[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5B46kUJXUY8nOFCdi7jRpp7rN9x-nMPYbDeUlaL-ARo":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":17,"download_link":24,"security_score":25,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27,"vulnerabilities":28,"developer":29,"crawl_stats":26,"alternatives":36,"analysis":130,"fingerprints":178},"ga-code-visibility","GA Code Visibility","0.4","Off Site Services","https:\u002F\u002Fprofiles.wordpress.org\u002Foff-site-services\u002F","\u003Cp>Allows admins to add Google Analytics code to \u003Ccode>\u003Chead>\u003C\u002Fcode> and use it only when site is switched to “Search Engine Visibility”.\u003C\u002Fp>\n\u003Cp>Use Settings->Reading: check\u002Funcheck “Search Engine Visibility” and add code to “GA code fields”.\u003C\u002Fp>\n","Easily add Google Analytics code to your head and use it only when site is switched to \"Search Engine Visibility\".",10,1681,0,"2021-03-10T15:22:00.000Z","5.7.15","3.0.1","",[19,20,21,22,23],"add-to-head","head","head-code","header","header-code","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fga-code-visibility.zip",85,null,"2026-03-15T15:16:48.613Z",[],{"slug":30,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":32,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"off-site-services",2,60,30,84,"2026-04-04T14:09:52.798Z",[37,50,69,87,111],{"slug":38,"name":39,"version":40,"author":7,"author_profile":8,"description":41,"short_description":42,"active_installs":43,"downloaded":44,"rating":13,"num_ratings":13,"last_updated":45,"tested_up_to":15,"requires_at_least":46,"requires_php":47,"tags":48,"homepage":17,"download_link":49,"security_score":25,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27},"gtm-code-visibility","GTM Code Visibility","0.1","\u003Cp>Allows admins to add Google Tag Manager code to your site and use it only when site is switched to “Search Engine Visibility”.\u003C\u002Fp>\n\u003Cp>Use Settings->Reading: check\u002Funcheck “Search Engine Visibility” and add code to “GTM code fields”.\u003C\u002Fp>\n","Easily add Google Tag Manager code to your site and use it only when site is switched to \"Search Engine Visibility\".",50,1520,"2021-03-10T15:26:00.000Z","4.0.1","5.2.4",[19,20,21,22,23],"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgtm-code-visibility.zip",{"slug":51,"name":52,"version":53,"author":54,"author_profile":55,"description":56,"short_description":57,"active_installs":58,"downloaded":59,"rating":60,"num_ratings":61,"last_updated":62,"tested_up_to":63,"requires_at_least":16,"requires_php":17,"tags":64,"homepage":17,"download_link":68,"security_score":25,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27},"addfunc-head-footer-code","AddFunc Head & Footer Code","2.3","AddFunc","https:\u002F\u002Fprofiles.wordpress.org\u002Faddfunc\u002F","\u003Cp>Allows administrators to add code to the \u003Ccode>\u003Chead>\u003C\u002Fcode> and\u002For footer of an individual post (or page or other content) and\u002For site-wide. Ideal for scripts such as Google Analytics conversion tracking code and any other general or page-specific JavaScript. A very simple, reliable and lightweight plugin.\u003C\u002Fp>\n","Easily add code to your head, footer and\u002For immediately after the opening body tag, site-wide and\u002For on any individual page\u002Fpost.",20000,234825,100,25,"2019-05-29T19:41:00.000Z","5.2.24",[19,65,21,66,67],"footer-code","per-page","tracking-code","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faddfunc-head-footer-code.2.3.zip",{"slug":70,"name":71,"version":72,"author":73,"author_profile":74,"description":75,"short_description":76,"active_installs":77,"downloaded":78,"rating":60,"num_ratings":79,"last_updated":80,"tested_up_to":81,"requires_at_least":82,"requires_php":83,"tags":84,"homepage":17,"download_link":86,"security_score":25,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27},"embed-code","Embed Code – Headers & Footers by DesignBombs","2.0.4","designbombs","https:\u002F\u002Fprofiles.wordpress.org\u002Fdesignbombs\u002F","\u003Cp>Easily insert or embed header and footer