[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcu_-7CdaCFd2oaiRfsmoJrV1jAt-ldrOM8xK6-rvadw":3,"$f8dJ4sc_0KFQ3C6RWG3K1x8chmtDYg40gsxhrGgAk-Oo":187,"$fW-cjBL2nFxu05SZIt61ewIuUrZIUYvepDysUvf73_oE":192},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":39,"analysis":131,"fingerprints":171},"image-protection","Image Protection","1.1.3","TWK Media","https:\u002F\u002Fprofiles.wordpress.org\u002Ftwkmedia\u002F","\u003Cp>This plugin protects images on your WordPress site from being copied, saved, or captured through screenshots. It achieves this by implementing various protective measures via JavaScript, ensuring that your visual content remains secure from unauthorized use.\u003C\u002Fp>\n\u003Cp>It also includes optional EXIF privacy tools to scan and remove privacy-sensitive metadata (such as GPS location) from images in your media library.\u003C\u002Fp>\n\u003Cp>Plugin developed by \u003Ca href=\"https:\u002F\u002Fthewebkitchen.co.uk\u002F\" rel=\"nofollow ugc\">TWK media\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Important Disclaimer\u003C\u002Fh4>\n\u003Cp>While this plugin implements various protection measures, it cannot guarantee 100% protection against all possible methods of image capture or copying. EXIF privacy cleanup cannot guarantee removal of every metadata field in every image format. Due to the nature of web browsers and operating systems, determined users may find ways to circumvent these protections. This plugin should be considered as a deterrent rather than an absolute solution. We do not provide any warranty or guarantee regarding the effectiveness of the protection measures.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Prevents right-click saving of images\u003C\u002Fli>\n\u003Cli>Blocks keyboard shortcuts for screenshots\u003C\u002Fli>\n\u003Cli>Disables drag-and-drop of images\u003C\u002Fli>\n\u003Cli>Prevents browser-based image copying\u003C\u002Fli>\n\u003Cli>Optional video blur protection (Settings > Image Protection)\u003C\u002Fli>\n\u003Cli>Optional site-wide right-click disable (Settings > Image Protection)\u003C\u002Fli>\n\u003Cli>Optional EXIF privacy cleanup on upload (Settings > Image Protection)\u003C\u002Fli>\n\u003Cli>Media library EXIF privacy scan and batch cleanup (Media > EXIF Privacy)\u003C\u002Fli>\n\u003Cli>Compatible with all major browsers\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Requirements\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress 5.0 or higher\u003C\u002Fli>\n\u003Cli>PHP 7.4 or higher\u003C\u002Fli>\n\u003Cli>JavaScript enabled in the browser\u003C\u002Fli>\n\u003Cli>EXIF privacy features require the PHP EXIF extension; selective cleanup works best with the ImageMagick (\u003Ccode>imagick\u003C\u002Fcode>) PHP extension\u003C\u002Fli>\n\u003C\u002Ful>\n","Protects images on your WordPress site from being copied or captured, with optional EXIF privacy tools for uploaded media.",100,1613,1,"2026-06-19T14:27:00.000Z","7.0.2","5.0","7.4",[19,20,21,22,23],"exif","image","privacy","protection","security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fimage-protection","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimage-protection.1.1.3.zip",0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":34,"avg_security_score":35,"avg_patch_time_days":36,"trust_score":37,"computed_at":38},"twkmedia",2,140,96,30,91,"2026-08-29T03:24:33.938Z",[40,60,78,94,112],{"slug":41,"name":42,"version":43,"author":44,"author_profile":45,"description":46,"short_description":47,"active_installs":48,"downloaded":49,"rating":11,"num_ratings":50,"last_updated":51,"tested_up_to":52,"requires_at_least":53,"requires_php":17,"tags":54,"homepage":57,"download_link":58,"security_score":59,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"wp-strip-image-metadata","WP Strip Image Metadata","1.0","Sami Falah","https:\u002F\u002Fprofiles.wordpress.org\u002Fsamiff\u002F","\u003Cp>WP Strip Image Metadata is a privacy focused WordPress plugin that helps in removing potentially sensitive metadata from your uploaded images.\u003C\u002Fp>\n\u003Cp>What is image metadata?\u003C\u002Fp>\n\u003Cp>Image metadata is extra information embedded in image files. This information is stored in a variety of formats and contains items like the model of the camera that took a photo.\u003C\u002Fp>\n\u003Cp>However, image metadata may also contain identifying information such as the GPS location coordinates of an image taken with a smartphone for example.\u003C\u002Fp>\n\u003Cp>This plugin provides an easy enabled\u002Fdisabled setting so you can make the call on when image metadata should be removed.