[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_SQkfbNqixHZQqqQXxqy1L74N_hhdvDDisdZ27S92VM":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":27,"vuln_count":28,"unpatched_count":29,"last_vuln_date":30,"fetched_at":31,"vulnerabilities":32,"developer":63,"crawl_stats":38,"alternatives":71,"analysis":177,"fingerprints":558},"easy-upload-files-during-checkout","Easy Upload Files During Checkout","3.0.1","Fahad Mahmood","https:\u002F\u002Fprofiles.wordpress.org\u002Ffahadmahmood\u002F","\u003Cul>\n\u003Cli>Author: \u003Ca href=\"https:\u002F\u002Fwww.androidbubbles.com\u002Fcontact\" rel=\"nofollow ugc\">Fahad Mahmood\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Project URI: \u003Ca href=\"http:\u002F\u002Fandroidbubble.com\u002Fblog\u002Fwufdc\" rel=\"nofollow ugc\">http:\u002F\u002Fandroidbubble.com\u002Fblog\u002Fwufdc\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Multiple Attachments (For Advanced Users): \u003Ca href=\"https:\u002F\u002Fshop.androidbubbles.com\u002Fproduct\u002Fwoocommerce-upload-files-checkout\" rel=\"nofollow ugc\">https:\u002F\u002Fshop.androidbubbles.com\u002Fproduct\u002Fwoocommerce-upload-files-checkout\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Demo URI: \u003Ca href=\"http:\u002F\u002Fdemo.androidbubble.com\u002Fproduct\u002Ffurniture\" rel=\"nofollow ugc\">http:\u002F\u002Fdemo.androidbubble.com\u002Fproduct\u002Ffurniture\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>License: GPL 3. See License below for copyright jots and tittles.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Attach files during checkout process with ease. Easy Upload Files During Checkout is a free plugin with a few premium features. It provides the facility of attaching files with orders during checkout. You can set display for uploading button on cart page, checkout page or checkout page after notes. For product pages, you will need premium version. Some check boxes on settings page to attach or detach billing\u002Fshipping details, order comments, secure file links and enable upload after login\u002Fregister. You can also choose a checkbox to send attachments in email.\u003Cbr \u002F>\nYou can control allowed files types on settings page like doc,txt,jpeg,png in an input text field. You can set upload file required with toggle button and specify maximum upload size in Megabytes on settings page. Example is available there. It provides secure storage for your upload files\u002Fdirectories with Amazon, it’s a new and premium feature. Setup your account on Amazon and get safe and secure storage for your important uploads. The premium version allows you to upload multiple files, change loading animation and display browse button on product page. It also provides an optional tab, with that tab you can select products which you want to whiteflag for upload files. By default, it is enabled for all products.\u003C\u002Fp>\n\u003Cp>If you want new users to provide some required information (ID, resume etc.) you can enable new users to upload file(s) while registering even for the first time. On settings tab check the radio button “Registration Page” next to “Display on:” and browse button will appear on registration page. If you make upload field required, a warning message will appear that  file is not uploaded.\u003C\u002Fp>\n\u003Ch4>Tags\u003C\u002Fh4>\n\u003Cp>woocommerce, order, wpml\u003C\u002Fp>\n\u003Ch3>Basic Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Display on cart on page (during checkout)\u003C\u002Fli>\n\u003Cli>Editable caption and success message\u003C\u002Fli>\n\u003Cli>Set image dimensions for uploading\u003C\u002Fli>\n\u003Cli>Define maximum upload size\u003C\u002Fli>\n\u003Cli>Specify allowed file types\u003C\u002Fli>\n\u003Cli>Upload single file (Only one file one)\u003C\u002Fli>\n\u003Cli>Make upload field required\u003C\u002Fli>\n\u003Cli>Define error message\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Advanced Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Shortcode + Compatibility with Hello Elementor WordPress Themes\u003C\u002Fli>\n\u003Cli>Display on product page\u003C\u002Fli>\n\u003Cli>Display on top of the checkout page\u003C\u002Fli>\n\u003Cli>Display on thank you page\u003C\u002Fli>\n\u003Cli>Display on order view page\u003C\u002Fli>\n\u003Cli>Upload files to directory with Amazon (Optional)\u003C\u002Fli>\n\u003Cli>File thumbnails\u002Ficons with filename\u003C\u002Fli>\n\u003Cli>Change loading animation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Beta Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Display on registration page\u003C\u002Fli>\n\u003Cli>Upload multiple files during registration\u003C\u002Fli>\n\u003Cli>Make upload field required on registration page\u003C\u002Fli>\n\u003Cli>Define error message on registration page\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Basic Version Demo\u003C\u002Fh4>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FGrQxj3olZ9E?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch4>Premium Version Demo\u003C\u002Fh4>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002Fp1m3-HuxVt8?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch4>Variable Products Demo\u003C\u002Fh4>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002F5uFQX7G7pn4?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch4>Using Hello Elementor WordPress Themes?\u003C\u002Fh4>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FJVYiwN7J7FQ?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This WordPress Plugin is free software: you can redistribute it and\u002For modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or any later version. This free software is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this software. If not, see http:\u002F\u002Fwww.gnu.org\u002Flicenses\u002Fgpl-2.0.html.\u003C\u002Fp>\n","Attach files during checkout process on cart page with ease.",600,127284,94,60,"2026-02-05T11:59:00.000Z","6.9.4","3.0","7.0",[20,21,22,23,24],"attach-files","checkout-process","during-checkout-process","login","upload-files","https:\u002F\u002Fandroidbubble.com\u002Fblog\u002Fwordpress\u002Fplugins\u002Feasy-upload-files-during-checkout","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Feasy-upload-files-during-checkout.3.0.1.zip",93,2,0,"2025-12-31 00:00:00","2026-03-15T15:16:48.613Z",[33,48],{"id":34,"url_slug":35,"title":36,"description":37,"plugin_slug":4,"theme_slug":38,"affected_versions":39,"patched_in_version":6,"severity":40,"cvss_score":41,"cvss_vector":42,"vuln_type":43,"published_date":30,"updated_date":44,"references":45,"days_to_patch":47},"CVE-2025-62078","easy-upload-files-during-checkout-missing-authorization","Easy Upload Files During Checkout \u003C= 3.0.0 - Missing Authorization","The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.",null,"\u003C=3.0.0","medium",4.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Missing Authorization","2026-02-06 17:33:34",[46],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fb712250f-4315-4188-bbe1-c2991a10ad3f?source=api-prod",38,{"id":49,"url_slug":50,"title":51,"description":52,"plugin_slug":4,"theme_slug":38,"affected_versions":53,"patched_in_version":54,"severity":55,"cvss_score":56,"cvss_vector":57,"vuln_type":58,"published_date":59,"updated_date":60,"references":61,"days_to_patch":28},"CVE-2025-12682","easy-upload-files-during-checkout-unauthenticated-arbitrary-javascript-file-upload","Easy Upload Files During Checkout \u003C= 2.9.8 - Unauthenticated Arbitrary JavaScript File Upload","The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in the 'file_during_checkout' function in all versions up to, and including, 2.9.8. This makes it possible for unauthenticated attackers to upload arbitrary JavaScript files on the affected site's server which may make remote code execution possible.","\u003C=2.9.8","2.9.9","critical",9.8,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H","Unrestricted Upload of File with Dangerous Type","2025-11-03 00:00:00","2025-11-04 13:47:39",[62],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F6a050764-0ba6-49a4-bd71-f79e3129fc4c?source=api-prod",{"slug":64,"display_name":7,"profile_url":8,"plugin_count":65,"total_installs":66,"avg_security_score":67,"avg_patch_time_days":68,"trust_score":69,"computed_at":70},"fahadmahmood",40,32660,96,237,76,"2026-04-04T02:46:45.405Z",[72,93,116,137,157],{"slug":73,"name":74,"version":75,"author":76,"author_profile":77,"description":78,"short_description":79,"active_installs":80,"downloaded":81,"rating":80,"num_ratings":28,"last_updated":82,"tested_up_to":83,"requires_at_least":84,"requires_php":85,"tags":86,"homepage":89,"download_link":90,"security_score":13,"vuln_count":91,"unpatched_count":29,"last_vuln_date":92,"fetched_at":31},"file-uploader-for-woocommerce","File Uploader for WooCommerce","1.0.4","Snowray Software","https:\u002F\u002Fprofiles.wordpress.org\u002Fsnowray\u002F","\u003Cul>\n\u003Cli>Project URI: \u003Ca href=\"http:\u002F\u002Fsnowray.co\" rel=\"nofollow ugc\">http:\u002F\u002Fsnowray.co\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Demo URI: \u003Ca href=\"http:\u002F\u002Fwoocommerce-test.snowray.co\u002F\" rel=\"nofollow ugc\">http:\u002F\u002Fwoocommerce-test.snowray.co\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Finally, a bloat-free solution to accept user uploads for your WooCommerce store. Let customers attach images and files relevant to their orders – with no support emails required, ever!