style the Visitorlog plugin frontend.\u003Cbr \u002F>\n  Link to privacy policy – wp-admin\u002Fadmin.php?page=visitorlog_privacy_policy\u003C\u002Fp>\n\u003Cp>= https:\u002F\u002Fitaugustine.com\u003Cbr \u002F>\n  This link connects the user to the developer’s website to access the full version of the plugin with advanced features.\u003Cbr \u002F>\n  Security Line developers.\u003Cbr \u002F>\n  Link to privacy policy – wp-admin\u002Fadmin.php?page=visitorlog_privacy_policy\u003C\u002Fp>\n\u003Cp>= https:\u002F\u002Fwww.gnu.org\u002Flicenses\u002Fgpl-2.0.txt\u003Cbr \u002F>\n  The plugin allows the user to click on the link and read the text of the GNU GENERAL PUBLIC LICENSE.\u003Cbr \u002F>\n  Link to privacy policy – wp-admin\u002Fadmin.php?page=visitorlog_privacy_policy\u003C\u002Fp>\n\u003Cp>= https:\u002F\u002Fwordpress.org\u002Fabout\u002Frequirements\u003Cbr \u002F>\n  https:\u002F\u002Fcodex.wordpress.org\u002FDebugging_in_WordPress\u003Cbr \u002F>\n  https:\u002F\u002Fdeveloper.wordpress.org\u002Fadvanced-administration\u002Fserver\u002Ffile-permissions\u002F\u003Cbr \u002F>\n  https:\u002F\u002Fdeveloper.wordpress.org\u002Fadvanced-administration\u002Fsecurity\u002Fhardening\u002F\u003Cbr \u002F>\n  https:\u002F\u002Fprofiles.wordpress.org\u002Fitaugustine\u002F\u003Cbr \u002F>\n  The plugin allows the user to use WordPress resources to obtain the necessary information.\u003Cbr \u002F>\n  Provided by https:\u002F\u002Fwordpress.org\u003Cbr \u002F>\n  Link to privacy policy – wp-admin\u002Fadmin.php?page=visitorlog_privacy_policy\u003C\u002Fp>\n","The VisitorLog plugin adds useful functionality to your site in the field of security, statistics and some other useful functions.",246,"2025-12-11T17:08:00.000Z","6.9.4","5.7","7.4",[89,90,91,20,21],"admin-protection","database-protection","ddos","https:\u002F\u002Fitaugustine.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitorlog.1.0.5.zip",100,"2026-03-15T15:16:48.613Z",{"slug":97,"name":98,"version":99,"author":100,"author_profile":101,"description":102,"short_description":103,"active_installs":104,"downloaded":105,"rating":106,"num_ratings":107,"last_updated":108,"tested_up_to":109,"requires_at_least":110,"requires_php":111,"tags":112,"homepage":115,"download_link":116,"security_score":117,"vuln_count":118,"unpatched_count":13,"last_vuln_date":119,"fetched_at":27},"loginizer","Loginizer","2.0.8","Softaculous","https:\u002F\u002Fprofiles.wordpress.org\u002Fsoftaculous\u002F","\u003Cp>Loginizer is a WordPress plugin which helps you fight against bruteforce attack by blocking login for the IP after it reaches maximum retries allowed. You can blacklist or whitelist IPs for login using Loginizer. You can use various other features like Two Factor Auth, reCAPTCHA, PasswordLess Login, etc. to improve security of your website.\u003C\u002Fp>\n\u003Cp>Loginizer is actively used by more than 1000000+ WordPress websites.\u003C\u002Fp>\n\u003Cp>You can find our official documentation at \u003Ca href=\"https:\u002F\u002Floginizer.com\u002Fdocs\" rel=\"nofollow ugc\">https:\u002F\u002Floginizer.com\u002Fdocs\u003C\u002Fa>. We are also active in our community support forums on \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Floginizer\" rel=\"ugc\">wordpress.org\u003C\u002Fa> if you are one of our free users. Our Premium Support Ticket System is at \u003Ca href=\"https:\u002F\u002Floginizer.deskuss.com\" rel=\"nofollow ugc\">https:\u002F\u002Floginizer.deskuss.com\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Free Features :\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Brute force protection. IPs trying to brute force your website will be blocked for 15 minutes after 3 failed login attempts. After multiple lockouts the IP is blocked for 24 hours. This is the default configuration and can be changed from Loginizer -> Brute force page in WordPress admin panel.