[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_KRd9iZRtGirxc8b1zAlhz2FEPiwYTl_mHlp8Oa2nic":3,"$f-SttU57D5icm4TnFHWFJRzl4vuRn9BRm1zHKbtpfHMw":233,"$f7ALMKyhj4oyH23sQmITmSSCEzvaTW8qnYEYcAoXz5Tg":238},{"slug":4,"name":5,"version":6,"author":4,"author_profile":7,"description":8,"short_description":9,"active_installs":10,"downloaded":11,"rating":12,"num_ratings":12,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":21,"download_link":22,"security_score":23,"vuln_count":12,"unpatched_count":12,"last_vuln_date":24,"fetched_at":25,"discovery_status":26,"vulnerabilities":27,"developer":28,"crawl_stats":24,"alternatives":33,"analysis":136,"fingerprints":211},"funifier","Funifier","1.1","https:\u002F\u002Fprofiles.wordpress.org\u002Ffunifier\u002F","\u003Cp>To learn more about how gamification your site, visit www.funifier.com!\u003C\u002Fp>\n","The Funifier plugin was created to integrate with gamification system of the company.",10,2262,0,"2016-01-20T17:47:00.000Z","3.0.5","2.7","",[18,4,19,20],"admin","gamification","javascript","http:\u002F\u002Fwww.funifier.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffunifier.zip",85,null,"2026-04-06T09:54:40.288Z","no_bundle",[],{"slug":4,"display_name":4,"profile_url":7,"plugin_count":29,"total_installs":10,"avg_security_score":23,"avg_patch_time_days":30,"trust_score":31,"computed_at":32},1,30,84,"2026-08-29T16:23:11.400Z",[34,57,77,94,121],{"slug":35,"name":36,"version":37,"author":38,"author_profile":39,"description":40,"short_description":41,"active_installs":42,"downloaded":43,"rating":44,"num_ratings":30,"last_updated":45,"tested_up_to":46,"requires_at_least":47,"requires_php":48,"tags":49,"homepage":53,"download_link":54,"security_score":23,"vuln_count":29,"unpatched_count":12,"last_vuln_date":55,"fetched_at":56},"scripts-n-styles","Scripts n Styles","3.5.8","WraithKenny","https:\u002F\u002Fprofiles.wordpress.org\u002Fwraithkenny\u002F","\u003Cp>This plugin allows Admin users the ability to add custom CSS and JavaScript directly into individual Post, Pages or any other registered custom post types. You can also add classes to the body tag and the post container. There is a Global settings page for which you can write Scripts n Styles for the entire blog.\u003C\u002Fp>\n\u003Cp>Admin’s can also add classes to the TinyMCE “Formats” dropdown which users can use to style posts and pages directly. As of Scripts n Styles 3+ styles are reflected in the post editor.\u003C\u002Fp>\n\u003Cp>Because only well trusted users should ever be allowed to insert JavaScript directly into the pages of your site, this plugin restricts usage to admin type users. Admin’s have access to even more sensitive areas by definition, so that should be relatively safe 😉\u003C\u002Fp>\n\u003Ch4>Notes about the implementation:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Admin users, or more specifically, \u003Cem>any user with the \u003Ccode>manage_options\u003C\u002Fcode> and \u003Ccode>unfiltered_html\u003C\u002Fcode> capabilities\u003C\u002Fem> (which by default is \u003Cem>only\u003C\u002Fem> the admin type user) can use this plugin’s functionality. Some plugins extend user rolls, and so this plugin would naturally extend include rolls that have the appropriate capability.\u003C\u002Fli>\n\u003Cli>CSS Styles are embeded, not linked, at the bottom of the \u003Ccode>head\u003C\u002Fcode> element with \u003Ccode>style\u003C\u002Fcode> tags by using \u003Ccode>wp-head\u003C\u002Fcode>. If your theme doesn’t have this hook, this plugin (as well as most others) won’t work.