\u003C\u002Fp>\n\u003Cp>File Uploader for WooCommerce is a plugin for customers to upload files when adding a product to cart – directly from their phone, computer, Instagram, Dropbox and other accounts. A must-have for shops that personalize merch or print on demand. It’s built on top of a specialized uploading infrastructure — meaning every file goes through, and so does your revenue!\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>\u003Cstrong>Since we integrated the file uploader plugin, our customers made 2x many orders. Upload is fast and using links is more convenient than downloading and emailing files to our typography.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>CoPrint CEO\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>✅ ENABLE EASY FILE UPLOADS ON CERTAIN PRODUCTS\u003Cbr \u002F>\nActivate image and file uploads when adding to cart. Simply enable the File Uploader plugin on relevant product categories, and your users will do the rest unattended.\u003C\u002Fp>\n\u003Cp>Upload images or files when adding to cart\u003Cbr \u002F>\nEnable the functionality on any number of categories\u003Cbr \u002F>\n14 upload sources: phone, desktop, camera, cloud & social accounts\u003Cbr \u002F>\nCross-reference uploads to orders in your WooCommerce Admin\u003C\u002Fp>\n\u003Cp>👨‍👩‍👦‍👦 USE CASES – WHO IS THIS FOR?\u003Cbr \u002F>\nIf your WooCommerce store offers any kind of personalization, you need an easy way for users to send you images or files related to their order. Whether you customize merch or work on customers’ digital files, this is the plugin for you.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Print-on-demand shops\u003C\u002Fli>\n\u003Cli>Personalized products or brand collateral\u003C\u002Fli>\n\u003Cli>Design and creative services\u003C\u002Fli>\n\u003Cli>Media or file editing services\u003C\u002Fli>\n\u003Cli>Legal or admin work requiring document upload\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>📂 SUPPORT 14 FILE SOURCES OUT OF THE BOX\u003Cbr \u002F>\nReduce friction by letting customers select files wherever they already are:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Phone or desktop: local disk, local camera, any URL\u003C\u002Fli>\n\u003Cli>Cloud storage: Google Drive, Google Photos, Dropbox, OneDrive, Box\u003C\u002Fli>\n\u003Cli>Social: Facebook, Instagram, Evernote, Flickr, VK, Huddle\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Upload sources are supported natively, so you don’t need to do any integrations or compliance work.\u003C\u002Fp>\n\u003Cp>🛡KEEP FILES SAFE, AND EASY TO FIND\u003Cbr \u002F>\nProcessing orders is as easy as it can be. For each uploaded file, the plugin stores a unique link that can be found by ‘seller’ in the WooCommerce order view, as well as in the order notification email you get as a seller.\u003C\u002Fp>\n\u003Cp>▶️ FREE PLUGIN: UPLOAD ANY IMAGES\u003Cbr \u002F>\nThe free version of File Uploader for WooCommerce supports all image files, and works on any number of product categories where you enable it. Usage limits are generous, and made to save us infrastructure costs.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>All image types supported\u003C\u002Fli>\n\u003Cli>Data retention for one month\u003C\u002Fli>\n\u003Cli>One file upload per product\u003C\u002Fli>\n\u003Cli>1,000 uploads per month\u003C\u002Fli>\n\u003Cli>Customers can preview or delete files\u003C\u002Fli>\n\u003Cli>Crop freely: users can crop images to any crop ratio they like\u003C\u002Fli>\n\u003Cli>Image editor: enhance, sharpen and rotate images after uploading (enable\u002Fdisable entire feature)\u003C\u002Fli>\n\u003Cli>Loads super-fast and works on all devices\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>⭐️ \u003Ca href=\"https:\u002F\u002Fsnowray.co\u002F\" rel=\"nofollow ugc\">PAID PLUGIN\u003C\u002Fa> FEATURES\u003Cbr \u002F>\nThe Pro version is on its way! Expect a great deal of customization and power-ups for your seller workflow:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cul>\n\u003Cli>Multiple files upload*  – Decide how many files can be uploaded per product\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Customize product targeting settings – allows file uploads on specific products only\u003C\u002Fli>\n\u003Cli>Customize text of the label that will appear above the upload button\u003C\u002Fli>\n\u003Cli>Customize upload button appearance\u003C\u002Fli>\n\u003Cli>More supported file types (videos, PDF, docs, design files and more)\u003C\u002Fli>\n\u003Cli>Add a text field to each uploaded file for customers to add a note or caption\u003C\u002Fli>\n\u003Cli>Crop presets: users can crop images using crop ratios you pre-define\u003C\u002Fli>\n\u003Cli>Image editor: enhance, sharpen and rotate images during upload (you enable\u002Fdisable individual operations)\u003C\u002Fli>\n\u003Cli>Require minimum image size to filter out low-quality images\u003C\u002Fli>\n\u003Cli>Higher data retention period: 3 months\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>⚙️ UNDER THE HOOD\u003Cbr \u002F>\nThe File Uploader plugin is nimble and lightweight… on both your site speed and admin time. It’s not bloated by features you don’t need, and it’s built on a leading Content Delivery Network specialized in uploads:  with a 99.99% uptime you can be sure every file will go through.\u003C\u002Fp>\n\u003Cp>❓SUPPORT AND SUGGESTIONS\u003Cbr \u002F>\nWe welcome all and every feedback! And while you’ll see your support queries tumble down (thanks, automated file uploads), we’re always ready to answer yours. Contact us at support@snowray.co and we will address all your burning questions.\u003C\u002Fp>\n","Allows to attach files from different sources to WooCommerce customer orders.",100,4926,"2025-12-18T16:21:00.000Z","6.8.5","5.0","7.4",[20,22,87,88,24],"image-upload","image-uploader","https:\u002F\u002Fsnowray.co\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffile-uploader-for-woocommerce.1.0.4.zip",1,"2025-12-19 15:04:43",{"slug":94,"name":95,"version":96,"author":97,"author_profile":98,"description":99,"short_description":100,"active_installs":101,"downloaded":102,"rating":103,"num_ratings":104,"last_updated":105,"tested_up_to":16,"requires_at_least":17,"requires_php":106,"tags":107,"homepage":106,"download_link":113,"security_score":103,"vuln_count":114,"unpatched_count":29,"last_vuln_date":115,"fetched_at":31},"limit-login-attempts-reloaded","Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall","2.26.28","WPChef","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpchefgadget\u002F","\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\" rel=\"nofollow ugc\">Limit Login Attempts Reloaded\u003C\u002Fa> functions as a robust deterrent against \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fcracking-the-code-unveiling-the-mechanics-behind-brute-force-attacks\u002F\" rel=\"nofollow ugc\">brute force attacks\u003C\u002Fa>, bolstering your website’s security measures and optimizing its performance. It achieves this by \u003Cstrong>restricting the number of login attempts allowed\u003C\u002Fstrong>. This applies not only to the standard login method, but also to XMLRPC, Woocommerce, and custom login pages. With more than 2.5 million active users, this plugin fulfills all your login security requirements.\u003C\u002Fp>\n\u003Cp>The plugin functions by automatically preventing further attempts from a particular Internet Protocol (IP) address and\u002For username once a predetermined limit of retries has been surpassed. This significantly weakens the effectiveness of brute force attacks on your website.\u003C\u002Fp>\n\u003Cp>By default, WordPress permits an unlimited number of login attempts, posing a vulnerability where passwords can be easily deciphered through brute force methods.