\u003C\u002Fli>\n\u003Cli>Failed login attempts logs.\u003C\u002Fli>\n\u003Cli>Blacklist IPs\u003C\u002Fli>\n\u003Cli>Whitelist IPs\u003C\u002Fli>\n\u003Cli>Custom error messages on failed login.\u003C\u002Fli>\n\u003Cli>Permission check for important files and folders.\u003C\u002Fli>\n\u003Cli>Allow only Trusted IP.\u003C\u002Fli>\n\u003Cli>Blocked Screen in place of the Login page.\u003C\u002Fli>\n\u003Cli>Email Notification on successful login.\u003C\u002Fli>\n\u003Cli>Let users login with LinkedIn\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Get Support and Pro Features\u003C\u002Fh4>\n\u003Cp>Get professional support from our experts and pro features to take your site’s security to the next level with \u003Ca href=\"https:\u002F\u002Floginizer.com\u002Fpricing\" rel=\"nofollow ugc\">Loginizer-Security\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Pro Features :\u003C\u002Fp>\n\u003Cul>\n\u003Cli>MD5 Checksum – of Core WordPress Files. The admin can check and ignore files as well.\u003C\u002Fli>\n\u003Cli>PasswordLess Login – At the time of Login, the username \u002F email address will be asked and an email will be sent to the email address of that account with a temporary link to login.\u003C\u002Fli>\n\u003Cli>Two Factor Auth via Email – On login, an email will be sent to the email address of that account with a temporary 6 digit code to complete the login.\u003C\u002Fli>\n\u003Cli>Two Factor Auth via App – The user can configure the account with a 2FA App like Google Authenticator, Authy, etc.\u003C\u002Fli>\n\u003Cli>Login Challenge Question – The user can setup a Challenge Question and Answer as an additional security layer. After Login, the user will need to answer the question to complete the login.\u003C\u002Fli>\n\u003Cli>reCAPTCHA – Google’s reCAPTCHA v3\u002Fv2, Cloudflare Turnstile, hCAPTCHA can be configured for the Login screen, Comments Section, Registration Form, etc. to prevent automated brute force attacks. Supports WooCommerce as well.\u003C\u002Fli>\n\u003Cli>Rename Login Page – The Admin can rename the login URL (slug) to something different from wp-login.php to prevent automated brute force attacks.\u003C\u002Fli>\n\u003Cli>Rename WP-Admin URL – The Admin area in WordPress is accessed via wp-admin. With loginizer you can change it to anything e.g. site-admin\u003C\u002Fli>\n\u003Cli>CSRF Protection – This helps in preventing CSRF attacks as it updates the admin URL with a session string which makes it difficult and nearly impossible for the attacker to predict the URL.\u003C\u002Fli>\n\u003Cli>Rename Login with Secrecy – If set, then all Login URL’s will still point to wp-login.php and users will have to access the New Login Slug by typing it in the browser.\u003C\u002Fli>\n\u003Cli>Disable XML-RPC – An option to simply disable XML-RPC in WordPress. Most of the WordPress users don’t need XML-RPC and can disable it to prevent automated brute force attacks.\u003C\u002Fli>\n\u003Cli>Rename XML-RPC – The Admin can rename the XML-RPC to something different from xmlrpc.php to prevent automated brute force attacks.\u003C\u002Fli>\n\u003Cli>Username Auto Blacklist – Attackers generally use common usernames like admin, administrator, or variations of your domain name \u002F business name. You can specify such username here and Loginizer will auto-blacklist the IP Address(s) of clients who try to use such username(s).\u003C\u002Fli>\n\u003Cli>New Registration Domain Blacklist – If you would like to ban new registrations from a particular domain, you can use this utility to do so.\u003C\u002Fli>\n\u003Cli>Change the Admin Username – The Admin can rename the admin username to something more difficult.\u003C\u002Fli>\n\u003Cli>Auto Blacklist IPs – IPs will be auto blacklisted, if certain usernames saved by the Admin are used to login by malicious bots \u002F users.\u003C\u002Fli>\n\u003Cli>Disable Pingbacks – Simple way to disable PingBacks.