\u003C\u002Fp>\n\u003Cp>Note: this plugin requires the “Imagick” or “Gmagick” PHP extension to function.\u003C\u002Fp>\n","Strip image metadata on upload or via bulk action, and view image EXIF data.",700,3823,3,"2022-06-12T23:00:00.000Z","6.0.12","5.9",[19,20,55,21,56],"metadata","strip","https:\u002F\u002Fgithub.com\u002Fsamiff\u002Fwp-strip-image-metadata","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-strip-image-metadata.1.0.zip",85,{"slug":61,"name":62,"version":63,"author":64,"author_profile":65,"description":66,"short_description":67,"active_installs":68,"downloaded":69,"rating":11,"num_ratings":13,"last_updated":70,"tested_up_to":71,"requires_at_least":72,"requires_php":17,"tags":73,"homepage":76,"download_link":77,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"simple-password-protect","Simple Password Protect","1.1.0","Desk9 Design","https:\u002F\u002Fprofiles.wordpress.org\u002Fdesk9\u002F","\u003Cp>Simple Password Protect provides an easy way to password-protect your entire WordPress website frontend. Perfect for development sites, private blogs, or any site that needs basic access control.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Global Protection\u003C\u002Fstrong>: Protects the entire frontend of your WordPress site\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GDPR Compliance\u003C\u002Fstrong>: Modal windows for Legal Disclosure and Privacy Policy pages\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure Authentication\u003C\u002Fstrong>: Uses WordPress password hashing and secure cookies\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Bypass\u003C\u002Fstrong>: WordPress administrators can access the site without password\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable Design\u003C\u002Fstrong>: Upload logos, customize colors and text\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Mobile Responsive\u003C\u002Fstrong>: Works perfectly ons all devices\u003C\u002Fli>\n\u003Cli>\u003Cstrong>24-Hour Sessions\u003C\u002Fstrong>: Authenticated users stay logged in for 24 hours\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Perfect For:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Development and staging sites\u003C\u002Fli>\n\u003Cli>Private family blogs\u003C\u002Fli>\n\u003Cli>Member-only websites\u003C\u002Fli>\n\u003Cli>Temporary site protection\u003C\u002Fli>\n\u003Cli>Client preview sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For support, please visit the plugin’s support forum or contact the developer.\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>This plugin stores a hashed version of your protection password in the WordPress database. It also sets a secure authentication cookie when users successfully enter the password. No personal data is collected or transmitted to external services.\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under the GPLv2 or later license.\u003Cbr \u002F>\nhttps:\u002F\u002Fwww.gnu.org\u002Flicenses\u002Fgpl-2.0.html\u003C\u002Fp>\n","Protect your entire WordPress site with a simple password. GDPR-compliant with modal links for legal pages.",400,1552,"2025-10-30T21:56:00.000Z","6.8.6","6.8",[74,75,21,22,23],"access-control","password","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsimple-password-protect","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsimple-password-protect.1.1.0.zip",{"slug":79,"name":80,"version":81,"author":82,"author_profile":83,"description":84,"short_description":85,"active_installs":86,"downloaded":87,"rating":11,"num_ratings":13,"last_updated":88,"tested_up_to":15,"requires_at_least":89,"requires_php":90,"tags":91,"homepage":92,"download_link":93,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"strip-image-metadata-for-jpg-and-webp","Strip Image Metadata","1.6.0","Martin von Berg","https:\u002F\u002Fprofiles.wordpress.org\u002Fmartinvonberg\u002F","\u003Cp>WP Strip Image Metadata is a privacy focused WordPress plugin that helps in removing potentially sensitive metadata from your uploaded images. It strips image metadata on upload or via bulk action, and view image EXIF data.\u003C\u002Fp>\n\u003Cp>This Plugin is based on the Plugin “WP Strip Image Metadata” from the WordPress.org plugin repository here: https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-strip-image-metadata\u002F\u003C\u002Fp>\n\u003Cp>This Plugin extends the Functionality of “WP Strip Image Metadata” with the following Functions:\u003C\u002Fp>\n\u003Ch4>Extended Functionality\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Handle AVIF and WEBP-Images, too.\u003C\u002Fli>\n\u003Cli>set \u002F add \u002F change Copyright, Artist or Credit Information in JPG and WEBP images Files.