[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fku2Za3r6cPACFuKzL3BZnfsRsTVVh_tAEhC9lIvuwjo":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":14,"tags":17,"homepage":21,"download_link":22,"security_score":23,"vuln_count":13,"unpatched_count":13,"last_vuln_date":24,"fetched_at":25,"vulnerabilities":26,"developer":27,"crawl_stats":24,"alternatives":33,"analysis":126,"fingerprints":213},"comments-statistics","Display Comments Statistics","1.6.0","Marco Rodrigues","https:\u002F\u002Fprofiles.wordpress.org\u002Fgothicx\u002F","\u003Cp>This plugin shows the total number of articles and comments as well as statistics about which platforms and browsers were used in comment writing. It uses icons to identify both platforms and browsers.\u003Cbr \u002F>\nYou can see a screenshot of it at “Screenshots”. Worry not, the plugin is written in English 🙂\u003C\u002Fp>\n\u003Cp>This plugin was originally created by Mario Gamito (R.I.P). I think he deserves someone to maintain it.\u003C\u002Fp>\n","This plugin shows the total number of articles and comments as well as statistics about which platforms and browsers were used in comment writing.",10,11792,0,"","3.0.5","2.0.2",[18,19,20],"comments","sidebar","statistics","http:\u002F\u002Fwww.marblehole.com\u002Fcomments-plugin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcomments-statistics.zip",100,null,"2026-03-15T10:48:56.248Z",[],{"slug":28,"display_name":7,"profile_url":8,"plugin_count":29,"total_installs":11,"avg_security_score":23,"avg_patch_time_days":30,"trust_score":31,"computed_at":32},"gothicx",1,30,94,"2026-04-05T09:06:59.627Z",[34,55,73,90,108],{"slug":35,"name":36,"version":37,"author":38,"author_profile":39,"description":40,"short_description":41,"active_installs":42,"downloaded":43,"rating":44,"num_ratings":29,"last_updated":45,"tested_up_to":46,"requires_at_least":47,"requires_php":14,"tags":48,"homepage":51,"download_link":52,"security_score":53,"vuln_count":13,"unpatched_count":13,"last_vuln_date":24,"fetched_at":54},"most-popular-posts","Most Popular Posts","1.6.2","wesg","https:\u002F\u002Fprofiles.wordpress.org\u002Fwesg\u002F","\u003Cp>Most Popular Posts is a basic widget for your sidebar that creates a list of links to the top posts on your blog according to the number of comments on the post. You can customize many aspects of the plugin to fit in your blog.\u003C\u002Fp>\n\u003Cp>Updates include including and excluding categories, reverse the order of comments and incorporation of WordPress widget standards.\u003C\u002Fp>\n\u003Cp>For a complete list of the changes from each version, please visit \u003Ca href=\"http:\u002F\u002Fwww.wesg.ca\u002F2008\u002F08\u002Fwordpress-widget-most-popular\u002F#changelog\" rel=\"nofollow ugc\">the plugin homepage\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>For examples and tips on using the plugin, please check \u003Ca href=\"http:\u002F\u002Fwww.wesg.ca\u002F2008\u002F08\u002Fwordpress-widget-most-popular\u002F#examples\" rel=\"nofollow ugc\">the examples\u003C\u002Fa> on the plugin homepage.\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cp>Used exclusively as a widget at the current time.\u003C\u002Fp>\n","This is a very simple widget that displays a link to the top commented posts on your blog.",300,51094,40,"2013-02-14T04:23:00.000Z","3.5.2","2.8",[18,49,19,50],"most-popular","widget","http:\u002F\u002Fwww.wesg.ca\u002F2008\u002F08\u002Fwordpress-widget-most-popular\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmost-popular-posts.1.6.2.zip",85,"2026-03-15T15:16:48.613Z",{"slug":56,"name":57,"version":58,"author":59,"author_profile":60,"description":61,"short_description":62,"active_installs":63,"downloaded":64,"rating":23,"num_ratings":65,"last_updated":66,"tested_up_to":67,"requires_at_least":47,"requires_php":14,"tags":68,"homepage":71,"download_link":72,"security_score":23,"vuln_count":13,"unpatched_count":13,"last_vuln_date":24,"fetched_at":54},"top-commentators-widget","Top Commentators Widget","1.7","Lorna Timbah","https:\u002F\u002Fprofiles.wordpress.org\u002Fwebgrrrl\u002F","\u003Cp>This plugin