\u003C\u002Fli>\n\u003Cli>SSO – Single Sign-on, let any user access to your WordPress Dashboard without the need to share username or password.\u003C\u002Fli>\n\u003Cli>Limit Concurrent Logins – It prevents user to login from different devices concurrently, you can define how many devices you want to allow, and how you want to restrict the user when concurrent limit is reached.\u003C\u002Fli>\n\u003Cli>Social Login – Users can login or register with their Google, Github, Facebook, X (Twitter), Discord, Twitch, LinkedIn, Microsoft with support for WooCommerce and Ultimate Member.\u003C\u002Fli>\n\u003Cli>Key Less Social Login – Use Loginizer’s Social Auth for easy key less Social login configuration, now supports Google, GitHub, X, LinkedIn more to be added later\u003C\u002Fli>\n\u003Cli>Country Blocking – Block IPs from specific countries to restrict access to your website.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Features in Loginizer include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Blocks IP after maximum retries allowed\u003C\u002Fli>\n\u003Cli>Extended Lockout after maximum lockouts allowed\u003C\u002Fli>\n\u003Cli>Email notification to admin after max lockouts\u003C\u002Fli>\n\u003Cli>Blacklist IP\u002FIP range\u003C\u002Fli>\n\u003Cli>Whitelist IP\u002FIP range\u003C\u002Fli>\n\u003Cli>Check logs of failed attempts\u003C\u002Fli>\n\u003Cli>Create IP ranges\u003C\u002Fli>\n\u003Cli>Delete IP ranges\u003C\u002Fli>\n\u003Cli>Licensed under LGPLv2.1\u003C\u002Fli>\n\u003Cli>Safe & Secure\u003C\u002Fli>\n\u003C\u002Ful>\n","Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.",1000000,30965148,96,1028,"2026-05-08T13:34:00.000Z","7.0.2","3.0","5.5",[113,19,114,97,20],"access","login","https:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Floginizer\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Floginizer.2.0.8.zip",87,8,"2024-11-04 00:00:00",{"slug":121,"name":122,"version":123,"author":124,"author_profile":125,"description":126,"short_description":127,"active_installs":128,"downloaded":129,"rating":130,"num_ratings":131,"last_updated":132,"tested_up_to":109,"requires_at_least":133,"requires_php":17,"tags":134,"homepage":138,"download_link":139,"security_score":140,"vuln_count":25,"unpatched_count":13,"last_vuln_date":141,"fetched_at":27},"sucuri-scanner","Sucuri Security – Auditing, Malware Scanner and Security Hardening","2.7.4","Sucuri","https:\u002F\u002Fprofiles.wordpress.org\u002Fsucuri\u002F","\u003Cp>At Sucuri, we are dedicated to keeping your website safe and secure. With a focus on protection and monitoring, we offer solutions that help you stay ahead of potential threats for your WordPress site.\u003C\u002Fp>\n\u003Cp>Our services include everything from malware detection to performance optimization, all designed to give you peace of mind.\u003C\u002Fp>\n\u003Cp>We understand the importance of your online presence and are here to support you every step of the way. Join us, and let’s work together to ensure your website remains secure and resilient.\u003C\u002Fp>\n\u003Cp>The Sucuri Security Monitoring Plugin is designed to safeguard your WordPress site with ease and reliability. Our plugin offers a range of essential security features, including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security Activity Auditing:\u003C\u002Fstrong> Keep track of every security-related event within your WordPress environment.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Integrity Monitoring:\u003C\u002Fstrong> Detect unauthorized changes to your files and protect your site from potential vulnerabilities.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remote Malware Scanning:\u003C\u002Fstrong> Regularly scan your site for malware with our remote scanner to ensure it’s clean and secure.