[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBG0SOa0kh6niArxNfc2tc24-bN9MVaXlfRx-FWRNRw8":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"vulnerabilities":31,"developer":32,"crawl_stats":29,"alternatives":40,"analysis":63,"fingerprints":162},"devvn-float-left-right-ads","DevVn Float Left Right Ads","1.0.9","Le Van Toan","https:\u002F\u002Fprofiles.wordpress.org\u002Flevantoan\u002F","\u003Cp>DevVn Float Left Right Ads help you add ads to left and right fixed position\u003C\u002Fp>\n","DevVn Float Left Right Ads help you add ads to left and right fixed position.",1000,29069,100,4,"2024-06-12T19:37:00.000Z","6.5.8","4.3","",[20,21,22,23,24],"float-ads","float-adv","float-advertising","float-left-ads","float-right-ads","https:\u002F\u002Flevantoan.com\u002Fdevvn-float-left-right-ads\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdevvn-float-left-right-ads.1.0.9.zip",92,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":33,"display_name":7,"profile_url":8,"plugin_count":34,"total_installs":35,"avg_security_score":36,"avg_patch_time_days":37,"trust_score":38,"computed_at":39},"levantoan",8,43660,94,85,84,"2026-04-04T17:42:24.393Z",[41],{"slug":42,"name":43,"version":44,"author":45,"author_profile":46,"description":47,"short_description":48,"active_installs":49,"downloaded":50,"rating":51,"num_ratings":52,"last_updated":53,"tested_up_to":54,"requires_at_least":55,"requires_php":18,"tags":56,"homepage":61,"download_link":62,"security_score":37,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"float-ads-fixed-position","Float Ads Fixed Position","1.0","saokim","https:\u002F\u002Fprofiles.wordpress.org\u002Fsaokim\u002F","\u003Cp>This plugin usefull for advertising on sidebar. Ads will drift vertically down to the footer, ads will disappear. The position of ads always fixed while it appear. See the demo of script here: http:\u002F\u002Flogoart.vn\u002Ffiles\u002Fadmicro.html\u003C\u002Fp>\n\u003Cp>How to use?\u003C\u002Fp>\n\u003Cp>Easy to use this plugin. After download and active this plugin, goto Appearance –> Widget –> find Float Ads Fixed Position and drag it to your sidebar. Fill content and configuration and goto front-end to see it.\u003C\u002Fp>\n","This plugin usefull for advertising on sidebar. Ads will drift vertically down to the footer, ads will disappear. The position of ads always fixed whi &hellip;",20,6258,86,3,"2013-03-14T04:41:00.000Z","3.5.2","2.8",[57,58,59,60,20],"ads-fixed-position","advertising","banner-fixed-position","fixed-ads","http:\u002F\u002Fblog.casanova.vn\u002Ffloat-ads-fixed-position\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffloat-ads-fixed-position.zip",{"attackSurface":64,"codeSignals":87,"taintFlows":155,"riskAssessment":156,"analyzedAt":161},{"hooks":65,"ajaxHandlers":83,"restRoutes":84,"shortcodes":85,"cronEvents":86,"entryPointCount":28,"unprotectedCount":28},[66,71,75,79],{"type":67,"name":68,"callback":68,"file":69,"line":70},"action","admin_menu","left-right-ads\\devvn-float-left-right-ads.php",33,{"type":67,"name":72,"callback":73,"file":69,"line":74},"admin_init","register_mysettings",34,{"type":67,"name":76,"callback":77,"file":69,"line":78},"wp_enqueue_scripts","flra_scripts",35,{"type":67,"name":80,"callback":81,"file":69,"line":82},"wp_footer","flra_footer",36,[],[],[],[],{"dangerousFunctions":88,"sqlUsage":89,"outputEscaping":91,"fileOperations":28,"externalRequests":28,"nonceChecks":28,"capabilityChecks":28,"bundledLibraries":154},[],{"prepared":28,"raw":28,"locations":90},[],{"escaped":92,"rawEcho":78,"locations":93},29,[94,96,97,98,99,100,101,103,106,108,110,112,114,116,117,118,119,120,122,124,126,128,130,132,134,136,138,139,140,142,144,146,148,150,152],{"file":69,"line":37,"context":95},"raw output",{"file":69,"line":37,"context":95},{"file":69,"line":37,"context":95},{"file":69,"line":51,"context":95},{"file":69,"line":51,"context":95},{"file":69,"line":51,"context":95},{"file":69,"line":102,"context":95},89,{"file":104,"line":105,"context":95},"left-right-ads\\options-page.php",18,{"file":104,"line":107,"context":95},19,{"file":104,"line":109,"context":95},25,{"file":104,"line":111,"context":95},26,{"file":104,"line":113,"context":95},27,{"file":104,"line":115,"context":95},28,{"file":104,"line":92,"context":95},{"file":104,"line":92,"context":95},{"file":104,"line":78,"context":95},{"file":104,"line":82,"context":95},{"file":104,"line":121,"context":95},37,{"file":104,"line":123,"context":95},38,{"file":104,"line":125,"context":95},39,{"file":104,"line":127,"context":95},45,{"file":104,"line":129,"context":95},51,{"file":104,"line":131,"context":95},58,{"file":104,"line":133,"context":95},59,{"file":104,"line":135,"context":95},68,{"file":104,"line":137,"context":95},72,{"file":104,"line":37,"context":95},{"file":104,"line":102,"context":95},{"file":104,"line":141,"context":95},99,{"file":104,"line":143,"context":95},106,{"file":104,"line":145,"context":95},113,{"file":104,"line":147,"context":95},120,{"file":104,"line":149,"context":95},127,{"file":104,"line":151,"context":95},133,{"file":104,"line":153,"context":95},140,[],[],{"summary":157,"deductions":158},"The plugin 'devvn-float-left-right-ads' v1.0.9 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the code demonstrates good practices with 100% of SQL queries utilizing prepared statements and no file operations or external HTTP requests observed. The lack of any recorded vulnerabilities in its history is also a positive indicator.\n\nHowever, a notable area of concern is the output escaping. With 64 total outputs, only 45% are properly escaped. This leaves a substantial portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is not handled securely before being displayed. The absence of nonce checks and capability checks, while less critical given the limited attack surface, could become a concern if the plugin were to introduce new entry points in future versions without proper authorization mechanisms.\n\nIn conclusion, while the plugin is currently very secure in terms of its attack surface and SQL handling, the significant percentage of unescaped output represents a tangible risk. Addressing this weakness should be a priority to further strengthen the plugin's security. The absence of historical vulnerabilities is promising, but the identified output escaping issue warrants attention.",[159],{"reason":160,"points":34},"Significant percentage of outputs not properly escaped","2026-03-16T18:47:33.162Z",{"wat":163,"direct":170},{"assetPaths":164,"generatorPatterns":166,"scriptPaths":167,"versionParams":168},[165],"\u002Fwp-content\u002Fplugins\u002Fdevvn-float-left-right-ads\u002Ffloat-left-right.js",[],[165],[169],"devvn-float-left-right-ads\u002Ffloat-left-right.js?ver=",{"cssClasses":171,"htmlComments":172,"htmlAttributes":173,"restEndpoints":174,"jsGlobals":175,"shortcodeOutput":177},[],[],[],[],[176],"flra_array",[178,179],"\u003Cdiv id=\"divFLRARight\"","\u003Cdiv id=\"divFLRALeft\""]