[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4TYqj3jYUi-vTx9Jyo00fEbh0Pq8yum1mMsNYEbUYQI":3,"$fIn0UaXHGdZLG9rhYVlg7DluuHnayzV--BX9d2cwQPS4":223,"$fECheGg8Hc0BpTapHDx8E5c9OxejyGhHL34Nt-0EQ8L0":228},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":16,"download_link":23,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26,"discovery_status":27,"vulnerabilities":28,"developer":29,"crawl_stats":25,"alternatives":35,"analysis":139,"fingerprints":202},"informationsabfrage-spigotmc","Informationsabfrage – Spigotmc","1.0","domisiding","https:\u002F\u002Fprofiles.wordpress.org\u002Fdomisiding\u002F","\u003Cp>Mit diesen Plugin kann man Informationen von einem Plugin abfragen, welches auf spigotmc.org hochgeladen wurde.\u003C\u002Fp>\n\u003Cp>Webseite: https:\u002F\u002Fdomisiding.de\u003C\u002Fp>\n\u003Ch3>Terms\u003C\u002Fh3>\n\u003Cp>Spiget API: https:\u002F\u002Fspiget.org\u003C\u002Fp>\n\u003Cp>Spiget Datenschutz \u002F Privacy: https:\u002F\u002Fspiget.org\u002Flegal\u002Fterms\u002F\u003C\u002Fp>\n","Mit diesen Plugin kann man Informationen von einem Plugin abfragen, welches auf spigotmc.org hochgeladen wurde.",0,5199,"2023-07-06T15:59:00.000Z","6.2.9","3.7.0","",[18,19,20,21,22],"import","information","json","spiget","spigotmc","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finformationsabfrage-spigotmc.1.0.zip",85,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":30,"total_installs":31,"avg_security_score":24,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},4,100,30,84,"2026-08-29T09:45:30.401Z",[36,60,80,101,121],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":46,"num_ratings":47,"last_updated":48,"tested_up_to":49,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":56,"download_link":57,"security_score":58,"vuln_count":30,"unpatched_count":11,"last_vuln_date":59,"fetched_at":26},"import-xml-feed","Import XML and RSS Feeds","2.1.6","Moove Agency","https:\u002F\u002Fprofiles.wordpress.org\u002Fmooveagency\u002F","\u003Cp>Import content from any XML or RSS file or URL.\u003C\u002Fp>\n\u003Cp>You can import the content to any post type in your WordPress install. You can also import taxonomies.\u003C\u002Fp>\n\u003Cp>Our plugin is especailly useful for importing content from Wix websites.\u003C\u002Fp>\n\u003Ch3>Step by Step process\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Select the source ( URL or FILE UPLOAD ).\u003C\u002Fli>\n\u003Cli>Select your repeated XML element you want to import – this should be the node in your XML file which will be considered a post upon import.\u003C\u002Fli>\n\u003Cli>Select the post type you want to import the content to.\u003C\u002Fli>\n\u003Cli>Match the fields from the XML node you’ve selected (step 2) to the corresponding fields you have available on the post type.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Supported files and URLs\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>The XML source file should be a valid XML file. \u003Ca href=\"https:\u002F\u002Fvalidator.w3.org\u002Ffeed\u002F\" rel=\"nofollow ugc\">You can check your feed validation here.\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>JSON feeds needs to be first converted to RSS or XML file \u003Ca href=\"https:\u002F\u002Fwww.convertjson.com\u002Fjson-to-xml.htm\" rel=\"nofollow ugc\">using tools such as this.\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>The plugin will then check if the URL source or the uploaded file is valid before the import and processing starts\u003C\u002Fli>\n\u003Cli>If you use  URL source for import, please ensure the URL is not password protected\u003C\u002Fli>\n\u003Cli>Supported formats: XML 1.0, XML 2.0, Atom 1, RSS\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>XML Preview\u003C\u002Fstrong> – After successfully uploading an XML file or reading an external URL, the plugin will present you with an XML preview of the selected node. This can be used to check if you’ve selected the correct node and ensure that the data are read correctly by the plugin. The preview presents one item from the selected node but it is paginated so you can navigate back and forward between the elements.