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Limit Login Attempts Reloaded Premium (Try Free with \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fpremium-security-zero-cost-discover-the-benefits-of-micro-cloud\u002F\" rel=\"nofollow ugc\">Micro Cloud\u003C\u002Fa>)\u003C\u002Fstrong>\u003Cbr \u002F>\nUpgrade to \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fplans\u002F\" rel=\"nofollow ugc\">Limit Login Attempts Reloaded Premium\u003C\u002Fa> to extend cloud-based protection to the Limit Login Attempts Reloaded plugin, thereby enhancing your login security. The premium version includes a range of highly beneficial features, including \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Ffeatures\u002Fip-intelligence\u002F\" rel=\"nofollow ugc\">IP intelligence\u003C\u002Fa> to \u003Cstrong>detect, counter and deny malicious login attempts\u003C\u002Fstrong>. Your \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Ffailed-login-attempts-in-wordpress\u002F\" rel=\"nofollow ugc\">failed login attempts\u003C\u002Fa> will be safely neutralized in the cloud so your website can function at its optimal performance during an attack.\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FJfkvIiQft14?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>Features (Free Version):\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>2FA\u003C\u002Fstrong> – Coming soon.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Limit Logins\u003C\u002Fstrong> – Limit the number of retry attempts when logging in (per each IP).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable Lockout Timings\u003C\u002Fstrong> – Modify the amount of time a user or IP must wait after a lockout.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remaining Tries\u003C\u002Fstrong> – Informs the user about the remaining retries or lockout time on the login page.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lockout Email Notifications\u003C\u002Fstrong> – Informs the admin via email of lockouts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Denied Attempt Logs\u003C\u002Fstrong> – View a log of all denied attempts and lockouts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP & Username Safelist\u002FDenylist\u003C\u002Fstrong> – Control access to usernames and IPs.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>New User Registration Protection (Micro Cloud Accounts)\u003C\u002Fstrong> – Protects default WP registration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sucuri\u003C\u002Fstrong> compatibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Wordfence\u003C\u002Fstrong> compatibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Ultimate Member\u003C\u002Fstrong> compatibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WPS Hide Login\u003C\u002Fstrong> compatibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>MemberPress\u003C\u002Fstrong> compatibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XMLRPC\u003C\u002Fstrong> gateway protection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Woocommerce\u003C\u002Fstrong> login page protection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-site compatibility\u003C\u002Fstrong> with extra MU settings.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GDPR\u003C\u002Fstrong> compliant.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom IP origins support\u003C\u002Fstrong> (Cloudflare, Sucuri, etc.).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>llar_admin\u003C\u002Fstrong> own capability.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Features (Premium Version):\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Performance Optimizer\u003C\u002Fstrong> – Offload the burden of excessive failed logins from your server to protect your server resources, resulting in improved speed and efficiency of your website.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enhanced IP Intelligence\u003C\u002Fstrong> – Identify repetitive and suspicious login attempts to detect potential brute force attacks. IPs with known malicious activity are stored and used to help prevent and counter future attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enhanced Throttling\u003C\u002Fstrong> – Longer lockout intervals each time a malicious IP or username tries to login unsuccessfully.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Deny By Country\u003C\u002Fstrong> – \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fblock-logins-by-country-in-wordpress\u002F\" rel=\"nofollow ugc\">Block logins by country\u003C\u002Fa> by simply selecting the countries you want to deny.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto IP Denylist\u003C\u002Fstrong> – Automatically add IP addresses to your active cloud deny list that repeatedly fail login attempts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>New User Registration Protection\u003C\u002Fstrong> – Protects default WP registration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Global Denylist Protection\u003C\u002Fstrong> – Utilize our active cloud IP data from thousands of websites in the LLAR network.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Synchronized Lockouts\u003C\u002Fstrong> –  Lockout IP data can be shared between multiple domains for enhanced protection in your network.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Synchronized Safelist\u002FDenylist\u003C\u002Fstrong> – Safelist\u002FDenylist IP and username data can be shared between multiple domains.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Premium Support\u003C\u002Fstrong> – Email support with a security tech.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto Backups of All IP Data\u003C\u002Fstrong> – Store your active IP data in the cloud.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Successful Logins Log\u003C\u002Fstrong> – Store successful logins in the cloud including IP info, city, state and lat\u002Flong.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enhanced lockout logs\u003C\u002Fstrong> – Gain valuable insights into the origins of IPs that are attempting logins.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CSV Download of IP Data\u003C\u002Fstrong> – Download IP data direclty from the cloud.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Supports IPV6 Ranges For Safelist\u002FDenylist\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Unlock The Locked Admin\u003C\u002Fstrong> – Easily \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fhow-to-unlock-your-site-if-you-are-locked-out-by-limit-login-attempts-reloaded\u002F\" rel=\"nofollow ugc\">unlock the locked admin\u003C\u002Fa> through the cloud.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>*Some features require higher level plans.\u003C\u002Fp>\n\u003Ch4>Upgrading from the old Limit Login Attempts plugin?\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to the Plugins section in your site’s backend.\u003C\u002Fli>\n\u003Cli>Remove the Limit Login Attempts plugin.\u003C\u002Fli>\n\u003Cli>Install the Limit Login Attempts Reloaded plugin.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>All your settings will be kept intact!\u003C\u002Fp>\n\u003Cp>Many languages are currently supported in the Limit Login Attempts Reloaded plugin but we welcome any additional ones.\u003C\u002Fp>\n\u003Cp>Help us bring Limit Login Attempts Reloaded to even more countries.\u003C\u002Fp>\n\u003Cp>Translations: Bulgarian, Brazilian Portuguese, Catalan, Chinese (Traditional), Czech, Dutch, Finnish, French, German, Hungarian, Norwegian, Persian, Romanian, Russian, Spanish, Swedish, Turkish\u003C\u002Fp>\n\u003Cp>Plugin uses standard actions and filters only.\u003C\u002Fp>\n\u003Cp>Based on the original code from Limit Login Attempts plugin by Johan Eenfeldt.\u003C\u002Fp>\n\u003Ch4>Branding Guidelines\u003C\u002Fh4>\n\u003Cp>Limit Login Attempts Reloaded™ is a trademark of Atlantic Silicon Inc. When writing about the plugin, please make sure to use Reloaded after Limit Login Attempts. Limit Login Attempts is the old plugin.