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocklist Monitoring:\u003C\u002Fstrong> Receive alerts if your site is blocklisted by any major services, allowing for quick resolution.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Hardening:\u003C\u002Fstrong> Implement recommended security practices to fortify your site against threats.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Post-Hack Security Actions:\u003C\u002Fstrong> If the worst happens, our plugin helps you recover your site easily.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>With Sucuri, you can focus on what matters most—growing your website—while we handle the security. Our feature set provides a clear view of your site’s status, making it easy to manage, monitor and take action.\u003C\u002Fp>\n\u003Ch3>Contributors & Maintenance Notice\u003C\u002Fh3>\n\u003Cp>Our dedicated team of engineers and security analysts is continually working to enhance the Sucuri Security Monitoring Plugin.\u003C\u002Fp>\n\u003Cp>We provide regular updates, address bugs, and actively incorporate \u003Ca href=\"https:\u002F\u002Fsucuri.typeform.com\u002Fto\u002FqNe18eDf\" rel=\"nofollow ugc\">user feedback\u003C\u002Fa> to ensure your WordPress site maintains its highest security stance. Our growth roadmap underscores our commitment to keeping you protected against emerging threats.\u003C\u002Fp>\n\u003Cp>To support you further, we offer a variety of resources, including prompt responses for the forum, our website’s various content types, and an extensive \u003Ca href=\"https:\u002F\u002Fdocs.sucuri.net\u002F\" rel=\"nofollow ugc\">knowledge base\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Our content is designed to help you maximize your plugin feature usage and benefits with the support you need.\u003C\u002Fp>\n\u003Cp>If you want to be ahead of possible threats and keep up-to-date with Plugin updates, subscribe to our content \u003Ca href=\"https:\u002F\u002Finfo.sucuri.net\u002Fsubscribe-to-security\" rel=\"nofollow ugc\">here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Introducing the Sucuri Firewall + WordPress Security Plugin\u003C\u002Fh3>\n\u003Cp>We’re excited to introduce the Sucuri Firewall + WordPress Security Plugin, designed for those who seek advanced protection for their WordPress sites.\u003C\u002Fp>\n\u003Cp>Building upon our trusted free plugin, this premium offering provides a robust suite of features to ensure comprehensive security and peace of mind.\u003C\u002Fp>\n\u003Cp>Key features include:\u003Cbr \u002F>\n* \u003Cstrong>Web Application Firewall (WAF):\u003C\u002Fstrong> Protect your site from malicious traffic with our powerful firewall solution.\u003Cbr \u002F>\n* \u003Cstrong>Brute Force Protection:\u003C\u002Fstrong> Safeguard your site against unauthorized login attempts.\u003Cbr \u002F>\n* \u003Cstrong>Brute Force Audit & Reporting:\u003C\u002Fstrong> Gain insights into login attempts with detailed auditing and reporting.\u003Cbr \u002F>\n* \u003Cstrong>DDoS Mitigation: Maintain site\u003C\u002Fstrong> availability even during targeted attacks.\u003Cbr \u002F>\n* \u003Cstrong>Core Vulnerabilities Scanning:\u003C\u002Fstrong> Identify and address security weaknesses in WordPress core files.\u003Cbr \u002F>\n* \u003Cstrong>Plugins Vulnerability Scanning:\u003C\u002Fstrong> Ensure your installed plugins are secure and up to date.\u003Cbr \u002F>\n* \u003Cstrong>Themes Vulnerability Scanning:\u003C\u002Fstrong> Protect your site by scanning for vulnerabilities in installed themes.\u003Cbr \u002F>\n* \u003Cstrong>PHP Vulnerability Scanning:\u003C\u002Fstrong> Detect and address potential security issues in your PHP environment.\u003C\u002Fp>\n\u003Cp>With the \u003Ca href=\"https:\u002F\u002Fsucuri.net\u002Fwebsite-firewall\u002F\" rel=\"nofollow ugc\">Sucuri Firewall + WordPress Security Plugin\u003C\u002Fa>, you benefit from the expertise and dedication of our team, committed to keeping your digital assets secure.