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Linking Taxonomies to Posts\u003C\u002Fstrong> – You can import categories and taxonomies from the XML file and link the imported posts to these taxonomies. First you need to have the taxonomies created in WordPress to allow the plugin to import into these taxonomies. By default WordPress has two taxonomies: categories and tags.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Limit posts\u003C\u002Fstrong> – In the “Import Settings” area you can set limits for the import. You can use multiple patterns to include posts in the import. Use semicolon to separate the values, for example: 1-8;10;14-\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Importing and linking multiple taxonomies to one post\u003C\u002Fstrong> – To import and link one post to multiple taxonomies, you need to have an XML element in your selected node with a list of categories separated by commas. These elements will be recognized and imported separately as taxonomy terms.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Save & Load templates\u003C\u002Fstrong> – Once the fields are matched, you can save the matching as a template, and use it again for another import.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Support for tag attributes\u003C\u002Fstrong>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Custom Fields & ACF support\u003C\u002Fstrong>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Demo Video\u003C\u002Fh3>\n\u003Cdiv class=\"embed-vimeo\" style=\"text-align: center;\">\u003Ciframe loading=\"lazy\" src=\"https:\u002F\u002Fplayer.vimeo.com\u002Fvideo\u002F305452075\" width=\"750\" height=\"422\" frameborder=\"0\" webkitallowfullscreen mozallowfullscreen allowfullscreen>\u003C\u002Fiframe>\u003C\u002Fdiv>\n\u003Ch3>Testimonials\u003C\u002Fh3>\n\u003Cp>★★★★★\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>“Excelent” – \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fexcelent-995\u002F\" rel=\"ugc\">mediadocena\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>★★★★★\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>“Works as expected, smooth process” – \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fworks-as-expected-smooth-process\u002F\" rel=\"ugc\">Sunfire\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>★★★★★\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>“Excellent! Finally a plugin that does exactly what I need” – \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fexcellent-finally-a-plugin-that-does-exactly-what-i-need\u002F\" rel=\"ugc\">golfinsa\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n","Import content from any XML or RSS file or URL. Very useful for importing content from Wix websites.",2000,123524,76,24,"2026-05-26T05:43:00.000Z","7.0.2","4.5","5.6",[53,18,20,54,55],"feed","rss","xml","http:\u002F\u002Fwww.mooveagency.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fimport-xml-feed.2.1.6.zip",95,"2024-04-05 00:00:00",{"slug":61,"name":62,"version":63,"author":64,"author_profile":65,"description":66,"short_description":67,"active_installs":68,"downloaded":69,"rating":31,"num_ratings":70,"last_updated":71,"tested_up_to":49,"requires_at_least":72,"requires_php":73,"tags":74,"homepage":78,"download_link":79,"security_score":31,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"blocks-export-import","Blocks Export Import – Backup & Move Gutenberg Blocks as JSON","1.2.0","Hardeep Asrani","https:\u002F\u002Fprofiles.wordpress.org\u002Fhardeepasrani\u002F","\u003Cp>Blocks Export Import plugin allows you to import and export blocks as JSON in Gutenberg Block Editor.\u003C\u002Fp>\n\u003Cp>All the code and sources for this plugin are publicly available as part of https:\u002F\u002Fgithub.com\u002FCodeinwp\u002Fotter-blocks.\u003C\u002Fp>\n","Export and import Gutenberg blocks as JSON files. Backup block layouts, move them between sites, or share them with your team — all without plugins.",1000,16829,1,"2026-07-22T07:05:00.000Z","6.6","5.4",[75,76,77,18,20],"blocks","export","gutenberg","https:\u002F\u002Fgithub.com\u002FCodeinwp\u002Fotter-blocks","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fblocks-export-import.3.2.1.zip",{"slug":81,"name":82,"version":83,"author":84,"author_profile":85,"description":86,"short_description":87,"active_installs":88,"downloaded":89,"rating":11,"num_ratings":11,"last_updated":90,"tested_up_to":91,"requires_at_least":92,"requires_php":93,"tags":94,"homepage":98,"download_link":99,"security_score":100,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"bulk-post-importer","Bulk Post Importer","1.0.3","Chris Wahlfeldt","https:\u002F\u002Fprofiles.wordpress.org\u002Fwafflewolf\u002F","\u003Cp>Import large amounts of content into WordPress from JSON or CSV files. Perfect for migrating from other platforms, importing API data, or bulk-creating content with a user-friendly mapping interface.