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Limit Login Attempts Reloaded (correct)\u003C\u002Fli>\n\u003Cli>Limit Login Attempts (incorrect)\u003C\u002Fli>\n\u003C\u002Ful>\n","Block excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.",2000000,79399145,98,1441,"2026-01-12T16:01:00.000Z","",[108,109,110,111,112],"2fa","brute-force","firewall","login-security","security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flimit-login-attempts-reloaded.2.26.28.zip",4,"2023-12-20 00:00:00",{"slug":117,"name":118,"version":119,"author":120,"author_profile":121,"description":122,"short_description":123,"active_installs":101,"downloaded":124,"rating":67,"num_ratings":125,"last_updated":126,"tested_up_to":16,"requires_at_least":127,"requires_php":18,"tags":128,"homepage":106,"download_link":133,"security_score":134,"vuln_count":135,"unpatched_count":29,"last_vuln_date":136,"fetched_at":31},"wps-hide-login","WPS Hide Login","1.9.18","Remy Perona","https:\u002F\u002Fprofiles.wordpress.org\u002Ftabrisrp\u002F","\u003Ch4>English\u003C\u002Fh4>\n\u003Cp>\u003Cem>WPS Hide Login\u003C\u002Fem> is a very light plugin that lets you easily and safely change the url of the login form page to anything you want. It doesn’t literally rename or change files in core, nor does it add rewrite rules. It simply intercepts page requests and works on any WordPress website. The wp-admin directory and wp-login.php page become inaccessible, so you should bookmark or remember the url. Deactivating this plugin brings your site back exactly to the state it was before.\u003C\u002Fp>\n\u003Cp>This plugin is kindly proposed by \u003Ca href=\"https:\u002F\u002Fwww.wpserveur.net\u002F?refwps=14&campaign=wpshidelogin\" rel=\"nofollow ugc\">WPServeur\u003C\u002Fa> the specialized WordPress web host.\u003C\u002Fp>\n\u003Cp>Discover also our other free extensions:\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwps-limit-login\u002F\" rel=\"ugc\">WPS Limit Login\u003C\u002Fa> to block brute force attacks.\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwps-bidouille\u002F\" rel=\"ugc\">WPS Bidouille\u003C\u002Fa> to optimize your WordPress and get more info.\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwps-cleaner\u002F\" rel=\"ugc\">WPS Cleaner\u003C\u002Fa> to clean your WordPress site.\u003C\u002Fp>\n\u003Cp>This plugin is only maintained, which means we do not guarantee free support. Consider reporting a problem and be patient.\u003C\u002Fp>\n\u003Ch4>Français\u003C\u002Fh4>\n\u003Cp>\u003Cem>WPS Hide Login\u003C\u002Fem> est un plugin très léger qui vous permet de changer facilement et en toute sécurité l’url de la page de formulaire de connexion. Il ne renomme pas littéralement ou ne modifie pas les fichiers dans le noyau, ni n’ajoute des règles de réécriture. Il intercepte simplement les demandes de pages et fonctionne sur n’importe quel site WordPress. Le répertoire wp-admin et la page wp-login.php deviennent inaccessibles, vous devez donc ajouter un signet ou vous souvenir de l’URL. Désactiver ce plugin ramène votre site exactement à l’état dans lequel il était auparavant.\u003C\u002Fp>\n\u003Cp>Ce plugin vous est gentiment proposé par \u003Ca href=\"https:\u002F\u002Fwww.wpserveur.net\u002F?refwps=14&campaign=wpshidelogin\" rel=\"nofollow ugc\">WPServeur\u003C\u002Fa> l’hébergeur spécialisé WordPress.\u003C\u002Fp>\n\u003Cp>Plus d’infos sur son utilisation : \u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Fwps-hide-login-url-connexion-wordpress\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fwpformation.com\u002Fwps-hide-login-url-connexion-wordpress\u002F\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Découvrez également nos autres extensions gratuites :\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Ffr.wordpress.org\u002Fplugins\u002Fwps-limit-login\u002F\" rel=\"nofollow ugc\">WPS Limit Login\u003C\u002Fa> pour bloquer les attaques par force brute.\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Ffr.wordpress.org\u002Fplugins\u002Fwps-bidouille\u002F\" rel=\"nofollow ugc\">WPS Bidouille\u003C\u002Fa> pour optimiser votre WordPress et faire le plein d’infos.\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Ffr.wordpress.org\u002Fplugins\u002Fwps-cleaner\u002F\" rel=\"nofollow ugc\">WPS Cleaner\u003C\u002Fa> pour nettoyer votre site WordPress.\u003C\u002Fp>\n\u003Cp>Ce plugin est seulement maintenu, ce qui signifie que nous ne garantissons pas un support gratuit. Envisagez de signaler un problème et soyez patient.\u003C\u002Fp>\n\u003Ch4>Compatibility\u003C\u002Fh4>\n\u003Ch4>English\u003C\u002Fh4>\n\u003Cp>Requires WordPress 4.1 or higher. All login related things such as the registration form, lost password form, login widget and expired sessions just keep working.\u003C\u002Fp>\n\u003Cp>It’s also compatible with any plugin that hooks in the login form, including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>BuddyPress,\u003C\u002Fli>\n\u003Cli>bbPress,\u003C\u002Fli>\n\u003Cli>Jetpack,\u003C\u002Fli>\n\u003Cli>WPS Limit Login,\u003C\u002Fli>\n\u003Cli>and User Switching.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Obviously it doesn’t work with plugins or themes that \u003Cem>hardcoded\u003C\u002Fem> wp-login.php.\u003C\u002Fp>\n\u003Cp>Works with multisite, with subdomains and subfolders. Activating it for a network allows you to set a networkwide default. Individual sites can still rename their login page to something else.\u003C\u002Fp>\n\u003Cp>If you’re using a \u003Cstrong>page caching plugin\u003C\u002Fstrong> other than WP Rocket, you should add the slug of the new login url to the list of pages not to cache. WP Rocket is already fully compatible with the plugin.\u003C\u002Fp>\n\u003Ch4>Français\u003C\u002Fh4>\n\u003Cp>Nécessite WordPress 4.1 ou supérieur. Toutes les choses liées à la connexion telles que le formulaire d’inscription, le formulaire de mot de passe perdu, le widget de connexion et les sessions expirées continuent de fonctionner.\u003C\u002Fp>\n\u003Cp>Il est également compatible avec tout plugin qui se connecte au formulaire de connexion, notamment:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>BuddyPress,\u003C\u002Fli>\n\u003Cli>bbPress,\u003C\u002Fli>\n\u003Cli>Jetpack,\u003C\u002Fli>\n\u003Cli>WPS Limit Login,\u003C\u002Fli>\n\u003Cli>and User Switching.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Évidemment, cela ne fonctionne pas avec les plugins ou les thèmes \u003Cem>hardcoded\u003C\u002Fem> wp-login.php.\u003C\u002Fp>\n\u003Cp>Fonctionne en multisite, avec sous-domaines ou sous dossiers. L’activer pour un réseau vous permet de définir une valeur par défaut pour l’ensemble du réseau. Les sites individuels peuvent toujours renommer leur page de connexion pour autre chose.\u003C\u002Fp>\n\u003Cp>Si vous utilisez un \u003Cstrong>plugin de mise en cache de pages\u003C\u002Fstrong> autre que WP Rocket, vous devez ajouter le slug de la nouvelle URL de connexion à la liste des pages à ne pas mettre en cache. WP Rocket est déjà entièrement compatible avec le plugin.\u003C\u002Fp>\n","Change wp-login.php to anything you want.",30498017,2101,"2026-01-12T08:47:00.000Z","4.1",[129,23,130,131,132],"custom-login-url","rename","wp-login","wp-login-php","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwps-hide-login.1.9.18.zip",95,10,"2024-06-24 00:00:00",{"slug":138,"name":139,"version":140,"author":141,"author_profile":142,"description":143,"short_description":144,"active_installs":145,"downloaded":146,"rating":13,"num_ratings":147,"last_updated":148,"tested_up_to":16,"requires_at_least":84,"requires_php":149,"tags":150,"homepage":153,"download_link":154,"security_score":27,"vuln_count":155,"unpatched_count":29,"last_vuln_date":156,"fetched_at":31},"all-in-one-wp-security-and-firewall","All-In-One Security (AIOS) – Security and Firewall","5.4.6","David Anderson \u002F Team Updraft","https:\u002F\u002Fprofiles.wordpress.org\u002Fdavidanderson\u002F","\u003Ch3>THE TOP RATED WORDPRESS SECURITY AND FIREWALL PLUGIN\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios&utm_creative_format=description\" rel=\"nofollow ugc\">All-in-One Security (AIOS)\u003C\u002Fa> is a WordPress security plugin from the same, trusted team that brought you UpdraftPlus.\u003C\u002Fp>\n\u003Cp>It’s called ‘All-In-One’ because it’s packed full of ways to keep your WordPress website(s) safe and secure.\u003C\u002Fp>\n\u003Cp>It includes:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login security features\u003C\u002Fstrong> keep bots at bay. Lock out users based on a configurable number of login attempts, get two-factor authentication and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File and database security.\u003C\u002Fstrong> Get notified of file changes that occur outside of normal operations. Block access to key files and scan files and folders to spot insecure permissions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Firewall.\u003C\u002Fstrong> Get PHP, .htaccess and 6G firewall rules courtesy of Perishable Press. Spot and block fake Google Bots and more!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Spam prevention.