[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fteFLxGSmozlkcIepQt9LcT-Vdm-uFAdeNsiiI7vgAKs":3,"$f5OExpzSMc71v-pv4RDpGDJrIIwsnZ6b9AnWvw36pk9o":122,"$fqeMCLdoIjzE-wBdu-romuJsIeVVHODYj9i-C2_hDflc":127},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":16,"download_link":18,"security_score":19,"vuln_count":11,"unpatched_count":11,"last_vuln_date":20,"fetched_at":21,"discovery_status":22,"vulnerabilities":23,"developer":24,"crawl_stats":20,"alternatives":29,"analysis":30,"fingerprints":102},"eventi-asiago-it","Eventi Asiago.it","1.1.4","wcmatteo","https:\u002F\u002Fprofiles.wordpress.org\u002Fwcmatteo\u002F","\u003Cp>Per utilizzare il plugin è necessario ottenere una Chiave API contattando info@webcloud.it.\u003C\u002Fp>\n","Gli eventi di Asiago.it direttamente nel tuo WordPress.",0,1299,"2019-11-05T11:06:00.000Z","5.2.24","4.6.1","",[],"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Feventi-asiago-it.1.1.4.zip",85,null,"2026-04-16T10:56:18.058Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":25,"total_installs":11,"avg_security_score":19,"avg_patch_time_days":26,"trust_score":27,"computed_at":28},2,30,84,"2026-05-20T09:10:07.291Z",[],{"attackSurface":31,"codeSignals":56,"taintFlows":89,"riskAssessment":90,"analyzedAt":101},{"hooks":32,"ajaxHandlers":47,"restRoutes":48,"shortcodes":49,"cronEvents":54,"entryPointCount":55,"unprotectedCount":11},[33,39,43],{"type":34,"name":35,"callback":36,"file":37,"line":38},"action","admin_menu","add_plugin_page","webcloud-asiago-events.php",120,{"type":34,"name":40,"callback":41,"file":37,"line":42},"admin_init","page_init",121,{"type":34,"name":44,"callback":45,"file":37,"line":46},"widgets_init","closure",237,[],[],[50],{"tag":51,"callback":52,"file":37,"line":53},"asiagoevents","Webcloud\\AsiagoEvents\\asiagoevents",42,[],1,{"dangerousFunctions":57,"sqlUsage":58,"outputEscaping":60,"fileOperations":11,"externalRequests":55,"nonceChecks":11,"capabilityChecks":11,"bundledLibraries":88},[],{"prepared":11,"raw":11,"locations":59},[],{"escaped":61,"rawEcho":62,"locations":63},13,12,[64,68,70,72,73,75,77,78,80,82,84,86],{"file":65,"line":66,"context":67},"views\u002Fevents.php",153,"raw output",{"file":65,"line":69,"context":67},158,{"file":65,"line":71,"context":67},164,{"file":65,"line":71,"context":67},{"file":65,"line":74,"context":67},168,{"file":65,"line":76,"context":67},170,{"file":65,"line":76,"context":67},{"file":65,"line":79,"context":67},173,{"file":65,"line":81,"context":67},176,{"file":37,"line":83,"context":67},65,{"file":37,"line":85,"context":67},67,{"file":37,"line":87,"context":67},70,[],[],{"summary":91,"deductions":92},"The \"eventi-asiago-it\" v1.1.4 plugin exhibits a generally positive security posture with no recorded vulnerabilities or critical code signals. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The plugin also demonstrates good practices in its limited attack surface, with all identified entry points (a single shortcode) not explicitly protected by authentication or capability checks, but given the lack of other entry points and the absence of taint analysis findings, this might indicate a well-contained functionality.\n\nHowever, there are areas for improvement. The 52% rate of properly escaped output is a concern, as it suggests a significant portion of user-facing data might be vulnerable to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks, while not leading to immediate critical issues in the static analysis, represents a potential weakness if the shortcode's functionality were to be expanded or if it interacts with user-supplied data in ways not immediately apparent. The lack of any taint analysis data could mean the analysis tools were not configured to perform it, or that the code structure did not lend itself to such analysis, which might hide subtle vulnerabilities.