\u003C\u002Fli>\n\u003Cli>Set an upper Size Limit for the Stripping. All Files with Width greater than Size Limit won’t be stripped.\u003C\u002Fli>\n\u003Cli>Show some more Information in the Image Edit Panel\u003C\u002Fli>\n\u003Cli>Set a Minimum version for Imagick (3.4.4) and Gmagick (2.0.5) to handle files at all. Gmagick is still limited in functionality.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Preparation of Copyright Template Files\u003C\u002Fh4>\n\u003Cp>Both Imagick and Gmagick do not allow to set EXIF-Metadata directly. The author of this plugin does not know an Open Source PHP or WordPress Function with appropriate License to set metadata in an Image File. So a Template File is used that has to be prepared by the user. It’s only possible to use one template File for\u003Cbr \u002F>\none Artist, only! The Plugin uses one Template File for the whole site. So, if you are on a Multi-User-Site this Plugin is not for you.\u003C\u002Fp>\n\u003Col>\n\u003Cli>Prepare a JPG, WEBP and AVIF File with very small size, e.g. 100×100 or so. Image dimensions do not matter, here.\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Strip all Metadata with exiftool (current version writes avif and webp, too):\u003C\u002Fp>\n\u003Cp>\u003Ccode>exiftool.exe -all= .\u002Fyourfile.jpg -o copyright.jpg\u003Cbr \u002F>\nexiftool.exe -all= .\u002Fanotherfile.webp -o copyright.webp\u003Cbr \u002F>\nexiftool.exe -all= .\u002Faviffile.jpg -o copyright.avif\u003C\u002Fcode>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Add the Copyright (or other) EXIF-Metadata you prefer with Exiftool like so\u003C\u002Fp>\n\u003Cp>\u003Ccode>exiftool.exe -copyright=\"Copyright by User of the Plugin and Site\" .\u002Fcopyright.jpg\u003Cbr \u002F>\nexiftool.exe -artist=\"User of the Plugin and Site\" .\u002Fcopyright.jpg\u003C\u002Fcode>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>The other functionality of the Plugin was not changed so the original Readme follows herafter.\u003C\u002Fp>\n\u003Ch4>Original Description\u003C\u002Fh4>\n\u003Cp>Strip image metadata on upload or via bulk action, and view image EXIF data.\u003Cbr \u002F>\nWP Strip Image Metadata is a privacy focused WordPress plugin that helps in removing potentially sensitive metadata from your uploaded images.\u003C\u002Fp>\n\u003Ch4>What is image metadata?\u003C\u002Fh4>\n\u003Cp>Image metadata is extra information embedded in image files. This information is stored in a variety of formats and contains items like the model of the camera that took a photo.\u003Cbr \u002F>\nHowever, image metadata may also contain identifying information such as the GPS location coordinates of an image taken with a smartphone for example.\u003Cbr \u002F>\nThis plugin provides an easy enabled\u002Fdisabled setting so you can make the call on when image metadata should be removed.\u003Cbr \u002F>\n\u003Cstrong>Note\u003C\u002Fstrong>: this plugin requires the “Imagick” or “Gmagick” PHP extension to function.\u003C\u002Fp>\n","WP Strip Image Metadata is a privacy focused WordPress plugin that helps in removing potentially sensitive metadata from your uploaded images.",200,3546,"2026-06-12T12:26:00.000Z","6.0","8.0",[19,20,55,21,56],"https:\u002F\u002Fgithub.com\u002FMartinvonBerg\u002Fwp-strip-image-metadata","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstrip-image-metadata-for-jpg-and-webp.1.6.0.zip",{"slug":95,"name":96,"version":97,"author":98,"author_profile":99,"description":100,"short_description":101,"active_installs":11,"downloaded":102,"rating":26,"num_ratings":26,"last_updated":103,"tested_up_to":104,"requires_at_least":16,"requires_php":105,"tags":106,"homepage":110,"download_link":111,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"protect-my-infos","Protect My Infos","1.3.8","Yuga Web","https:\u002F\u002Fprofiles.wordpress.org\u002Fyugaweb\u002F","\u003Cp>\u003Cstrong>Protect My Infos\u003C\u002Fstrong> is a WordPress plugin designed to protect sensitive information, such as phone numbers and email addresses, by obfuscating or hiding them on the frontend of your site.\u003C\u002Fp>\n\u003Cp>Emails and phone numbers are encoded and hidden from bots, while visitors can interact with placeholders to reveal the information.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Obfuscate sensitive information with placeholders, blur effects, or base64 encoding.\u003C\u002Fli>\n\u003Cli>Use the \u003Ccode>[protect_my_infos]\u003C\u002Fcode> shortcode for integration in posts or pages.\u003C\u002Fli>\n\u003Cli>Fully customizable settings for icons, colors, and reveal texts.\u003C\u002Fli>\n\u003Cli>Easy-to-use admin interface.