\u003C\u002Fstrong> Prevent annoying spam comments and reduce unnecessary load on the server. Automatically and permanently block IP addresses that exceed a set number of spam comments.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit log.\u003C\u002Fstrong> View events happening on your WordPress website. Find out if a plugin or theme has been added, removed, updated and more.\u003C\u002Fp>\n\u003Ch4>WHY ALL-IN-ONE SECURITY?\u003C\u002Fh4>\n\u003Cp>AIOS has a near-perfect \u003Cstrong>4.7 \u002F 5-star user rating\u003C\u002Fstrong> across more than 1 million installs.\u003C\u002Fp>\n\u003Cp>Great for beginners and experts alike. AIOS guides you logically and clearly through each of its features which are all clearly explained. Security features are marked as basic, intermediate and advanced. Each step increases your security score. Turn them on and watch your protection grow!\u003C\u002Fp>\n\u003Cp>We have a large support team of software developers. That means we have the availability and the skillset to help you with the trickiest of queries.\u003C\u002Fp>\n\u003Cp>We comb the WordPress plugin directory for support tickets daily – most queries are responded to within 24 hours.\u003C\u002Fp>\n\u003Cp>\u003Cem>Excellent plugin with numerous well-thought-out options for making a website more secure. I have been using it for years and am very happy with it. I recently had a small problem setting up a website and – even as a non-premium user – I received support very quickly. Highly recommended!\u003C\u002Fem>\u003C\u002Fp>\n\u003Cp>For even more ways to stay safe and secure, upgrade to \u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002Fpricing?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios_premium&utm_creative_format=description\" rel=\"nofollow ugc\">AIOS Premium\u003C\u002Fa> – it packs a punch security-wise, whilst being \u003Cstrong>extremely cost-competitive\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch4>LOGIN SECURITY\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication (TFA)\u003C\u002Fstrong> – Require TFA for specific user roles. Supports Google Authenticator, Microsoft Authenticator, Authy, and many more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Detect and manage ‘admin’ usernames\u003C\u002Fstrong> – Identify default ‘admin’ usernames and guide users to change them to protect against brute force attacks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Identify and correct identical login and display names\u003C\u002Fstrong> – Detect cases where the display name matches the username and provide guidance to improve login security.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent user enumeration\u003C\u002Fstrong> – Block unauthorised access to URLs that can reveal sensitive information such as usernames or other details.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control login attempts\u003C\u002Fstrong> – Prevent brute force attacks by limiting the number of failed login attempts. Choose how many login attempts are allowed, set lockout durations, and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Force user logout\u003C\u002Fstrong> – Automatically log out users after a specified period of time. Unattended sessions are closed, reducing the risk of unauthorised access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Manually approve new registrations\u003C\u002Fstrong> – Review and approve new user registrations to prevent spam and fake sign-ups.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Enhance WordPress salt security\u003C\u002Fstrong> – Adds 64 extra characters to WordPress salts, rotating them weekly. Makes cracking passwords virtually impossible, even if your database is stolen.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002F\u003Cbr \u002F>\n\u003Cstrong>Monitor and manage active sessions\u003C\u002Fstrong> – If a user is logged in who shouldn’t be, log them out or add them to a blacklist.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>SPAM PREVENTION\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block spam coming from bots\u003C\u002Fstrong> – Reduce the load on your server and improve the user experience by automatically blocking spam comments from bots.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Monitor spam IP addresses\u003C\u002Fstrong> – Monitor the IP addresses of people or bots leaving spam comments. Choose which ones to block based on a configurable number of comments left.\u003C\u002Fp>\n\u003Ch4>FILE \u002F DATABASE Security\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Scan and fix file permissions\u003C\u002Fstrong> – Scan for insecure file permissions. Click once to fix issues and safeguard critical files and folders.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Disable PHP file editing\u003C\u002Fstrong> – Disable editing of PHP files (such as plugins and themes) via the dashboard. It’s often the first tool that attackers use as it allows for code execution.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Protect sensitive files\u003C\u002Fstrong> – Prevent access to files like readme.html that might reveal information about your WordPress installation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File change scanner\u003C\u002Fstrong> – Get notified of any file changes which occur on your system. Exclude files and folders which change as part of normal operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent image hotlinking\u003C\u002Fstrong> – Prevent other websites from displaying your images via hotlinking and protect server bandwidth.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Secure database backups\u003C\u002Fstrong> – Perform a database backup via UpdraftPlus from AIOS. Change the default ‘wp_’ prefix to hide your WordPress database from hackers.\u003C\u002Fp>\n\u003Ch4>FIREWALL\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Get .htaccess firewall rules\u003C\u002Fstrong> – Deny access to the .htaccess and wp-config.php files. Disable the server signature and limit file uploads to a configurable size.**\u003C\u002Fp>\n\u003Cp>Block access to the debug.log file and prevent Apache servers from listing the contents of a directory when an index.php file is not present\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Get PHP firewall rules\u003C\u002Fstrong> – PHP firewall rules prevent malicious users from exploiting well-known vulnerabilities in XML-RPC. Safeguard your content by disabling RSS and Atom feeds and avoid cross-site scripting (XSS) attacks.\u003Cbr \u002F>\nBlock fake Google bots and POST requests made by bots – Block fake Google bots and stop bots from making POST requests by blocking IP addresses where the user-agent and referrer fields are blank.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Utilise 6G firewall rules\u003C\u002Fstrong> – Employ flexible blacklist rules to reduce the number of malicious URL requests that hit your website (courtesy of Perishable Press).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>And more\u003C\u002Fstrong> – Blacklist (and whitelist) IP ranges and user agents and block unauthorized access to data by disabling REST API access for non-logged-in requests.\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION ENHANCED [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication\u003C\u002Fstrong> is included in the free plugin. Upgrade to Premium if you’d like to:\u003Cbr \u002F>\nRequire TFA after a set time period – Mandate TFA for all admins or other roles after their accounts reach a specified age.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control how often TFA is required\u003C\u002Fstrong> – Set TFA to be required after a certain number of days on trusted devices instead of every login.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Customise design layout\u003C\u002Fstrong> – Adjust the TFA design to match your website’s existing layout and branding.\u003Cbr \u002F>\nEmergency codes – Generate one-time use emergency codes to regain access if you lose your TFA device.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Multisite Compatible\u003C\u002Fstrong> – Ensure compatibility with WordPress multisite networks and their sub-sites for consistent TFA application.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Integration with login forms\u003C\u002Fstrong> – Integrate TFA with various login forms, including WooCommerce, Affiliates-WP, Elementor Pro, bbPress, and ‘Theme My Login’ without additional coding.\u003C\u002Fp>\n\u003Ch4>SMART 404 BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block IPs based on 404 errors\u003C\u002Fstrong> – Detect hackers probing your URLs via script and bots by the 404 errors they leave behind.