[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAGzlOVEjCf7vT6jrgT51v8yUQOSyHS15o7P2zJjvn90":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":19,"download_link":20,"security_score":21,"vuln_count":13,"unpatched_count":13,"last_vuln_date":22,"fetched_at":23,"vulnerabilities":24,"developer":25,"crawl_stats":22,"alternatives":32,"analysis":33,"fingerprints":100},"colors-for-woocommerce","Colors For WooCommerce","1.0","seosbg","https:\u002F\u002Fprofiles.wordpress.org\u002Fseosbg\u002F","\u003Cp>Colors For WooCommerce is easy to use.\u003Cbr \u002F>\nTo learn more about the Colors For WooCommerce please see Plugin URI. See screenshot examples at http:\u002F\u002Fseosthemes.com\u002Fcolors-for-woocommerce\u002F\u003C\u002Fp>\n","Simple WordPress Plugin - Colors For WooCommerce.",10,2385,0,"2017-01-14T05:52:00.000Z","4.3.34","4.3.1","",[4],"http:\u002F\u002Fseosthemes.com\u002Fcolors-for-woocommerce","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcolors-for-woocommerce.zip",85,null,"2026-03-15T15:16:48.613Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":26,"total_installs":27,"avg_security_score":28,"avg_patch_time_days":29,"trust_score":30,"computed_at":31},74,10250,95,1,97,"2026-04-04T07:18:16.798Z",[],{"attackSurface":34,"codeSignals":62,"taintFlows":93,"riskAssessment":94,"analyzedAt":99},{"hooks":35,"ajaxHandlers":58,"restRoutes":59,"shortcodes":60,"cronEvents":61,"entryPointCount":13,"unprotectedCount":13},[36,42,46,50,54],{"type":37,"name":38,"callback":39,"file":40,"line":41},"action","admin_menu","colors_for_woocommerce_menu","colors-for-woocommerce.php",16,{"type":37,"name":43,"callback":44,"file":40,"line":45},"admin_init","colors_for_woocommerce_settings",22,{"type":37,"name":47,"callback":48,"file":40,"line":49},"admin_enqueue_scripts","colors_for_woocommerce_admin_scripts",38,{"type":37,"name":51,"callback":52,"file":40,"line":53},"init","colors_for_woocommerce_language_load",94,{"type":37,"name":55,"callback":56,"file":40,"line":57},"wp_head","colors_for_woocommerce_css",137,[],[],[],[],{"dangerousFunctions":63,"sqlUsage":64,"outputEscaping":66,"fileOperations":13,"externalRequests":13,"nonceChecks":13,"capabilityChecks":13,"bundledLibraries":92},[],{"prepared":13,"raw":13,"locations":65},[],{"escaped":13,"rawEcho":67,"locations":68},11,[69,72,74,76,78,80,82,84,86,88,90],{"file":40,"line":70,"context":71},55,"raw output",{"file":40,"line":73,"context":71},65,{"file":40,"line":75,"context":71},69,{"file":40,"line":77,"context":71},73,{"file":40,"line":79,"context":71},77,{"file":40,"line":81,"context":71},81,{"file":40,"line":83,"context":71},105,{"file":40,"line":85,"context":71},113,{"file":40,"line":87,"context":71},121,{"file":40,"line":89,"context":71},129,{"file":40,"line":91,"context":71},132,[],[],{"summary":95,"deductions":96},"The \"colors-for-woocommerce\" plugin v1.0 presents a concerning security posture despite having no recorded vulnerabilities or known CVEs. The static analysis reveals a significant weakness in its output escaping, with 0% of its 11 output operations being properly escaped. This is a critical flaw as it opens the door to Cross-Site Scripting (XSS) vulnerabilities, where malicious code could be injected into the website through user-generated or dynamic content.  While the plugin demonstrates good practices by not utilizing dangerous functions, performing SQL queries solely with prepared statements, and having no file operations or external HTTP requests, the lack of output escaping overshadows these strengths. The absence of any attack surface in terms of AJAX, REST API, shortcodes, or cron events is a positive aspect, but it doesn't mitigate the inherent XSS risk. The vulnerability history being clean is encouraging but, in conjunction with the static analysis findings, suggests a potential for undiscovered issues rather than a proven robust security.",[97],{"reason":98,"points":11},"No output properly escaped","2026-03-17T00:43:34.891Z",{"wat":101,"direct":110},{"assetPaths":102,"generatorPatterns":104,"scriptPaths":105,"versionParams":107},[103],"\u002Fwp-content\u002Fplugins\u002Fcolors-for-woocommerce\u002Fcss\u002Fadmin.css",[],[106],"\u002Fwp-content\u002Fplugins\u002Fcolors-for-woocommerce\u002Fjs\u002Fscript.js",[108,109],"colors-for-woocommerce\u002Fcss\u002Fadmin.css?ver=","colors-for-woocommerce\u002Fjs\u002Fscript.js?ver=",{"cssClasses":111,"htmlComments":114,"htmlAttributes":115,"restEndpoints":117,"jsGlobals":118,"shortcodeOutput":119},[4,112,113],"colors-for-woocommerce-seos","ss-logo",[],[116],"data-default-color",[],[],[]]