code in WordPress. Embed Code makes embedding global or page\u002Fpost-specific header and footer code super easy. It can be used to add almost anything, including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Google Analytics tracking code\u003C\u002Fli>\n\u003Cli>Site verification snippets\u003C\u002Fli>\n\u003Cli>Typekit font scripts\u003C\u002Fli>\n\u003Cli>Custom CSS\u003C\u002Fli>\n\u003Cli>Custom JavaScript\u003C\u002Fli>\n\u003Cli>Optimizely embed code\u003C\u002Fli>\n\u003Cli>Facebook tracking pixel\u003C\u002Fli>\n\u003Cli>Live chat integration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>It even supports embedding code on custom post types!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What’s Next?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This plugin is maintained by folks over at \u003Ca href=\"http:\u002F\u002Fdesignbombs.com\" rel=\"nofollow ugc\">DesignBombs.com\u003C\u002Fa>. If you are looking to start a new website, checkout their guide on \u003Ca href=\"https:\u002F\u002Fwww.designbombs.com\u002Fhow-to-make-a-website\u002F\" rel=\"nofollow ugc\">how to create a website\u003C\u002Fa>. They also have in-depth guides on other topics like how to \u003Ca href=\"https:\u002F\u002Fwww.designbombs.com\u002Fbest-wordpress-hosting\" rel=\"nofollow ugc\">choose the best WordPress hosting\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fwww.designbombs.com\u002Fhow-to-start-a-blog\u002F\" rel=\"nofollow ugc\">how to start a blog\u003C\u002Fa>, and \u003Ca href=\"https:\u002F\u002Fwww.designbombs.com\u002Fwordpress-security\u002F\" rel=\"nofollow ugc\">WordPress security\u003C\u002Fa>.\u003C\u002Fp>\n","The easiest way to embed code in the head or footer of your site, globally or on a per-page\u002Fpost basis.",5000,59115,6,"2021-08-04T08:03:00.000Z","5.8.13","4.7.0","5.4",[70,85,65,23,67],"embed-javascript","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fembed-code.zip",{"slug":88,"name":89,"version":90,"author":91,"author_profile":92,"description":93,"short_description":94,"active_installs":95,"downloaded":96,"rating":60,"num_ratings":79,"last_updated":97,"tested_up_to":98,"requires_at_least":99,"requires_php":100,"tags":101,"homepage":17,"download_link":107,"security_score":108,"vuln_count":109,"unpatched_count":13,"last_vuln_date":110,"fetched_at":27},"add-custom-codes","Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript","4.80","SaifuMak","https:\u002F\u002Fprofiles.wordpress.org\u002Fsaifumak\u002F","\u003Cp>Add custom codes to your wordpress website. You can add custom PHP Functions, HTML, custom CSS, Javascript, Google Analytics, Search Console verification tags or other code snippets to your site.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>100% free wordpress plugin, no paid upgrades needed!\u003C\u002Fli>\n\u003Cli>Add PHP Snippets, Custom CSS, Javascript, Google Analytics, Facebook Scripts, Meta Verification Codes, Search console verification and other codes to your wordpress website easily.\u003C\u002Fli>\n\u003Cli>Generate Shortcodes for HTML Snippets and use it anywhere on the site!\u003C\u002Fli>\n\u003Cli>Syntax highlighter enabled with Light and Dark Mode Editors\u003C\u002Fli>\n\u003Cli>Classify snippets using tags\u003C\u002Fli>\n\u003Cli>Add Notes to Snippets\u003C\u002Fli>\n\u003Cli>Activate\u002FInactivate snippets with a single click\u003C\u002Fli>\n\u003Cli>Auto-deactivate feature for PHP snippets that causes errors.\u003C\u002Fli>\n\u003Cli>Add Custome Codes globally or on individual posts, pages, products and even on custom post types.\u003C\u002Fli>\n\u003Cli>Option to select where to put snippets: before \u003Cem>\u003C\u002Fhead>\u003C\u002Fem> or before \u003Cem>\u003C\u002Fbody>\u003C\u002Fem> etc.\u003C\u002Fli>\n\u003Cli>Import\u002FExport Snippets to use on other sites.