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 Configuration\u003C\u002Fstrong> – Set a figure for the maximum number of 404 events allowed before an IP address is blocked. Choose a time period within which the 404 events must occur (e.g., 10 errors within 10 minutes).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 block by URL string\u003C\u002Fstrong> – Instantly block an IP address if a 404 event includes a specific URL string.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 whitelisting\u003C\u002Fstrong> – Prevent particular IP addresses from being permanently blocked due to 404 events.\u003C\u002Fp>\n\u003Ch4>COUNTRY BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block traffic to the entire site or to specific pages or posts\u003C\u002Fstrong> – Useful if you’re an e-commerce site and you want to block sales to some countries for shipping or tax reasons.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Whitelist some users from blocked countries\u003C\u002Fstrong> – Whitelist IP addresses or IP ranges even if they are part of a blocked country.\u003C\u002Fp>\n\u003Ch4>MALWARE SCANNING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Automatic malware scanning\u003C\u002Fstrong> – Detect and protect against the latest malware, trojans, and spyware.\u003Cbr \u002F>\nAlerts you to blacklisting by search engines – Monitor your site for blacklisting by search engines due to malicious code.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Response time monitoring\u003C\u002Fstrong> – Keep track of your website’s response time to identify and address any performance issues.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Uptime monitoring\u003C\u002Fstrong> – Checks your website’s uptime every 5 minutes and alerts you immediately if your site or server goes down.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advice and malware removal\u003C\u002Fstrong> – Need hands-on advice and support for malware removal? Our team of genuine cybersecurity experts is here to help.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Notification if something’s amiss\u003C\u002Fstrong> – Receive notifications about any issues with your site so you can address problems before they escalate.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cp>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u003C\u002Fp>\n\u003Ch4>Developers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you are a developer and you need some extra hooks or filters for this plugin then let us know.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Translations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>All-In-One Security plugin can be translated to any language.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Currently available translations:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>Hungarian\u003C\u002Fli>\n\u003Cli>Italian\u003C\u002Fli>\n\u003Cli>Swedish\u003C\u002Fli>\n\u003Cli>Russian\u003C\u002Fli>\n\u003Cli>Chinese\u003C\u002Fli>\n\u003Cli>Portuguese (Brazil)\u003C\u002Fli>\n\u003Cli>Persian\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy Policy\u003C\u002Fh4>\n\u003Cp>This plugin may collect IP addresses for security reasons such as mitigating brute force login threats and malicious activity.\u003C\u002Fp>\n\u003Cp>The collected information is stored on your server. No information is transmitted to third parties or remote server locations.\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n","Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.",1000000,36139406,1693,"2026-01-28T22:15:00.000Z","5.6",[110,111,151,112,152],"malware-scanning","two-factor-authentication","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fall-in-one-wp-security-and-firewall\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fall-in-one-wp-security-and-firewall.5.4.6.zip",26,"2024-02-08 00:00:00",{"slug":158,"name":159,"version":160,"author":161,"author_profile":162,"description":163,"short_description":164,"active_installs":145,"downloaded":165,"rating":67,"num_ratings":166,"last_updated":167,"tested_up_to":16,"requires_at_least":17,"requires_php":168,"tags":169,"homepage":172,"download_link":173,"security_score":174,"vuln_count":175,"unpatched_count":29,"last_vuln_date":176,"fetched_at":31},"loginizer","Loginizer","2.0.6","Softaculous","https:\u002F\u002Fprofiles.wordpress.org\u002Fsoftaculous\u002F","\u003Cp>Loginizer is a WordPress plugin which helps you fight against bruteforce attack by blocking login for the IP after it reaches maximum retries allowed. You can blacklist or whitelist IPs for login using Loginizer. You can use various other features like Two Factor Auth, reCAPTCHA, PasswordLess Login, etc. to improve security of your website.\u003C\u002Fp>\n\u003Cp>Loginizer is actively used by more than 1000000+ WordPress websites.\u003C\u002Fp>\n\u003Cp>You can find our official documentation at \u003Ca href=\"https:\u002F\u002Floginizer.com\u002Fdocs\" rel=\"nofollow ugc\">https:\u002F\u002Floginizer.com\u002Fdocs\u003C\u002Fa>. We are also active in our community support forums on \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Floginizer\" rel=\"ugc\">wordpress.org\u003C\u002Fa> if you are one of our free users. Our Premium Support Ticket System is at \u003Ca href=\"https:\u002F\u002Floginizer.deskuss.com\" rel=\"nofollow ugc\">https:\u002F\u002Floginizer.deskuss.com\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Free Features :\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Brute force protection. IPs trying to brute force your website will be blocked for 15 minutes after 3 failed login attempts. After multiple lockouts the IP is blocked for 24 hours. This is the default configuration and can be changed from Loginizer -> Brute force page in WordPress admin panel.\u003C\u002Fli>\n\u003Cli>Failed login attempts logs.\u003C\u002Fli>\n\u003Cli>Blacklist IPs\u003C\u002Fli>\n\u003Cli>Whitelist IPs\u003C\u002Fli>\n\u003Cli>Custom error messages on failed login.\u003C\u002Fli>\n\u003Cli>Permission check for important files and folders.\u003C\u002Fli>\n\u003Cli>Allow only Trusted IP.\u003C\u002Fli>\n\u003Cli>Blocked Screen in place of the Login page.\u003C\u002Fli>\n\u003Cli>Email Notification on successful login.\u003C\u002Fli>\n\u003Cli>Let users login with LinkedIn\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Get Support and Pro Features\u003C\u002Fh4>\n\u003Cp>Get professional support from our experts and pro features to take your site’s security to the next level with \u003Ca href=\"https:\u002F\u002Floginizer.com\u002Fpricing\" rel=\"nofollow ugc\">Loginizer-Security\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Pro Features :\u003C\u002Fp>\n\u003Cul>\n\u003Cli>MD5 Checksum – of Core WordPress Files. The admin can check and ignore files as well.\u003C\u002Fli>\n\u003Cli>PasswordLess Login – At the time of Login, the username \u002F email address will be asked and an email will be sent to the email address of that account with a temporary link to login.\u003C\u002Fli>\n\u003Cli>Two Factor Auth via Email – On login, an email will be sent to the email address of that account with a temporary 6 digit code to complete the login.\u003C\u002Fli>\n\u003Cli>Two Factor Auth via App – The user can configure the account with a 2FA App like Google Authenticator, Authy, etc.\u003C\u002Fli>\n\u003Cli>Login Challenge Question – The user can setup a Challenge Question and Answer as an additional security layer. After Login, the user will need to answer the question to complete the login.\u003C\u002Fli>\n\u003Cli>reCAPTCHA – Google’s reCAPTCHA v3\u002Fv2, Cloudflare Turnstile, hCAPTCHA can be configured for the Login screen, Comments Section, Registration Form, etc. to prevent automated brute force attacks. Supports WooCommerce as well.\u003C\u002Fli>\n\u003Cli>Rename Login Page – The Admin can rename the login URL (slug) to something different from wp-login.php to prevent automated brute force attacks.\u003C\u002Fli>\n\u003Cli>Rename WP-Admin URL – The Admin area in WordPress is accessed via wp-admin. With loginizer you can change it to anything e.g. site-admin\u003C\u002Fli>\n\u003Cli>CSRF Protection – This helps in preventing CSRF attacks as it updates the admin URL with a session string which makes it difficult and nearly impossible for the attacker to predict the URL.\u003C\u002Fli>\n\u003Cli>Rename Login with Secrecy – If set, then all Login URL’s will still point to wp-login.php and users will have to access the New Login Slug by typing it in the browser.