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin integrates with the PayPal Donate API to facilitate donations via PayPal’s secure platform.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service Name\u003C\u002Fstrong>: PayPal Donate API\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: To provide a “Donate” button for collecting user donations securely via PayPal.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent\u003C\u002Fstrong>:\n\u003Cul>\n\u003Cli>Donation amount\u003C\u002Fli>\n\u003Cli>Currency\u003C\u002Fli>\n\u003Cli>PayPal Merchant ID\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When\u003C\u002Fstrong>: Data is sent to PayPal only when a user interacts with the “Donate” button.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service Links\u003C\u002Fstrong>:\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.paypal.com\u002Fus\u002Fwebapps\u002Fmpp\u002Fua\u002Flegalhub-full\" rel=\"nofollow ugc\">PayPal Terms of Service\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.paypal.com\u002Fus\u002Fwebapps\u002Fmpp\u002Fua\u002Fprivacy-full\" rel=\"nofollow ugc\">PayPal Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Note: This plugin does not store or process sensitive personal information. All payment transactions are handled securely by PayPal’s platform.\u003C\u002Fp>\n","Protect sensitive information like emails and phone numbers from bots with advanced obfuscation techniques.",1167,"2025-12-11T15:33:00.000Z","6.9.5","7.2",[107,108,109,21,23],"anti-spam","email-obfuscation","phone-number-protection","https:\u002F\u002Fwww.yugaweb.com\u002Fprotect-my-infos\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fprotect-my-infos.1.3.8.zip",{"slug":113,"name":114,"version":115,"author":116,"author_profile":117,"description":118,"short_description":119,"active_installs":120,"downloaded":121,"rating":122,"num_ratings":33,"last_updated":123,"tested_up_to":124,"requires_at_least":125,"requires_php":126,"tags":127,"homepage":129,"download_link":130,"security_score":59,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"page-protection","Page Protection","1.2","mortenf","https:\u002F\u002Fprofiles.wordpress.org\u002Fmortenf\u002F","\u003Cp>This plugin adds optional per-page user name and password protection, implemented using standard HTTP protocol authorization headers, thus triggering the standard user\u002Fpassword dialog of the browser, and making it possible to make the browser store the credentials.\u003C\u002Fp>\n\u003Cp>Subpages of a protected page are protected with the same user name and password as their parent.\u003C\u002Fp>\n\u003Cp>Protected pages and their subpages do not show up in menus, search results and page lists.\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Col>\n\u003Cli>When editing a page, locate the section titled “Page Protection” (probably located near the bottom of the right sidebar).\u003C\u002Fli>\n\u003Cli>Check the box “Protect page and subpages”, and provide a user name and password combination.\u003C\u002Fli>\n\u003Cli>Optionally, check the box “Make page and subpages searchable”, if you want the page and its subpages turn up in search results, but only with their title, not their content.\u003C\u002Fli>\n\u003Cli>Save your page.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>Copyright (c) 2009 Morten Høybye Frederiksen \u003Ca href=\"mailto:morten@wasab.dk\" rel=\"nofollow ugc\">morten@wasab.dk\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Permission to use, copy, modify, and distribute this software for any\u003Cbr \u002F>\npurpose with or without fee is hereby granted, provided that the above\u003Cbr \u002F>\ncopyright notice and this permission notice appear in all copies.\u003C\u002Fp>\n\u003Cp>THE SOFTWARE IS PROVIDED “AS IS” AND THE AUTHOR DISCLAIMS ALL WARRANTIES\u003Cbr \u002F>\nWITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF\u003Cbr \u002F>\nMERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR\u003Cbr \u002F>\nANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES\u003Cbr \u002F>\nWHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN\u003Cbr \u002F>\nACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF\u003Cbr \u002F>\nOR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.