\u003C\u002Fli>\n\u003C\u002Ful>\n","Add custom codes to your wordpress site. A completely free plugin to add Custom PHP functions, HTML, CSS, Javascript, any other codes to your website.",1000,16630,"2025-04-29T06:08:00.000Z","6.8.5","6.6.2","7.4",[102,103,104,105,106],"custom-codes","custom-css","footer-codes","header-codes","php-snippets","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadd-custom-codes.4.80.zip",93,4,"2025-12-31 00:00:00",{"slug":112,"name":113,"version":114,"author":115,"author_profile":116,"description":117,"short_description":118,"active_installs":119,"downloaded":120,"rating":60,"num_ratings":121,"last_updated":122,"tested_up_to":123,"requires_at_least":124,"requires_php":17,"tags":125,"homepage":127,"download_link":128,"security_score":129,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27},"vanilla-bean-meta-maid","Vanilla Bean – Meta Maid","2.1.0","vsmash","https:\u002F\u002Fprofiles.wordpress.org\u002Fvsmash\u002F","\u003Cp>Meta Maid is the simplest of plugins, allowing you to add meta tags, script tags and tracking code to\u003Cbr \u002F>\nthe top and bottom of your page.\u003C\u002Fp>\n","Meta Maid is the simplest of plugins, allowing you to add meta tags, script tags and tracking code to",20,3390,1,"2024-06-22T03:42:00.000Z","6.5.8","4.0",[65,23,126,67],"meta-tags","http:\u002F\u002Fwww.velvary.com.au\u002Fvanilla-beans\u002Fwordpress\u002Fmeta-maid\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvanilla-bean-meta-maid.2.1.0.zip",92,{"attackSurface":131,"codeSignals":152,"taintFlows":167,"riskAssessment":168,"analyzedAt":177},{"hooks":132,"ajaxHandlers":148,"restRoutes":149,"shortcodes":150,"cronEvents":151,"entryPointCount":13,"unprotectedCount":13},[133,139,144],{"type":134,"name":135,"callback":136,"file":137,"line":138},"filter","admin_init","register_fields","ga_add.php",27,{"type":140,"name":141,"callback":142,"file":137,"line":143},"action","admin_footer","custom_admin_js",48,{"type":140,"name":145,"callback":146,"file":137,"line":147},"wp_head","outputGaCode",62,[],[],[],[],{"dangerousFunctions":153,"sqlUsage":154,"outputEscaping":156,"fileOperations":13,"externalRequests":13,"nonceChecks":13,"capabilityChecks":13,"bundledLibraries":166},[],{"prepared":13,"raw":13,"locations":155},[],{"escaped":13,"rawEcho":157,"locations":158},3,[159,162,164],{"file":137,"line":160,"context":161},35,"raw output",{"file":137,"line":163,"context":161},45,{"file":137,"line":165,"context":161},59,[],[],{"summary":169,"deductions":170},"The static analysis of 'ga-code-visibility' v0.4 reveals a plugin with a seemingly minimal attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, and therefore no unprotected entry points. The code also avoids dangerous functions, file operations, and external HTTP requests.  Furthermore, all SQL queries are confirmed to use prepared statements, which is a strong security practice.\n\nHowever, a significant concern arises from the complete lack of output escaping, with 100% of identified outputs being unescaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is ever reflected directly in the output without proper sanitization. The absence of nonce checks and capability checks across all entry points is also a weakness, as it means any authenticated user could potentially trigger actions within the plugin, even if those actions were intended for administrators.\n\nThe plugin's vulnerability history is clean, with no known CVEs or past vulnerabilities. This suggests a good track record, but it does not negate the inherent risks identified in the current code. In conclusion, while the plugin demonstrates strengths in avoiding common pitfalls like raw SQL and external requests, the critical lack of output escaping and insufficient authorization checks present notable security risks.",[171,173,175],{"reason":172,"points":79},"Outputs are not properly escaped",{"reason":174,"points":109},"No nonce checks on entry points",{"reason":176,"points":109},"No capability checks on entry points","2026-03-17T00:53:12.111Z",{"wat":179,"direct":185},{"assetPaths":180,"generatorPatterns":182,"scriptPaths":183,"versionParams":184},[181],"\u002Fwp-content\u002Fplugins\u002Fga-code-visibility\u002Fjs\u002Fga-plugin.js",[],[181],[],{"cssClasses":186,"htmlComments":187,"htmlAttributes":188,"restEndpoints":189,"jsGlobals":190,"shortcodeOutput":191},[],[],[],[],[],[]]