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Dual Format Support\u003C\u002Fstrong>: Import from JSON or CSV files\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Intelligent Field Mapping\u003C\u002Fstrong>: Visual interface for mapping data fields to WordPress fields\u003C\u002Fli>\n\u003Cli>\u003Cstrong>ACF Integration\u003C\u002Fstrong>: Full support for Advanced Custom Fields with automatic detection\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gutenberg Ready\u003C\u002Fstrong>: Automatically converts text content to Gutenberg paragraph blocks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Meta Fields\u003C\u002Fstrong>: Support for WordPress post meta fields\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure Processing\u003C\u002Fstrong>: Built-in security checks and data validation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Error Handling\u003C\u002Fstrong>: Comprehensive error reporting and import logging\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Supported File Formats\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>JSON Format\u003C\u002Fstrong>: Array of objects\u003Cbr \u002F>\n    [\u003Cbr \u002F>\n      {\u003Cbr \u002F>\n        “title”: “Post Title”,\u003Cbr \u002F>\n        “content”: “Post content”,\u003Cbr \u002F>\n        “custom_field”: “value”\u003Cbr \u002F>\n      }\u003Cbr \u002F>\n    ]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>CSV Format\u003C\u002Fstrong>: Headers in first row, data in subsequent rows\u003Cbr \u002F>\n    title,content,custom_field\u003Cbr \u002F>\n    “Post Title”,”Post content”,”value”\u003Cbr \u002F>\n    “Another Post”,”More content”,”another value”\u003C\u002Fp>\n\u003Ch4>Requirements\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress 5.0+\u003C\u002Fli>\n\u003Cli>PHP 7.4+\u003C\u002Fli>\n\u003Cli>Administrator privileges\u003C\u002Fli>\n\u003Cli>Optional: Advanced Custom Fields plugin for ACF support\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Ch4>3-Step Process\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>Upload\u003C\u002Fstrong>: Go to \u003Cstrong>Tools > Bulk Post Importer\u003C\u002Fstrong>, select your JSON\u002FCSV file and target post type\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Map Fields\u003C\u002Fstrong>: Use the visual interface to map your data fields to WordPress fields\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Import\u003C\u002Fstrong>: Review and process the import with detailed progress reporting\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Field Mapping Options\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Standard Fields\u003C\u002Fstrong>: Title, content, excerpt, status, date\u003C\u002Fli>\n\u003Cli>\u003Cstrong>ACF Fields\u003C\u002Fstrong>: Automatically detected if ACF plugin is active\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Meta\u003C\u002Fstrong>: WordPress post meta fields\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>This plugin processes files locally on your server. No data is transmitted externally. Uploaded files are processed and removed from temporary storage.\u003C\u002Fp>\n","Import posts and custom post types from JSON and CSV files with intelligent field mapping for WordPress fields, ACF, and custom meta.",700,1340,"2025-07-17T15:25:00.000Z","6.8.6","5.0","7.4",[95,96,18,20,97],"bulk","csv","posts","https:\u002F\u002Fgithub.com\u002Fcwahlfeldt\u002Fbulk-post-importer","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbulk-post-importer.1.0.3.zip",92,{"slug":102,"name":103,"version":104,"author":105,"author_profile":106,"description":107,"short_description":108,"active_installs":109,"downloaded":110,"rating":31,"num_ratings":70,"last_updated":111,"tested_up_to":49,"requires_at_least":112,"requires_php":113,"tags":114,"homepage":16,"download_link":120,"security_score":31,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"api-press","API Press – External API data, Connect API, Import API","2.0.2","Quicksnail Plugins","https:\u002F\u002Fprofiles.wordpress.org\u002Fquicksnail\u002F","\u003Cp>API Press is a no-code WordPress plugin that connects external APIs to your site without touching any code.