[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTwzsR1h2M6qxh1ZzcfFCuRlH8lnaw-YhiSu6f9ENTQ0":3,"$fXRQdrqeMMMu_bi95dR_GDHS5psaASd1JahkADIBetK8":79,"$fEikh721iYVc8GuPvr7QTlLmOIQD1hHmCoI5gx_ChFR0":84},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":20,"download_link":21,"security_score":22,"vuln_count":23,"unpatched_count":23,"last_vuln_date":24,"fetched_at":25,"discovery_status":26,"vulnerabilities":27,"developer":28,"crawl_stats":24,"alternatives":34,"analysis":35,"fingerprints":66},"get-page-url","Get Page URL","1.0","Ehab Ahmad","https:\u002F\u002Fprofiles.wordpress.org\u002Fehabahmad\u002F","\u003Cp>Get Page URL is a simple plugin to get the current opened page URL. Just copy the ShortCode [getpageurl] and paste it in your post\u002Fpage in default or any page builder.\u003C\u002Fp>\n","Just copy the ShortCode [getpageurl] and paste it in your post\u002Fpage",20,972,100,2,"2022-06-14T05:52:00.000Z","6.0.11","4.0","",[],"#","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fget-page-url.zip",85,0,null,"2026-04-06T09:54:40.288Z","no_bundle",[],{"slug":29,"display_name":7,"profile_url":8,"plugin_count":14,"total_installs":11,"avg_security_score":30,"avg_patch_time_days":31,"trust_score":32,"computed_at":33},"ehabahmad",93,30,89,"2026-08-29T19:25:33.721Z",[],{"attackSurface":36,"codeSignals":48,"taintFlows":55,"riskAssessment":56,"analyzedAt":65},{"hooks":37,"ajaxHandlers":38,"restRoutes":39,"shortcodes":40,"cronEvents":46,"entryPointCount":47,"unprotectedCount":23},[],[],[],[41],{"tag":42,"callback":43,"file":44,"line":45},"getpageurl","get_current_page_url","get_current_url.php",39,[],1,{"dangerousFunctions":49,"sqlUsage":50,"outputEscaping":52,"fileOperations":23,"externalRequests":23,"nonceChecks":23,"capabilityChecks":23,"bundledLibraries":54},[],{"prepared":23,"raw":23,"locations":51},[],{"escaped":47,"rawEcho":23,"locations":53},[],[],[],{"summary":57,"deductions":58},"The 'get-page-url' plugin version 1.0 presents a generally positive security posture based on the provided static analysis.  The absence of dangerous functions, raw SQL queries, and unescaped output are strong indicators of good development practices. Furthermore, the lack of any recorded vulnerabilities in its history suggests a history of secure development and maintenance.  The plugin also demonstrates a minimal attack surface, with only one shortcode identified and no AJAX handlers or REST API routes exposed without proper authentication checks.\n\nHowever, a significant area of concern is the complete lack of nonce checks and capability checks. While the static analysis found no direct exploitable flows, the absence of these fundamental security mechanisms leaves the shortcode open to potential Cross-Site Request Forgery (CSRF) attacks.  If the shortcode performs any sensitive actions or manipulates data in a way that could be leveraged by an attacker through a malicious link, this lack of protection is a critical oversight.  Given the limited attack surface and the absence of other security flaws, the primary risk lies in this potential for CSRF.",[59,62],{"reason":60,"points":61},"Missing Nonce Checks",15,{"reason":63,"points":64},"Missing Capability Checks",10,"2026-03-16T22:55:41.559Z",{"wat":67,"direct":72},{"assetPaths":68,"generatorPatterns":69,"scriptPaths":70,"versionParams":71},[],[],[],[],{"cssClasses":73,"htmlComments":74,"htmlAttributes":75,"restEndpoints":76,"jsGlobals":77,"shortcodeOutput":78},[],[],[],[],[],[42],{"error":80,"url":81,"statusCode":82,"statusMessage":83,"message":83},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fget-page-url\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":23,"versions":85},[]]