\u003C\u002Fli>\n\u003Cli>JavaScript is embeded, not linked, at the bottom of the \u003Ccode>body\u003C\u002Fcode> (or \u003Ccode>head\u003C\u002Fcode>) element with \u003Ccode>script\u003C\u002Fcode> tags by using \u003Ccode>wp-footer\u003C\u002Fcode> (or \u003Ccode>wp-head\u003C\u002Fcode>). If your theme doesn’t have this hook, this plugin (as well as most others) won’t work.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>There is no input validation.\u003C\u002Fstrong> This plugin puts exactly what you type in the meta box directly into the \u003Ccode>html\u003C\u002Fcode> with no error checking. You are an Admin, and we trust you to be carefull. Try not to break anything.\u003C\u002Fli>\n\u003Cli>Do to the licensing of the libraries used, this plugin is released “GPL 3.0 or later” if you care about those things.\u003C\u002Fli>\n\u003C\u002Ful>\n","This plugin allows Admin users to individually add HTML, custom CSS, Classes and JavaScript directly to Post, Pages or any other custom post types.",30000,381931,88,"2023-06-06T19:13:00.000Z","6.2.9","5.0","7.4",[18,50,51,52,20],"code","css","custom","https:\u002F\u002Fwww.unfocus.com\u002Fprojects\u002Fscripts-n-styles\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fscripts-n-styles.3.5.8.zip","2023-05-18 00:00:00","2026-07-22T17:31:50.256Z",{"slug":58,"name":59,"version":60,"author":61,"author_profile":62,"description":63,"short_description":64,"active_installs":65,"downloaded":66,"rating":67,"num_ratings":68,"last_updated":69,"tested_up_to":70,"requires_at_least":71,"requires_php":16,"tags":72,"homepage":16,"download_link":76,"security_score":23,"vuln_count":12,"unpatched_count":12,"last_vuln_date":24,"fetched_at":56},"insert-code-lite","Insert Code Lite","0.1.4","Dmitry Mayorov","https:\u002F\u002Fprofiles.wordpress.org\u002Fiamdmitrymayorov\u002F","\u003Cp>With this plugin you can safely change your theme without worrying to loose the code you’ve added.\u003C\u002Fp>\n","Insert Code Lite lets you add scripts, styles, and other custom code to your website.",70,6406,100,2,"2018-12-04T20:45:00.000Z","5.0.25","3.9.2",[18,73,20,74,75],"counter","tracking","tracking-code","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finsert-code-lite.0.1.4.zip",{"slug":78,"name":79,"version":80,"author":81,"author_profile":82,"description":83,"short_description":84,"active_installs":10,"downloaded":85,"rating":67,"num_ratings":29,"last_updated":86,"tested_up_to":87,"requires_at_least":88,"requires_php":16,"tags":89,"homepage":92,"download_link":93,"security_score":23,"vuln_count":12,"unpatched_count":12,"last_vuln_date":24,"fetched_at":56},"admin-ajax-php-no-thank-you","Admin Ajax dot php? No Thank You!","0.6.3","postpostmodern","https:\u002F\u002Fprofiles.wordpress.org\u002Fpostpostmodern\u002F","\u003Cp>Changes the wp-admin\u002Fadmin-ajax.php endpoint to \u002Fajax\u002F\u003Cbr \u002F>\nAdds an endpoint to the REST API at \u003Ccode>\u002Fwp-json\u002Fwp\u002Fv2\u002Fadmin-ajax\u003C\u002Fcode> that behaves exactly as wp-admin\u002Fadmin-ajax.php\u003Cbr \u002F>\n– requires PHP 5.3\u003C\u002Fp>\n","Changes the wp-admin\u002Fadmin-ajax.php endpoint to \u002Fajax\u002F",2052,"2017-10-06T15:21:00.000Z","4.8.28","4.0",[90,91,20],"admin-ajax-php","ajax","https:\u002F\u002Fgithub.com\u002Fpinecone-dot-website\u002Fadmin-ajax-dot-php-no-thank-you","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadmin-ajax-php-no-thank-you.zip",{"slug":95,"name":96,"version":97,"author":98,"author_profile":99,"description":100,"short_description":101,"active_installs":10,"downloaded":102,"rating":67,"num_ratings":29,"last_updated":103,"tested_up_to":104,"requires_at_least":105,"requires_php":16,"tags":106,"homepage":119,"download_link":120,"security_score":23,"vuln_count":12,"unpatched_count":12,"last_vuln_date":24,"fetched_at":56},"admin-menu-slide","Admin Menu Slide","1.0","Maciej Krawczyk","https:\u002F\u002Fprofiles.wordpress.org\u002Fhelium-3\u002F","\u003Cp>Admin Menu Slide is a simple plugin that adds a feature to hide admin menu and make it slide when hovering on the edge of the screen. Works exactly like WordPress collapse menu – you can toggle the feature on\u002Foff by clicking a button, which is at the bottom of admin menu. When enabled, admin pages have full screen width.