\u003C\u002Fli>\n\u003Cli>Disable XML-RPC – An option to simply disable XML-RPC in WordPress. Most of the WordPress users don’t need XML-RPC and can disable it to prevent automated brute force attacks.\u003C\u002Fli>\n\u003Cli>Rename XML-RPC – The Admin can rename the XML-RPC to something different from xmlrpc.php to prevent automated brute force attacks.\u003C\u002Fli>\n\u003Cli>Username Auto Blacklist – Attackers generally use common usernames like admin, administrator, or variations of your domain name \u002F business name. You can specify such username here and Loginizer will auto-blacklist the IP Address(s) of clients who try to use such username(s).\u003C\u002Fli>\n\u003Cli>New Registration Domain Blacklist – If you would like to ban new registrations from a particular domain, you can use this utility to do so.\u003C\u002Fli>\n\u003Cli>Change the Admin Username – The Admin can rename the admin username to something more difficult.\u003C\u002Fli>\n\u003Cli>Auto Blacklist IPs – IPs will be auto blacklisted, if certain usernames saved by the Admin are used to login by malicious bots \u002F users.\u003C\u002Fli>\n\u003Cli>Disable Pingbacks – Simple way to disable PingBacks.\u003C\u002Fli>\n\u003Cli>SSO – Single Sign-on, let any user access to your WordPress Dashboard without the need to share username or password.\u003C\u002Fli>\n\u003Cli>Limit Concurrent Logins – It prevents user to login from different devices concurrently, you can define how many devices you want to allow, and how you want to restrict the user when concurrent limit is reached.\u003C\u002Fli>\n\u003Cli>Social Login – Users can login or register with their Google, Github, Facebook, X (Twitter), Discord, Twitch, LinkedIn, Microsoft with support for WooCommerce and Ultimate Member.\u003C\u002Fli>\n\u003Cli>Key Less Social Login – Use Loginizer’s Social Auth for easy key less Social login configuration, now supports Google, GitHub, X, LinkedIn more to be added later\u003C\u002Fli>\n\u003Cli>Country Blocking – Block IPs from specific countries to restrict access to your website.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Features in Loginizer include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Blocks IP after maximum retries allowed\u003C\u002Fli>\n\u003Cli>Extended Lockout after maximum lockouts allowed\u003C\u002Fli>\n\u003Cli>Email notification to admin after max lockouts\u003C\u002Fli>\n\u003Cli>Blacklist IP\u002FIP range\u003C\u002Fli>\n\u003Cli>Whitelist IP\u002FIP range\u003C\u002Fli>\n\u003Cli>Check logs of failed attempts\u003C\u002Fli>\n\u003Cli>Create IP ranges\u003C\u002Fli>\n\u003Cli>Delete IP ranges\u003C\u002Fli>\n\u003Cli>Licensed under LGPLv2.1\u003C\u002Fli>\n\u003Cli>Safe & Secure\u003C\u002Fli>\n\u003C\u002Ful>\n","Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.",29791210,1020,"2026-03-02T12:38:00.000Z","5.5",[170,171,23,158,112],"access","admin","https:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Floginizer\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Floginizer.2.0.6.zip",87,8,"2024-11-04 00:00:00",{"attackSurface":178,"codeSignals":352,"taintFlows":446,"riskAssessment":542,"analyzedAt":557},{"hooks":179,"ajaxHandlers":325,"restRoutes":348,"shortcodes":349,"cronEvents":350,"entryPointCount":351,"unprotectedCount":28},[180,186,191,196,200,204,208,212,216,220,224,228,231,235,240,244,247,251,254,258,261,264,267,269,273,277,279,282,286,289,292,295,298,301,305,309,312,315,319,323],{"type":181,"name":182,"callback":183,"file":184,"line":185},"action","admin_init","closure","inc\\functions-inner.php",91,{"type":187,"name":188,"callback":189,"file":184,"line":190},"filter","woo_salesforce_crmperks_post_data","eufdc_salesforce_crmperks_post_data",196,{"type":181,"name":192,"callback":193,"priority":135,"file":194,"line":195},"woocommerce_register_post","wufdc_validate_extra_register_fields","inc\\functions.php",383,{"type":181,"name":197,"callback":198,"file":194,"line":199},"woocommerce_created_customer","wufdc_save_extra_register_fields",415,{"type":187,"name":201,"callback":202,"file":194,"line":203},"intermediate_image_sizes","__return_empty_array",892,{"type":181,"name":205,"callback":206,"priority":135,"file":194,"line":207},"woocommerce_email_before_order_table","add_order_attachments",1031,{"type":181,"name":209,"callback":210,"file":194,"line":211},"wp_head","eufdc_header_scripts",1201,{"type":187,"name":213,"callback":214,"file":194,"line":215},"woocommerce_checkout_fields","eufdc_override_checkout_fields",1203,{"type":181,"name":217,"callback":218,"priority":135,"file":194,"line":219},"woocommerce_order_details_after_order_table","eufdc_custom_notes_on_single_order_page",1251,{"type":181,"name":221,"callback":222,"file":194,"line":223},"wp","eufdc_translate_file_link",1373,{"type":181,"name":225,"callback":226,"file":194,"line":227},"show_user_profile","eufdc_show_user_register_files",1447,{"type":181,"name":229,"callback":226,"file":194,"line":230},"edit_user_profile",1448,{"type":187,"name":232,"callback":233,"file":194,"line":234},"wp_handle_upload_prefilter","eufdc_check_file_type_before_upload",1697,{"type":181,"name":236,"callback":237,"file":238,"line":239},"admin_menu","easy_ufdc_admin_menu","index.php",149,{"type":181,"name":241,"callback":242,"file":238,"line":243},"init","ufdc_custom_file_upload",151,{"type":181,"name":221,"callback":245,"file":238,"line":246},"ufdc_custom_init",152,{"type":181,"name":248,"callback":249,"file":238,"line":250},"woocommerce_checkout_after_customer_details","add_file_to_upcoming_order",158,{"type":181,"name":252,"callback":249,"file":238,"line":253},"woocommerce_after_cart_table",162,{"type":181,"name":255,"callback":256,"file":238,"line":257},"wp_footer","ufdc_easy_ufdc_req",163,{"type":181,"name":259,"callback":249,"file":238,"line":260},"woocommerce_after_order_notes",166,{"type":181,"name":262,"callback":249,"file":238,"line":263},"woocommerce_register_form_start",169,{"type":181,"name":265,"callback":183,"file":238,"line":266},"woocommerce_view_order",177,{"type":181,"name":255,"callback":268,"file":238,"line":190},"eufdc_open_form",{"type":181,"name":270,"callback":268,"priority":271,"file":238,"line":272},"woocommerce_before_checkout_form",20,207,{"type":187,"name":274,"callback":275,"file":238,"line":276},"the_content","eufdc_filter_the_content",220,{"type":181,"name":255,"callback":268,"file":238,"line":278},226,{"type":181,"name":221,"callback":280,"file":238,"line":281},"file_during_checkout",230,{"type":181,"name":283,"callback":284,"file":238,"line":285},"woocommerce_order_status_pending","wc_checkout_order_processed",231,{"type":181,"name":287,"callback":284,"file":238,"line":288},"woocommerce_order_status_failed",232,{"type":181,"name":290,"callback":284,"file":238,"line":291},"woocommerce_order_status_on-hold",233,{"type":181,"name":293,"callback":284,"file":238,"line":294},"woocommerce_order_status_processing",234,{"type":181,"name":296,"callback":284,"file":238,"line":297},"woocommerce_order_status_completed",235,{"type":181,"name":299,"callback":284,"file":238,"line":300},"woocommerce_order_status_cancelled",236,{"type":181,"name":302,"callback":303,"file":238,"line":304},"save_post","pre_wc_checkout_order_processed",240,{"type":181,"name":306,"callback":307,"file":238,"line":308},"wp_enqueue_scripts","wufdc_enqueue_style",247,{"type":181,"name":306,"callback":310,"file":238,"line":311},"wufdc_enqueue_script",248,{"type":181,"name":306,"callback":313,"file":238,"line":314},"eufdc_enqueue_common_scripts",249,{"type":181,"name":316,"callback":317,"priority":135,"file":238,"line":318},"add_meta_boxes","easy_ufdc_add_box_for_files",251,{"type":181,"name":320,"callback":321,"file":238,"line":322},"admin_enqueue_scripts","wufdc_admin_enqueue_script",253,{"type":181,"name":320,"callback":313,"file":238,"line":324},255,[326,331,335,337,340,342,345],{"action":327,"nopriv":328,"callback":327,"hasNonce":329,"hasCapCheck":329,"file":184,"line":330},"eufdc_connect_to_amazon",false,true,65,{"action":332,"nopriv":329,"callback":333,"hasNonce":329,"hasCapCheck":329,"file":194,"line":334},"eufdc_update_file_caption","eufdc_update_file_caption_ajax",1566,{"action":332,"nopriv":328,"callback":333,"hasNonce":329,"hasCapCheck":329,"file":194,"line":336},1567,{"action":338,"nopriv":329,"callback":338,"hasNonce":328,"hasCapCheck":328,"file":194,"line":339},"eufdc_get_file_upload_error",1751,{"action":338,"nopriv":328,"callback":338,"hasNonce":328,"hasCapCheck":328,"file":194,"line":341},1752,{"action":343,"nopriv":328,"callback":343,"hasNonce":329,"hasCapCheck":329,"file":194,"line":344},"eufdc_delete_orphan_files",1771,{"action":346,"nopriv":328,"callback":346,"hasNonce":329,"hasCapCheck":329,"file":194,"line":347},"eufdc_get_orphan_files_statistics",1827,[],[],[],7,{"dangerousFunctions":353,"sqlUsage":354,"outputEscaping":364,"fileOperations":135,"externalRequests":91,"nonceChecks":443,"capabilityChecks":444,"bundledLibraries":445},[],{"prepared":355,"raw":355,"locations":356},3,[357,360,362],{"file":194,"line":358,"context":359},257,"$wpdb->get_results() with