\u003C\u002Fp>\n\u003Cp>Experience the next level of protection and support, and enjoy the peace of mind that comes with knowing your site is in good hands.\u003C\u002Fp>\n","The Sucuri WordPress Security plugin is a security toolset for security integrity monitoring, malware detection and security hardening.",600000,36023943,84,384,"2026-07-07T15:41:00.000Z","3.6",[135,136,137,20,21],"firewall","malware","scan","https:\u002F\u002Fwordpress.sucuri.net\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsucuri-scanner.2.7.4.zip",99,"2022-09-14 00:00:00",{"slug":143,"name":144,"version":145,"author":146,"author_profile":147,"description":148,"short_description":149,"active_installs":150,"downloaded":151,"rating":152,"num_ratings":153,"last_updated":154,"tested_up_to":109,"requires_at_least":155,"requires_php":87,"tags":156,"homepage":160,"download_link":161,"security_score":106,"vuln_count":162,"unpatched_count":13,"last_vuln_date":163,"fetched_at":27},"admin-menu-editor","Admin Menu Editor","1.15.1","Janis Elsts","https:\u002F\u002Fprofiles.wordpress.org\u002Fwhiteshadow\u002F","\u003Cp>Admin Menu Editor lets you manually edit the Dashboard menu. You can reorder the menus, show\u002Fhide specific items, change permissions, and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Change menu titles, URLs, icons, CSS classes and so on.\u003C\u002Fli>\n\u003Cli>Organize menu items via drag & drop.\u003C\u002Fli>\n\u003Cli>Change menu permissions by setting the required capability or role.\u003C\u002Fli>\n\u003Cli>Move a menu item to a different submenu. \u003C\u002Fli>\n\u003Cli>Create custom menus that point to any part of the Dashboard or an external URL.\u003C\u002Fli>\n\u003Cli>Hide\u002Fshow any menu or menu item. A hidden menu is invisible to all users, including administrators.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The \u003Ca href=\"http:\u002F\u002Fw-shadow.com\u002FAdminMenuEditor\u002F\" rel=\"nofollow ugc\">Pro version\u003C\u002Fa> lets you set per-role menu permissions, hide a menu from everyone except a specific user, export your admin menu, drag items between menu levels, make menus open in a new window and more. \u003Ca href=\"http:\u002F\u002Famedemo.com\u002Fwpdemo\u002Fdemo.php\" rel=\"nofollow ugc\">Try online demo\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Additional Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Despite the name, this plugin is not limited to just editing the admin menu. You can also:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Create login redirects and logout redirects.\u003C\u002Fli>\n\u003Cli>Allow\u002Fdeny access to specific posts based on user roles.\u003C\u002Fli>\n\u003Cli>Hide plugins on the \u003Cem>Plugins -> Installed Plugins\u003C\u002Fem> page from other users.\u003C\u002Fli>\n\u003Cli>Edit the display name, description, and other plugin details shown on the \u003Cem>Plugins -> Installed Plugins\u003C\u002Fem> page (e.g. for white-labelling).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Shortcodes\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The plugin provides a few utility shortcodes. These are mainly intended to help with creating login\u002Flogout redirects, but you can also use them in posts and pages.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>[ame-wp-admin]\u003C\u002Fcode> – URL of the WordPress dashboard (with a trailing slash).\u003C\u002Fli>\n\u003Cli>\u003Ccode>[ame-home-url]\u003C\u002Fcode> – Site URL. Usually, this is the same as the URL in the “Site Address” field in \u003Cem>Settings -> General\u003C\u002Fem>.\u003C\u002Fli>\n\u003Cli>\u003Ccode>[ame-user-info field=\"...