[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQScmAy6bcV4HF2VHBZXhDfYQR2Rb2XTsh6XI3W4SSTA":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":20,"download_link":21,"security_score":13,"vuln_count":22,"unpatched_count":22,"last_vuln_date":23,"fetched_at":24,"vulnerabilities":25,"developer":26,"crawl_stats":23,"alternatives":33,"analysis":34,"fingerprints":69},"hide-user-fields","Hide User fields","1.0","Benjamin Hagh Parast","https:\u002F\u002Fprofiles.wordpress.org\u002Fhaghs\u002F","\u003Cp>This plugin hides all social media fields and other user profile like email on profile page.\u003C\u002Fp>\n","Just activate the plugin and enjoy.",10,874,100,1,"2026-01-09T17:39:00.000Z","6.9.4","6.9","8.0",[4],"https:\u002F\u002Fwordtune.me","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhide-user-fields.1.0.zip",0,null,"2026-03-15T15:16:48.613Z",[],{"slug":27,"display_name":7,"profile_url":8,"plugin_count":28,"total_installs":29,"avg_security_score":13,"avg_patch_time_days":30,"trust_score":31,"computed_at":32},"haghs",18,330,30,94,"2026-04-04T07:57:06.416Z",[],{"attackSurface":35,"codeSignals":56,"taintFlows":64,"riskAssessment":65,"analyzedAt":68},{"hooks":36,"ajaxHandlers":52,"restRoutes":53,"shortcodes":54,"cronEvents":55,"entryPointCount":22,"unprotectedCount":22},[37,43,48],{"type":38,"name":39,"callback":40,"file":41,"line":42},"filter","user_contactmethods","hide_user_fields","HideProfileFields.php",12,{"type":44,"name":45,"callback":46,"file":41,"line":47},"action","admin_head","hide_user_fields_start",50,{"type":44,"name":49,"callback":50,"file":41,"line":51},"admin_footer","hide_user_fields_end",51,[],[],[],[],{"dangerousFunctions":57,"sqlUsage":58,"outputEscaping":60,"fileOperations":22,"externalRequests":22,"nonceChecks":22,"capabilityChecks":62,"bundledLibraries":63},[],{"prepared":22,"raw":22,"locations":59},[],{"escaped":22,"rawEcho":22,"locations":61},[],2,[],[],{"summary":66,"deductions":67},"The \"hide-user-fields\" plugin v1.0 demonstrates an excellent security posture based on the provided static analysis. The plugin has no identified attack surface in terms of AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authentication or permission checks. Furthermore, the code signals indicate a complete absence of dangerous functions, and all SQL queries utilize prepared statements, with all output being properly escaped. There are no file operations or external HTTP requests, and importantly, no nonce checks were found, suggesting that the plugin doesn't rely on nonces for its operations, which is generally a good sign when other security measures are in place.\n\nThe taint analysis also reveals no critical or high severity unsanitized paths, reinforcing the impression of secure coding practices. The plugin also has no recorded vulnerability history, including no known CVEs, which is a significant positive indicator of its security.  While the absence of nonce checks might, in other contexts, be a concern, given the total lack of any identified entry points and other strong security signals, it is unlikely to represent a vulnerability here. The plugin's strengths lie in its minimal attack surface, robust handling of data (SQL, output), and clean vulnerability record.",[],"2026-03-17T01:12:57.413Z",{"wat":70,"direct":79},{"assetPaths":71,"generatorPatterns":74,"scriptPaths":75,"versionParams":76},[72,73],"\u002Fwp-content\u002Fplugins\u002Fhide-user-fields\u002Fassets\u002Fcss\u002Fstyle.css","\u002Fwp-content\u002Fplugins\u002Fhide-user-fields\u002Fassets\u002Fjs\u002Fscript.js",[],[73],[77,78],"hide-user-fields\u002Fassets\u002Fcss\u002Fstyle.css?ver=","hide-user-fields\u002Fassets\u002Fjs\u002Fscript.js?ver=",{"cssClasses":80,"htmlComments":81,"htmlAttributes":82,"restEndpoints":83,"jsGlobals":84,"shortcodeOutput":85},[],[],[],[],[],[]]