creates a widget to show the top commentators in your WP site. Always go back to the Widget settings after each version update to Save your settings. Demo can be found at http:\u002F\u002Fdemo.webgrrrl.net\u003C\u002Fp>\n\u003Cp>The Top Commentators Widget plugin is adapted from Show Top Commentators plugin at Personal Financial Advice, this widget is easier to manage via the control form (no need to edit the PHP file); additional options are also available to make it more flexible. Read the FAQ section on how to customize the widget. Read the Changelog as well as http:\u002F\u002Fwebgrrrl.net\u002Ftags\u002Ftcw for the latest news on this widget.\u003C\u002Fp>\n\u003Cp>This widget is extensively tested with the following settings: Google Chrome 13.0.782.215 m, PHP 5.2.13, Apache 2.2.15 (Win32), MySQL 5.0.51a, WordPress 3.2.1. Further testing and bug report on this widget is greatly welcomed and appreciated.\u003C\u002Fp>\n","Adds a sidebar widget to show the top commentators in your WP site. Demo: http:\u002F\u002Fdemo.webgrrrl.net",200,156008,2,"2025-12-20T13:00:00.000Z","6.6.5",[18,69,70,19,50],"gravatar","seo","http:\u002F\u002Fwebgrrrl.net\u002Farchives\u002Fmy-top-commentators-widget-quick-dirty.htm","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftop-commentators-widget.1.7.zip",{"slug":74,"name":75,"version":76,"author":77,"author_profile":78,"description":79,"short_description":80,"active_installs":23,"downloaded":81,"rating":82,"num_ratings":83,"last_updated":84,"tested_up_to":85,"requires_at_least":86,"requires_php":14,"tags":87,"homepage":14,"download_link":89,"security_score":53,"vuln_count":13,"unpatched_count":13,"last_vuln_date":24,"fetched_at":54},"disqus-recent-comments-widget","Disqus Recent Comments Widget","1.2","Andrew Bartel","https:\u002F\u002Fprofiles.wordpress.org\u002Fandrew-bartel\u002F","\u003Cp>The Disqus Recent Comments Widget plugin will create a configurable widget that will allow you to display comments in any widgetized area of your theme like sidebars and footers.\u003C\u002Fp>\n\u003Cp>You can customize the comment length and date format, filter users and choose from three different markup templates, among other things.  The plugin has full support for custom markup defined with register_sidebars() and should integrate smoothly with most themes in the wp.org repository.\u003C\u002Fp>\n\u003Cp>We try to be very proactive and responsive with support.  So, if you have any issues, please post in the support forums and we’ll do our best to resolve your issue promptly.\u003C\u002Fp>\n\u003Cp>You can follow development here: https:\u002F\u002Fgithub.com\u002Fandrewbartel\u002FDisqus_Recent_Comments\u003C\u002Fp>\n","Disqus has dropped support for their recent comments widget.  This plugin creates a configurable widget that will display your latest Disqus comments.",25099,86,7,"2014-09-22T01:54:00.000Z","4.0.38","3.4.1",[18,88,19,50],"disqus","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdisqus-recent-comments-widget.zip",{"slug":91,"name":92,"version":93,"author":94,"author_profile":95,"description":96,"short_description":97,"active_installs":23,"downloaded":98,"rating":99,"num_ratings":100,"last_updated":14,"tested_up_to":101,"requires_at_least":102,"requires_php":14,"tags":103,"homepage":106,"download_link":107,"security_score":23,"vuln_count":13,"unpatched_count":13,"last_vuln_date":24,"fetched_at":25},"os-emi-calculator","EMI Calculator","1.0","vkt005","https:\u002F\u002Fprofiles.wordpress.org\u002Fvkt005\u002F","\u003Cp>Use EMI calculator as shortcode in post content or widget area without editing your theme files\u003C\u002Fp>\n\u003Cp>USAGE:\u003Cbr \u002F>\nUse [emicalc format=”full”][\u002Femicalc] OR [emicalc format=”sidebar”][\u002Femicalc] shortcode in your post content to show the EMI calculator without editing your theme files\u003Cbr \u002F>\nEXAMPLE:\u003Cbr \u002F>\n[emicalc format=”full”][\u002Femicalc] OR\u003Cbr \u002F>\nOR\u003Cbr \u002F>\n[emicalc format=”sidebar”][\u002Femicalc]\u003C\u002Fp>\n","Use EMI calculator as shortcode in post content or widget area without editing your theme files",7269,74,3,"3.7.41","2.0.5",[104,18,105,19,50],"calculator","match","http:\u002F\u002Fopensum.