\u003C\u002Fp>\n","Protect pages and their subpages with user name\u002Fpassword, and keep protected pages from showing up in menus, search results and page lists.",80,10131,60,"2009-09-09T20:45:00.000Z","2.8.4","2.8","",[128,21,22,23],"access","http:\u002F\u002Fwww.mfd-consult.dk\u002Fpage-protection\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpage-protection.zip",{"attackSurface":132,"codeSignals":155,"taintFlows":163,"riskAssessment":164,"analyzedAt":170},{"hooks":133,"ajaxHandlers":151,"restRoutes":152,"shortcodes":153,"cronEvents":154,"entryPointCount":26,"unprotectedCount":26},[134,140,144,148],{"type":135,"name":136,"callback":137,"file":138,"line":139},"action","admin_init","image_protection_register_settings","image-protection.php",74,{"type":135,"name":141,"callback":142,"file":138,"line":143},"admin_menu","image_protection_add_settings_page",90,{"type":135,"name":145,"callback":146,"file":138,"line":147},"wp_enqueue_scripts","image_protection_enqueue_scripts",186,{"type":135,"name":149,"callback":150,"file":138,"line":86},"plugins_loaded","image_protection_load_textdomain",[],[],[],[],{"dangerousFunctions":156,"sqlUsage":157,"outputEscaping":159,"fileOperations":26,"externalRequests":26,"nonceChecks":26,"capabilityChecks":13,"bundledLibraries":162},[],{"prepared":26,"raw":26,"locations":158},[],{"escaped":160,"rawEcho":26,"locations":161},8,[],[],[],{"summary":165,"deductions":166},"The 'image-protection' plugin, in version 1.0.7, demonstrates a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, reliance on prepared statements for any SQL queries, and proper output escaping are excellent security practices. Furthermore, the plugin shows no history of known vulnerabilities (CVEs), which is a significant positive indicator.  The plugin also appears to have a minimal attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events identified as entry points, and all identified entry points (though few) have capability checks. The lack of any identified taint flows further reinforces its secure design.\n\nHowever, the static analysis also highlights a critical area for potential concern: the complete absence of nonce checks. While the plugin only has one capability check, any interaction point that is not properly secured with nonces can be susceptible to Cross-Site Request Forgery (CSRF) attacks. The current data shows 0 unprotected entry points, which is good, but this relies on the existing capability checks being sufficient and correctly implemented for all potential interactions. The complete lack of taint analysis flows, while seemingly positive, might also indicate a very limited scope of analysis or a plugin with very minimal functionality that doesn't expose complex data processing paths.\n\nIn conclusion, the plugin exhibits robust security practices in key areas like SQL handling and output escaping, and its vulnerability history is clean. The primary weakness identified is the complete absence of nonce checks, which introduces a potential CSRF risk if the single capability check isn't sufficient for all plugin operations. The minimal attack surface is a strength, but further scrutiny of the single capability check's robustness and the overall data flow handling would be advisable.",[167],{"reason":168,"points":169},"Missing nonce checks",10,"2026-03-16T21:34:10.966Z",{"wat":172,"direct":179},{"assetPaths":173,"generatorPatterns":175,"scriptPaths":176,"versionParams":177},[174],"\u002Fwp-content\u002Fplugins\u002Fimage-protection\u002Fprotection.js",[],[174],[178],"image-protection\u002Fprotection.js?ver=",{"cssClasses":180,"htmlComments":181,"htmlAttributes":182,"restEndpoints":183,"jsGlobals":184,"shortcodeOutput":186},[],[],[],[],[185],"imageProtectionVars",[],{"error":188,"url":189,"statusCode":190,"statusMessage":191,"message":191},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fimage-protection\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":193,"versions":194},12,[195,201,208,215,221,228,235,242,249,256,263,270],{"version":6,"download_url":25,"svn_tag_url":196,"released_at":27,"has_diff":197,"diff_files_changed":198,"diff_lines":27,"trac_diff_url":199,"vulnerabilities":200,"is_current":188},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fimage-protection\u002Ftags\u002F1.1.3\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fimage-protection%2Ftags%2F1.1.2&new_path=%2Fimage-protection%2Ftags%2F1.1.3",[],{"version":202,"download_url":203,"svn_tag_url":204,"released_at":27,"has_diff":197,"diff_files_changed":205,"diff_lines":27,"trac_diff_url":206,"vulnerabilities":207,"is_current":197},"1.1.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimage-protection.1.1.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fimage-protection\u002Ftags\u002F1.1.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fimage-protection%2Ftags%2F1.1.1&new_path=%2Fimage-protection%2Ftags%2F1.1.2",[],{"version":209,"download_url":210,"svn_tag_url":211,"released_at":27,"has_diff":197,"diff_files_changed":212,"diff_lines":27,"trac_diff_url":213,"vulnerabilities":214,"is_current":197},"1.1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimage-protection.1.