\u003C\u002Fp>\n","Adds a feature to hide admin menu and make it slide when hovering on the edge of the screen.",2592,"2015-07-30T13:50:00.000Z","4.3.34","3.8",[18,107,108,109,110,20,111,112,113,114,115,116,117,118],"administration","backend","dashboard","free","jquery","menu","mobile","navigation","page","performance","plugins","sidebar","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fadmin-menu-slide","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadmin-menu-slide.1.0.zip",{"slug":122,"name":123,"version":97,"author":124,"author_profile":125,"description":126,"short_description":127,"active_installs":10,"downloaded":128,"rating":67,"num_ratings":29,"last_updated":129,"tested_up_to":130,"requires_at_least":131,"requires_php":16,"tags":132,"homepage":134,"download_link":135,"security_score":23,"vuln_count":12,"unpatched_count":12,"last_vuln_date":24,"fetched_at":56},"follow-me-sidebar","Follow Me Sidebar","WazzaJB","https:\u002F\u002Fprofiles.wordpress.org\u002Fwazzajb\u002F","\u003Cp>This plugin is really great and simple, especially for those with long edit screens (perhaps due to custom fields?).\u003C\u002Fp>\n\u003Cp>With this plugin your admin sidebar (where your update\u002Fpublish button is housed) will follow you as you scroll down the page, this plugin also takes the following factors in to account.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>If the sidebar is longer than the viewport.\u003C\u002Fli>\n\u003Cli>If the edit screen goes into single column mode.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>With this plugin you can also still drag to reorder your sidebar boxes.\u003C\u002Fp>\n","Make the WordPress admin sidebar follow you as you scroll down the page, great for long edit screens!",2837,"2013-07-19T11:00:00.000Z","3.5.2","3.0",[18,133,20,111],"admin-sidebar","http:\u002F\u002Fwbickley.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffollow-me-sidebar.zip",{"attackSurface":137,"codeSignals":159,"taintFlows":180,"riskAssessment":201,"analyzedAt":210},{"hooks":138,"ajaxHandlers":155,"restRoutes":156,"shortcodes":157,"cronEvents":158,"entryPointCount":12,"unprotectedCount":12},[139,145,148,151],{"type":140,"name":141,"callback":142,"file":143,"line":144},"action","admin_enqueue_scripts","admin_funifier_js","funifier.php",66,{"type":140,"name":146,"callback":147,"file":143,"line":44},"wp_enqueue_scripts","site_funifier_js",{"type":140,"name":146,"callback":149,"file":143,"line":150},"site_funifier_basic_js",109,{"type":140,"name":152,"callback":153,"file":143,"line":154},"admin_menu","funifier_add_menu",116,[],[],[],[],{"dangerousFunctions":160,"sqlUsage":161,"outputEscaping":163,"fileOperations":12,"externalRequests":12,"nonceChecks":12,"capabilityChecks":12,"bundledLibraries":179},[],{"prepared":12,"raw":12,"locations":162},[],{"escaped":164,"rawEcho":165,"locations":166},15,5,[167,171,173,175,177],{"file":168,"line":169,"context":170},"funifier-options.php",21,"raw