\"]\u003C\u002Fcode> – Information about the logged-in user. Parameters:\n\u003Cul>\n\u003Cli>\u003Ccode>field\u003C\u002Fcode> – The part of user profile to display. Supported fields include: \u003Ccode>ID\u003C\u002Fcode>, \u003Ccode>user_login\u003C\u002Fcode>, \u003Ccode>display_name\u003C\u002Fcode>, \u003Ccode>locale\u003C\u002Fcode>, \u003Ccode>user_nicename\u003C\u002Fcode>, \u003Ccode>user_url\u003C\u002Fcode>, and so on.\u003C\u002Fli>\n\u003Cli>\u003Ccode>placeholder\u003C\u002Fcode> – Optional. Text that will be shown if the visitor is not logged in.\u003C\u002Fli>\n\u003Cli>\u003Ccode>encoding\u003C\u002Fcode> – Optional. How to encode or escape the output. This is useful if you want to use the shortcode in your own HTML or JS code. Supported values: \u003Ccode>auto\u003C\u002Fcode> (default), \u003Ccode>html\u003C\u002Fcode>, \u003Ccode>attr\u003C\u002Fcode>, \u003Ccode>js\u003C\u002Fcode>, \u003Ccode>none\u003C\u002Fcode>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Notes\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>If you delete any of the default menus they will reappear after saving. This is by design. To get rid of a menu for good, either hide it or change it’s access permissions.\u003C\u002Fli>\n\u003Cli>In the free version, it’s not possible to give a role access to a menu item that it couldn’t see before. You can only restrict menu access further.\u003C\u002Fli>\n\u003Cli>In case of emergency, you can reset the menu configuration back to the default by going to http:\u002F\u002Fexample.com\u002Fwp-admin\u002F?reset_admin_menu=1 (replace example.com with your site URL). You must be logged in as an Administrator to do this.\u003C\u002Fli>\n\u003C\u002Ful>\n","Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.",300000,8117588,92,312,"2026-05-17T12:17:00.000Z","5.9",[19,157,158,20,159],"dashboard","menu","wpmu","http:\u002F\u002Fw-shadow.com\u002Fblog\u002F2008\u002F12\u002F20\u002Fadmin-menu-editor-for-wordpress\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadmin-menu-editor.1.15.1.zip",3,"2026-03-10 00:00:00",{"attackSurface":165,"codeSignals":186,"taintFlows":198,"riskAssessment":217,"analyzedAt":225},{"hooks":166,"ajaxHandlers":182,"restRoutes":183,"shortcodes":184,"cronEvents":185,"entryPointCount":13,"unprotectedCount":13},[167,173,178],{"type":168,"name":169,"callback":170,"file":171,"line":172},"action","admin_menu","countryLimitSetupLoad","CaretCountryAccessLimit.php",29,{"type":174,"name":175,"callback":176,"priority":11,"file":171,"line":177},"filter","plugin_action_links","countryLimitAddLink",30,{"type":168,"name":179,"callback":180,"priority":94,"file":171,"line":181},"admin_head","countryLimitAddJs",31,[],[],[],[],{"dangerousFunctions":187,"sqlUsage":192,"outputEscaping":194,"fileOperations":196,"externalRequests":13,"nonceChecks":25,"capabilityChecks":13,"bundledLibraries":197},[188],{"fn":189,"file":171,"line":190,"context":191},"exec",275,"@exec(\"nohup php -c '' '\".COUNTRY_LIMIT_BATCH_SCRIPT.\"' '\".$renew_only.\"' > \u002Fdev\u002Fnull &\");",{"prepared":13,"raw":13,"locations":193},[],{"escaped":172,"rawEcho":13,"locations":195},[],13,[],[199],{"entryPoint":200,"graph":201,"unsanitizedCount":13,"severity":216},"\u003Csetup> (setup.php:0)",{"nodes":202,"edges":213},[203,208],{"id":204,"type":205,"label":206,"file":207,"line":162},"n0","source","$_POST['country-limit_result']","setup.php",{"id":209,"type":210,"label":211,"file":207,"line":162,"wp_function":212},"n1","sink","echo() [XSS]","echo",[214],{"from":204,"to":209,"sanitized":215},true,"low",{"summary":218,"deductions":219},"The 'caret-country-access-limit' plugin presents a mixed security posture.  On the positive side, the static analysis indicates good practices in areas like output escaping and SQL query handling, with 100% of outputs being properly escaped and all SQL queries utilizing prepared statements. The absence of a large attack surface, especially with unprotected entry points, is also a strength. However, the presence of the `exec` function, which is inherently dangerous if not handled with extreme care and robust input validation, is a significant concern.  