variable interpolation",{"file":194,"line":361,"context":359},844,{"file":194,"line":363,"context":359},1798,{"escaped":365,"rawEcho":47,"locations":366},124,[367,371,373,375,377,379,381,383,384,386,388,390,392,394,396,398,400,402,404,406,408,410,412,414,416,418,420,422,424,426,428,429,431,433,435,437,439,441],{"file":368,"line":369,"context":370},"admin\\ufdc-settings.php",192,"raw output",{"file":368,"line":372,"context":370},246,{"file":368,"line":374,"context":370},252,{"file":368,"line":376,"context":370},258,{"file":368,"line":378,"context":370},394,{"file":368,"line":380,"context":370},400,{"file":368,"line":382,"context":370},426,{"file":368,"line":382,"context":370},{"file":368,"line":385,"context":370},432,{"file":368,"line":387,"context":370},434,{"file":368,"line":389,"context":370},436,{"file":368,"line":391,"context":370},654,{"file":368,"line":393,"context":370},657,{"file":368,"line":395,"context":370},660,{"file":368,"line":397,"context":370},663,{"file":368,"line":399,"context":370},668,{"file":368,"line":401,"context":370},756,{"file":368,"line":403,"context":370},835,{"file":368,"line":405,"context":370},871,{"file":368,"line":407,"context":370},942,{"file":368,"line":409,"context":370},948,{"file":368,"line":411,"context":370},952,{"file":368,"line":413,"context":370},963,{"file":368,"line":415,"context":370},1002,{"file":368,"line":417,"context":370},1008,{"file":368,"line":419,"context":370},1012,{"file":368,"line":421,"context":370},1018,{"file":368,"line":423,"context":370},1058,{"file":368,"line":425,"context":370},1155,{"file":368,"line":427,"context":370},1166,{"file":368,"line":219,"context":370},{"file":368,"line":430,"context":370},1299,{"file":368,"line":432,"context":370},1317,{"file":184,"line":434,"context":370},59,{"file":184,"line":436,"context":370},110,{"file":194,"line":438,"context":370},1433,{"file":194,"line":440,"context":370},1793,{"file":194,"line":442,"context":370},1879,5,6,[],[447,464,477,485,495,503,528],{"entryPoint":448,"graph":449,"unsanitizedCount":91,"severity":40},"file_during_checkout (inc\\functions.php:685)",{"nodes":450,"edges":462},[451,456],{"id":452,"type":453,"label":454,"file":194,"line":455},"n0","source","$_FILES",747,{"id":457,"type":458,"label":459,"file":194,"line":460,"wp_function":461},"n1","sink","file_get_contents() [SSRF\u002FLFI]",771,"file_get_contents",[463],{"from":452,"to":457,"sanitized":328},{"entryPoint":465,"graph":466,"unsanitizedCount":29,"severity":476},"easy_ufdc_page (admin\\ufdc-settings.php:11)",{"nodes":467,"edges":474},[468,471],{"id":452,"type":453,"label":469,"file":368,"line":470},"$_POST['eufdc_tn']",361,{"id":457,"type":458,"label":472,"file":368,"line":470,"wp_function":473},"echo() [XSS]","echo",[475],{"from":452,"to":457,"sanitized":329},"low",{"entryPoint":478,"graph":479,"unsanitizedCount":29,"severity":476},"\u003Cufdc-settings> (admin\\ufdc-settings.php:0)",{"nodes":480,"edges":483},[481,482],{"id":452,"type":453,"label":469,"file":368,"line":470},{"id":457,"type":458,"label":472,"file":368,"line":470,"wp_function":473},[484],{"from":452,"to":457,"sanitized":329},{"entryPoint":486,"graph":487,"unsanitizedCount":29,"severity":476},"eufdc_connect_to_amazon (inc\\functions-inner.php:4)",{"nodes":488,"edges":493},[489,492],{"id":452,"type":453,"label":490,"file":184,"line":491},"$_POST",16,{"id":457,"type":458,"label":472,"file":184,"line":434,"wp_function":473},[494],{"from":452,"to":457,"sanitized":329},{"entryPoint":496,"graph":497,"unsanitizedCount":29,"severity":476},"\u003Cfunctions-inner> (inc\\functions-inner.php:0)",{"nodes":498,"edges":501},[499,500],{"id":452,"type":453,"label":490,"file":184,"line":491},{"id":457,"type":458,"label":472,"file":184,"line":434,"wp_function":473},[502],{"from":452,"to":457,"sanitized":329},{"entryPoint":504,"graph":505,"unsanitizedCount":29,"severity":476},"\u003Cfunctions> (inc\\functions.php:0)",{"nodes":506,"edges":524},[507,508,509,513,516,519],{"id":452,"type":453,"label":454,"file":194,"line":455},{"id":457,"type":458,"label":459,"file":194,"line":460,"wp_function":461},{"id":510,"type":453,"label":511,"file":194,"line":512},"n2","$_GET (x4)",567,{"id":514,"type":458,"label":472,"file":194,"line":515,"wp_function":473},"n3",910,{"id":517,"type":453,"label":518,"file":194,"line":512},"n4","$_GET (x2)",{"id":520,"type":458,"label":521,"file":194,"line":522,"wp_function":523},"n5","wp_redirect() [Open Redirect]",1279,"wp_redirect",[525,526,527],{"from":452,"to":457,"sanitized":329},{"from":510,"to":514,"sanitized":329},{"from":517,"to":520,"sanitized":329},{"entryPoint":529,"graph":530,"unsanitizedCount":91,"severity":541},"\u003Cindex> (index.php:0)",{"nodes":531,"edges":539},[532,535],{"id":452,"type":453,"label":533,"file":238,"line":534},"$_SERVER",37,{"id":457,"type":458,"label":536,"file":238,"line":537,"wp_function":538},"get_row() [SQLi]",63,"get_row",[540],{"from":452,"to":457,"sanitized":328},"high",{"summary":543,"deductions":544},"The 'easy-upload-files-during-checkout' plugin v3.0.1 presents a mixed security posture. While it demonstrates some good practices like a significant percentage of properly escaped outputs and a majority of SQL queries using prepared statements, there are notable concerns. The presence of two AJAX handlers without authentication checks creates an immediate attack surface that could be exploited by unauthenticated users. Furthermore, the taint analysis revealed one high-severity flow with unsanitized paths, indicating a potential for privilege escalation or unauthorized file access. The plugin's vulnerability history, including a past critical vulnerability and a general pattern of missing authorization and unrestricted file uploads, is a significant red flag. Although there are no currently unpatched CVEs, the recurring nature of these vulnerability types suggests persistent coding weaknesses that could be re-introduced or exploited in future versions. The plugin's strengths lie in its relative lack of dangerous functions and no obvious REST API vulnerabilities. However, the combination of unprotected entry points, high-severity taint flows, and historical vulnerability patterns warrants caution.",[545,547,550,553,555],{"reason":546,"points":175},"Unprotected AJAX handlers",{"reason":548,"points":549},"High severity taint flow",12,{"reason":551,"points":552},"Past critical CVE",15,{"reason":554,"points":175},"Historical missing authorization",{"reason":556,"points":175},"Historical unrestricted file upload","2026-03-16T19:32:27.045Z",{"wat":559,"direct":574},{"assetPaths":560,"generatorPatterns":566,"scriptPaths":567,"versionParams":568},[561,562,563,564,565],"\u002Fwp-content\u002Fplugins\u002Feasy-upload-files-during-checkout\u002Fcss\u002Fjquery-ui.css","\u002Fwp-content\u002Fplugins\u002Feasy-upload-files-during-checkout\u002Fcss\u002Fstyle.css","\u002Fwp-content\u002Fplugins\u002Feasy-upload-files-during-checkout\u002Fjs\u002Fmain.js","\u002Fwp-content\u002Fplugins\u002Feasy-upload-files-during-checkout\u002Fjs\u002Fupload.js","\u002Fwp-content\u002Fplugins\u002Feasy-upload-files-during-checkout\u002Fjs\u002Fjquery-ui.js",[],[563,564,565],[569,570,571,572,573],"easy-upload-files-during-checkout\u002Fcss\u002Fjquery-ui.css?ver=","easy-upload-files-during-checkout\u002Fcss\u002Fstyle.css?ver=","easy-upload-files-during-checkout\u002Fjs\u002Fmain.js?ver=","easy-upload-files-during-checkout\u002Fjs\u002Fupload.js?ver=","easy-upload-files-during-checkout\u002Fjs\u002Fjquery-ui.js?ver=",{"cssClasses":575,"htmlComments":578,"htmlAttributes":583,"restEndpoints":588,"jsGlobals":589,"shortcodeOutput":591},[576,577],"eufdc-upload-main-div","eufdc-upload-content",[5,10,579,580,581,582],"Author: Fahad Mahmood","Plugin URI: https:\u002F\u002Fandroidbubble.com\u002Fblog\u002Fwordpress\u002Fplugins\u002Feasy-upload-files-during-checkout","Author URI: https:\u002F\u002Fwww.androidbubbles.com","This WordPress Plugin is free software: you can redistribute it and\u002For modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or any later version. This free software is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this software. If not, see http:\u002F\u002Fwww.gnu.org\u002Flicenses\u002Fgpl-2.0.html.",[584,585,586,587],"data-eufdc-id","data-max-size","data-file-types","data-is-required",[],[590],"eufdc_obj",[]]