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fimage-protection\u002Ftags\u002F1.1.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fimage-protection%2Ftags%2F1.1.0&new_path=%2Fimage-protection%2Ftags%2F1.1.1",[],{"version":63,"download_url":216,"svn_tag_url":217,"released_at":27,"has_diff":197,"diff_files_changed":218,"diff_lines":27,"trac_diff_url":219,"vulnerabilities":220,"is_current":197},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimage-protection.1.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fimage-protection\u002Ftags\u002F1.1.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fimage-protection%2Ftags%2F1.0.7&new_path=%2Fimage-protection%2Ftags%2F1.1.0",[],{"version":222,"download_url":223,"svn_tag_url":224,"released_at":27,"has_diff":197,"diff_files_changed":225,"diff_lines":27,"trac_diff_url":226,"vulnerabilities":227,"is_current":197},"1.0.7","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimage-protection.1.0.7.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fimage-protection\u002Ftags\u002F1.0.7\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fimage-protection%2Ftags%2F1.0.6&new_path=%2Fimage-protection%2Ftags%2F1.0.7",[],{"version":229,"download_url":230,"svn_tag_url":231,"released_at":27,"has_diff":197,"diff_files_changed":232,"diff_lines":27,"trac_diff_url":233,"vulnerabilities":234,"is_current":197},"1.0.6","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimage-protection.1.0.6.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fimage-protection\u002Ftags\u002F1.0.6\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fimage-protection%2Ftags%2F1.0.5&new_path=%2Fimage-protection%2Ftags%2F1.0.6",[],{"version":236,"download_url":237,"svn_tag_url":238,"released_at":27,"has_diff":197,"diff_files_changed":239,"diff_lines":27,"trac_diff_url":240,"vulnerabilities":241,"is_current":197},"1.0.5","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimage-protection.1.0.5.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fimage-protection\u002Ftags\u002F1.0.5\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fimage-protection%2Ftags%2F1.0.4&new_path=%2Fimage-protection%2Ftags%2F1.0.5",[],{"version":243,"download_url":244,"svn_tag_url":245,"released_at":27,"has_diff":197,"diff_files_changed":246,"diff_lines":27,"trac_diff_url":247,"vulnerabilities":248,"is_current":197},"1.0.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimage-protection.1.0.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fimage-protection\u002Ftags\u002F1.0.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fimage-protection%2Ftags%2F1.0.3&new_path=%2Fimage-protection%2Ftags%2F1.0.4",[],{"version":250,"download_url":251,"svn_tag_url":252,"released_at":27,"has_diff":197,"diff_files_changed":253,"diff_lines":27,"trac_diff_url":254,"vulnerabilities":255,"is_current":197},"1.0.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimage-protection.1.0.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fimage-protection\u002Ftags\u002F1.0.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fimage-protection%2Ftags%2F1.0.2&new_path=%2Fimage-protection%2Ftags%2F1.0.3",[],{"version":257,"download_url":258,"svn_tag_url":259,"released_at":27,"has_diff":197,"diff_files_changed":260,"diff_lines":27,"trac_diff_url":261,"vulnerabilities":262,"is_current":197},"1.0.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimage-protection.1.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fimage-protection\u002Ftags\u002F1.0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fimage-protection%2Ftags%2F1.0.1&new_path=%2Fimage-protection%2Ftags%2F1.0.2",[],{"version":264,"download_url":265,"svn_tag_url":266,"released_at":27,"has_diff":197,"diff_files_changed":267,"diff_lines":27,"trac_diff_url":268,"vulnerabilities":269,"is_current":197},"1.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimage-protection.1.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fimage-protection\u002Ftags\u002F1.0.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fimage-protection%2Ftags%2F1.0.0&new_path=%2Fimage-protection%2Ftags%2F1.0.1",[],{"version":271,"download_url":272,"svn_tag_url":273,"released_at":27,"has_diff":197,"diff_files_changed":274,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":275,"is_current":197},"1.0.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimage-protection.1.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fimage-protection\u002Ftags\u002F1.0.0\u002F",[],[]]