output",{"file":168,"line":172,"context":170},27,{"file":143,"line":174,"context":170},57,{"file":143,"line":176,"context":170},77,{"file":143,"line":178,"context":170},99,[],[181],{"entryPoint":182,"graph":183,"unsanitizedCount":199,"severity":200},"\u003Cfunifier-options> (funifier-options.php:0)",{"nodes":184,"edges":196},[185,190],{"id":186,"type":187,"label":188,"file":168,"line":189},"n0","source","$_POST (x4)",8,{"id":191,"type":192,"label":193,"file":168,"line":194,"wp_function":195},"n1","sink","update_option() [Settings Manipulation]",13,"update_option",[197],{"from":186,"to":191,"sanitized":198},false,4,"low",{"summary":202,"deductions":203},"The \"funifier\" v1.1 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified attack vectors such as unprotected AJAX handlers, REST API routes, shortcodes, or cron events. The code also avoids dangerous functions, file operations, and external HTTP requests. Importantly, all SQL queries are prepared, and there are no recorded vulnerabilities in its history, suggesting a diligent development approach to security.\n\nHowever, a closer examination reveals some potential areas of concern. While the overall number of output escapings is 20, a significant portion (25%) are not properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if the unescaped output contains user-supplied data. Additionally, the taint analysis indicates one flow with an unsanitized path, which, although not flagged as critical or high severity, still represents a potential risk that could be exploited under specific circumstances.\n\nThe plugin's lack of vulnerability history and the absence of specific security checks like nonce and capability checks on its entry points (which are currently zero, but this could change with future updates) are also noteworthy. While currently secure due to a lack of exposed entry points, this absence of fundamental security mechanisms could become a weakness if the plugin's functionality expands. Overall, the plugin appears to be developed with security in mind, but the unescaped outputs and the single unsanitized path warrant attention.",[204,207],{"reason":205,"points":206},"Unescaped output detected",6,{"reason":208,"points":209},"Unsanitized path in taint flow",7,"2026-03-17T01:37:08.842Z",{"wat":212,"direct":219},{"assetPaths":213,"generatorPatterns":215,"scriptPaths":216,"versionParams":218},[214],"\u002Fwp-content\u002Fplugins\u002Ffunifier\u002Ffunifier.php",[],[217],"\u002F\u002Fclient2.funifier.com\u002F2.0.0\u002Ffunifier.js",[],{"cssClasses":220,"htmlComments":221,"htmlAttributes":222,"restEndpoints":225,"jsGlobals":226,"shortcodeOutput":232},[],[],[223,224],"data-funifier-gui=\"start\"","data-id=\"pluginStart\"",[],[227,228,229,230,231],"window.funifierAsyncInit","Funifier.auth.authenticate","Funifier.init","Funifier._$","Funifier.widget._init",[],{"error":234,"url":235,"statusCode":236,"statusMessage":237,"message":237},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Ffunifier\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":68,"versions":239},[240,246],{"version":6,"download_url":241,"svn_tag_url":242,"released_at":24,"has_diff":198,"diff_files_changed":243,"diff_lines":24,"trac_diff_url":244,"vulnerabilities":245,"is_current":234},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffunifier.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Ffunifier\u002Ftags\u002F1.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Ffunifier%2Ftags%2F1.0&new_path=%2Ffunifier%2Ftags%2F1.1",[],{"version":97,"download_url":247,"svn_tag_url":248,"released_at":24,"has_diff":198,"diff_files_changed":249,"diff_lines":24,"trac_diff_url":24,"vulnerabilities":250,"is_current":198},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffunifier.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Ffunifier\u002Ftags\u002F1.0\u002F",[],[]]