Furthermore, the vulnerability history shows one known medium severity CVE related to Cross-Site Request Forgery (CSRF), which, although currently patched, highlights a past weakness in input validation or nonce protection that could potentially resurface in future versions or be exploited in older, unpatched instances.",[220,223],{"reason":221,"points":222},"Presence of dangerous function `exec`",15,{"reason":224,"points":11},"One known medium CVE for CSRF","2026-03-16T22:35:02.404Z",{"wat":227,"direct":234},{"assetPaths":228,"generatorPatterns":230,"scriptPaths":231,"versionParams":232},[229],"\u002Fwp-content\u002Fplugins\u002Fcaret-country-access-limit\u002Fsetup.js",[],[229],[233],"caret-country-access-limit\u002Fsetup.js?ver=",{"cssClasses":235,"htmlComments":236,"htmlAttributes":237,"restEndpoints":238,"jsGlobals":239,"shortcodeOutput":240},[],[],[],[],[],[],{"error":215,"url":242,"statusCode":243,"statusMessage":244,"message":244},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fcaret-country-access-limit\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":246,"versions":247},5,[248,253,259,266,274],{"version":6,"download_url":23,"svn_tag_url":249,"released_at":35,"has_diff":47,"diff_files_changed":250,"diff_lines":35,"trac_diff_url":251,"vulnerabilities":252,"is_current":215},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fcaret-country-access-limit\u002Ftags\u002F1.0.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fcaret-country-access-limit%2Ftags%2F1.0.3&new_path=%2Fcaret-country-access-limit%2Ftags%2F1.0.4",[],{"version":37,"download_url":254,"svn_tag_url":255,"released_at":35,"has_diff":47,"diff_files_changed":256,"diff_lines":35,"trac_diff_url":257,"vulnerabilities":258,"is_current":47},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcaret-country-access-limit.1.0.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fcaret-country-access-limit\u002Ftags\u002F1.0.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fcaret-country-access-limit%2Ftags%2F1.0.2&new_path=%2Fcaret-country-access-limit%2Ftags%2F1.0.3",[],{"version":59,"download_url":260,"svn_tag_url":261,"released_at":35,"has_diff":47,"diff_files_changed":262,"diff_lines":35,"trac_diff_url":263,"vulnerabilities":264,"is_current":47},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcaret-country-access-limit.1.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fcaret-country-access-limit\u002Ftags\u002F1.0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fcaret-country-access-limit%2Ftags%2F1.0.1&new_path=%2Fcaret-country-access-limit%2Ftags%2F1.0.2",[265],{"id":31,"url_slug":32,"title":33,"severity":38,"cvss_score":39,"vuln_type":41,"patched_in_version":37},{"version":267,"download_url":268,"svn_tag_url":269,"released_at":35,"has_diff":47,"diff_files_changed":270,"diff_lines":35,"trac_diff_url":271,"vulnerabilities":272,"is_current":47},"1.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcaret-country-access-limit.1.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fcaret-country-access-limit\u002Ftags\u002F1.0.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fcaret-country-access-limit%2Ftags%2F1.0.0&new_path=%2Fcaret-country-access-limit%2Ftags%2F1.0.1",[273],{"id":31,"url_slug":32,"title":33,"severity":38,"cvss_score":39,"vuln_type":41,"patched_in_version":37},{"version":275,"download_url":276,"svn_tag_url":277,"released_at":35,"has_diff":47,"diff_files_changed":278,"diff_lines":35,"trac_diff_url":35,"vulnerabilities":279,"is_current":47},"1.0.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcaret-country-access-limit.1.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fcaret-country-access-limit\u002Ftags\u002F1.0.0\u002F",[],[280],{"id":31,"url_slug":32,"title":33,"severity":38,"cvss_score":39,"vuln_type":41,"patched_in_version":37}]