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fos-emi-calculator.zip",{"slug":109,"name":110,"version":111,"author":112,"author_profile":113,"description":114,"short_description":115,"active_installs":116,"downloaded":117,"rating":118,"num_ratings":100,"last_updated":119,"tested_up_to":101,"requires_at_least":120,"requires_php":14,"tags":121,"homepage":124,"download_link":125,"security_score":53,"vuln_count":13,"unpatched_count":13,"last_vuln_date":24,"fetched_at":54},"ff-tab-widget","FF Tab Widget","1.1","Kharis Sulistiyono","https:\u002F\u002Fprofiles.wordpress.org\u002Fkharisblank\u002F","\u003Cp>FF Tab Widget is a great solution for you to display different contents in a single widget. You can display popular posts, recent posts, recent commets, and tags in an animated tabs.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Easy to install, just drag the widget into your widgetized sidebar.\u003C\u002Fli>\n\u003Cli>Has widget options: Label name, limit tab content and show\u002Fhide tab item.\u003C\u002Fli>\n\u003Cli>Uses jQuery Tabs \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FamazingSurge\u002Fjquery-tabs\" rel=\"nofollow ugc\">script\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>If you’d like to contribute to the plugin you can find it on \u003Ca href=\"http:\u002F\u002Fgithub.com\u002Fkharissulistiyo\u002FFF-Tab-Widget\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>FF doesn’t stand for anything.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"http:\u002F\u002Fwww.kharissulistiyono.com\u002Fff-tab-widget-pro\u002F\" rel=\"nofollow ugc\">PRO version\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cp>Simply go to Appearance > Widgets and drag “FF Tab Widget” instance to the sidebar of your choice. Within the widget are several options where you can show\u002Fhide tab item and specifify the content limit. See the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fff-tab-widget\u002Fscreenshots\" rel=\"ugc\">screenshots\u003C\u002Fa> for more details.\u003C\u002Fp>\n\u003Ch4>Tabs Widget Style\u003C\u002Fh4>\n\u003Cp>The tab widget style tested on “Twenty Twelve” theme (see the plugin screenshot). It may look different on other themes. You can adjust its style by modifying CSS file (fftw.css) inside the plugin folder. To make developers easy to make modification I also profide the LESS file (fftw.less).\u003C\u002Fp>\n\u003Cp>If you do not have time to make your tabs widget looks beautiful on your theme, you can \u003Ca href=\"mailto:kharisblank@gmail.com\" rel=\"nofollow ugc\">contact me\u003C\u002Fa> for plugin customization service.\u003C\u002Fp>\n\u003Cp>Contact this \u003Ca href=\"http:\u002F\u002Fkharissulistiyo.com\" rel=\"nofollow ugc\">plugin author\u003C\u002Fa>.\u003C\u002Fp>\n","Display popular posts, recent posts, recent commets, and tags in an animated tabs in a single widget.",80,7765,46,"2014-01-09T17:16:00.000Z","3.0",[18,122,19,123,50],"posts","tags","https:\u002F\u002Fgithub.com\u002Fkharissulistiyo\u002FFF-Tab-Widget","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fff-tab-widget.zip",{"attackSurface":127,"codeSignals":139,"taintFlows":199,"riskAssessment":200,"analyzedAt":212},{"hooks":128,"ajaxHandlers":135,"restRoutes":136,"shortcodes":137,"cronEvents":138,"entryPointCount":13,"unprotectedCount":13},[129],{"type":130,"name":131,"callback":132,"file":133,"line":134},"action","post_submit","display_comment_stats","dcs.php",75,[],[],[],[],{"dangerousFunctions":140,"sqlUsage":141,"outputEscaping":185,"fileOperations":13,"externalRequests":13,"nonceChecks":13,"capabilityChecks":13,"bundledLibraries":198},[],{"prepared":13,"raw":142,"locations":143},20,[144,147,149,151,153,155,157,159,161,163,165,167,169,171,173,175,177,179,181,183],{"file":133,"line":145,"context":146},21,"$wpdb->get_var() with variable