\n\nOverall, the plugin appears to be reasonably secure for its current version and scope, primarily due to the lack of known vulnerabilities and dangerous code patterns. The main risk lies in the unescaped output, which could be exploited by attackers. Strengthening output escaping and potentially implementing more robust access controls, even for seemingly simple shortcodes, would further enhance its security.",[93,96,99],{"reason":94,"points":95},"Significant portion of output not properly escaped",8,{"reason":97,"points":98},"Missing nonce checks",5,{"reason":100,"points":98},"Missing capability checks","2026-04-16T15:00:14.686Z",{"wat":103,"direct":108},{"assetPaths":104,"generatorPatterns":105,"scriptPaths":106,"versionParams":107},[],[],[],[],{"cssClasses":109,"htmlComments":111,"htmlAttributes":112,"restEndpoints":118,"jsGlobals":119,"shortcodeOutput":120},[110],"webcloud-asiago-events-widget",[],[113,114,115,116,117],"id=\"webcloud_asiago_events_widget\"","id=\"api-key\"","name=\"webcloud_asiago_events_options[api_key]\"","id=\"filter_by_customer\"","name=\"webcloud_asiago_events_options[filter_by_customer]\"",[],[],[121],"[asiagoevents]",{"error":123,"url":124,"statusCode":125,"statusMessage":126,"message":126},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Feventi-asiago-it\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":128,"versions":129},6,[130,136,143,150,157,164],{"version":6,"download_url":18,"svn_tag_url":131,"released_at":20,"has_diff":132,"diff_files_changed":133,"diff_lines":20,"trac_diff_url":134,"vulnerabilities":135,"is_current":123},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Feventi-asiago-it\u002Ftags\u002F1.1.4\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Feventi-asiago-it%2Ftags%2F1.1.3&new_path=%2Feventi-asiago-it%2Ftags%2F1.1.4",[],{"version":137,"download_url":138,"svn_tag_url":139,"released_at":20,"has_diff":132,"diff_files_changed":140,"diff_lines":20,"trac_diff_url":141,"vulnerabilities":142,"is_current":132},"1.1.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Feventi-asiago-it.1.1.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Feventi-asiago-it\u002Ftags\u002F1.1.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Feventi-asiago-it%2Ftags%2F1.1.2&new_path=%2Feventi-asiago-it%2Ftags%2F1.1.3",[],{"version":144,"download_url":145,"svn_tag_url":146,"released_at":20,"has_diff":132,"diff_files_changed":147,"diff_lines":20,"trac_diff_url":148,"vulnerabilities":149,"is_current":132},"1.1.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Feventi-asiago-it.1.1.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Feventi-asiago-it\u002Ftags\u002F1.1.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Feventi-asiago-it%2Ftags%2F1.1.1&new_path=%2Feventi-asiago-it%2Ftags%2F1.1.2",[],{"version":151,"download_url":152,"svn_tag_url":153,"released_at":20,"has_diff":132,"diff_files_changed":154,"diff_lines":20,"trac_diff_url":155,"vulnerabilities":156,"is_current":132},"1.1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Feventi-asiago-it.1.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Feventi-asiago-it\u002Ftags\u002F1.1.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Feventi-asiago-it%2Ftags%2F1.1&new_path=%2Feventi-asiago-it%2Ftags%2F1.1.1",[],{"version":158,"download_url":159,"svn_tag_url":160,"released_at":20,"has_diff":132,"diff_files_changed":161,"diff_lines":20,"trac_diff_url":162,"vulnerabilities":163,"is_current":132},"1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Feventi-asiago-it.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Feventi-asiago-it\u002Ftags\u002F1.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Feventi-asiago-it%2Ftags%2F1.0&new_path=%2Feventi-asiago-it%2Ftags%2F1.1",[],{"version":165,"download_url":166,"svn_tag_url":167,"released_at":20,"has_diff":132,"diff_files_changed":168,"diff_lines":20,"trac_diff_url":20,"vulnerabilities":169,"is_current":132},"1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Feventi-asiago-it.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Feventi-asiago-it\u002Ftags\u002F1.0\u002F",[],[]]