interpolation",{"file":133,"line":148,"context":146},26,{"file":133,"line":150,"context":146},27,{"file":133,"line":152,"context":146},34,{"file":133,"line":154,"context":146},35,{"file":133,"line":156,"context":146},36,{"file":133,"line":158,"context":146},37,{"file":133,"line":160,"context":146},38,{"file":133,"line":162,"context":146},52,{"file":133,"line":164,"context":146},53,{"file":133,"line":166,"context":146},54,{"file":133,"line":168,"context":146},55,{"file":133,"line":170,"context":146},56,{"file":133,"line":172,"context":146},57,{"file":133,"line":174,"context":146},58,{"file":133,"line":176,"context":146},59,{"file":133,"line":178,"context":146},60,{"file":133,"line":180,"context":146},61,{"file":133,"line":182,"context":146},62,{"file":133,"line":184,"context":146},63,{"escaped":13,"rawEcho":186,"locations":187},5,[188,191,193,195,196],{"file":133,"line":189,"context":190},23,"raw output",{"file":133,"line":192,"context":190},29,{"file":133,"line":194,"context":190},45,{"file":133,"line":118,"context":190},{"file":133,"line":197,"context":190},70,[],[],{"summary":201,"deductions":202},"The \"comments-statistics\" plugin v1.6.0 presents a concerning security posture due to significant code quality issues, despite the absence of known vulnerabilities and a seemingly small attack surface. The static analysis reveals a complete lack of output escaping and the use of raw SQL queries without prepared statements. This means that any data processed or displayed by the plugin is susceptible to injection attacks, including cross-site scripting (XSS) and SQL injection, as the input is not properly sanitized or validated before being outputted or used in database queries.  The absence of capability checks and nonce checks also raises alarms, as it implies that sensitive operations, if present, might be accessible to unauthenticated or low-privileged users.\n\nThe lack of any recorded vulnerabilities in its history is a positive sign, but it does not negate the severe coding flaws identified. It's possible that the plugin's functionality is limited, or that its usage is confined to environments where these vulnerabilities haven't been exploited. However, relying solely on this historical pattern would be imprudent given the identified code quality issues. The plugin exhibits a concerning disregard for fundamental security practices, making it a high-risk component, especially if it handles any user-provided data or interacts with sensitive WordPress functionalities.",[203,205,208,210],{"reason":204,"points":11},"SQL queries not using prepared statements",{"reason":206,"points":207},"Output not properly escaped",8,{"reason":209,"points":186},"No capability checks implemented",{"reason":211,"points":186},"No nonce checks implemented","2026-03-16T23:30:16.532Z",{"wat":214,"direct":236},{"assetPaths":215,"generatorPatterns":233,"scriptPaths":234,"versionParams":235},[216,217,218,219,220,221,222,223,224,225,226,227,228,229,230,231,232],"\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fwindows.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Flinux.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fmacos.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fwp.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fsun.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Ffirefox.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fie.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fsafari.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fopera.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Ficeweasel.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fkonqueror.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Flynx.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fnetnewswire.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fepiphany.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fbonecho.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fchrome.png","\u002Fwp-content\u002Fplugins\u002Fcomments-statistics\u002Fflock.png",[],[],[],{"cssClasses":237,"htmlComments":238,"htmlAttributes":239,"restEndpoints":240,"jsGlobals":241,"shortcodeOutput":242},[],[],[],[],[],[243,244],"\u003Ch2>Writing\u003C\u002Fh2>","\u003Ch2>Comments\u003C\u002Fh2>"]