\u003C\u002Fp>\n\u003Cp>You can set up and manage unlimited API connections right from your WordPress admin dashboard. Easily define your API endpoint and add your query parameters, headers, body data and login settings.\u003C\u002Fp>\n\u003Ch3>Three Simple Workflows\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Send\u003C\u002Fstrong> – Push API requests on demand or use automatic triggers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Display\u003C\u002Fstrong> – Show API data on your site using simple shortcodes or template tags.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Import\u003C\u002Fstrong> – Pull API data directly into WordPress to create or update your posts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>If you have ever used Postman, API Press will feel very familiar. It is a low-code tool built specifically to connect your site to JSON APIs.\u003C\u002Fp>\n\u003Ch3>External API Plugin Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Works with all REST APIs (GET, POST, PUT, PATCH, and DELETE)\u003C\u002Fli>\n\u003Cli>Query parameters, headers and body data\u003C\u002Fli>\n\u003Cli>Saves resources with API caching and logs all requests\u003C\u002Fli>\n\u003Cli>Handles multiple data types like raw JSON, form-data, and x-www-form-urlencoded\u003C\u002Fli>\n\u003Cli>Lets you preview live responses inside your admin panel\u003C\u002Fli>\n\u003Cli>Shortcode or template tag to output API data anywhere on your site\u003C\u002Fli>\n\u003Cli>Built-in auth: API Keys, Bearer tokens, and Basic Auth\u003C\u002Fli>\n\u003Cli>No code\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>API Press PRO Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Smart Triggers:\u003C\u002Fstrong> Use advanced automation and dynamic variables.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Visual Displays:\u003C\u002Fstrong> Use pre-built layouts like Galleries, Tables, and Carousels.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Deep Mapping:\u003C\u002Fstrong> Get extended import options and automated scheduling.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure Access:\u003C\u002Fstrong> Full OAuth 2.0 Authorization support.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Instant Alerts:\u003C\u002Fstrong> Receive email notifications if a response fails.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer Tools:\u003C\u002Fstrong> One-click API cloning, log retention, and CSV exports.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>View the \u003Ca href=\"https:\u002F\u002Fapi-press.com\u002Fdownloads\u002Fpro-plugin\u002F\" rel=\"nofollow ugc\">API Press PRO\u003C\u002Fa> plugin.\u003C\u002Fp>\n\u003Cp>API Press is an easy to use WordPress API integration plugin. It is ideal for developers, site builders and businesses that need a flexible, no-code way to connect APIs inside WordPress.\u003C\u002Fp>\n\u003Ch3>WordPress API plugin\u003C\u002Fh3>\n\u003Cp>API Press is perfect for developers, site builders, and businesses who want a fast, flexible, and code-free way to manage integrations. To get started, just install the plugin, head to your admin panel, paste your API URL, and click Test.\u003C\u002Fp>\n","Connect APIs to WordPress. Send data to API, display external API data with shortcode, or import API data and create posts.",40,1731,"2026-06-25T09:14:00.000Z","5.9","7.0",[115,116,117,118,119],"connect-api","endpoint","external-api","import-api","json-api","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fapi-press.2.0.2.zip",{"slug":122,"name":123,"version":6,"author":124,"author_profile":125,"description":126,"short_description":127,"active_installs":11,"downloaded":128,"rating":11,"num_ratings":11,"last_updated":129,"tested_up_to":130,"requires_at_least":131,"requires_php":16,"tags":132,"homepage":16,"download_link":138,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"display-realtime-json-data-through-ajax","Display Real Time JSON data with Auto update","Mahesh Bisen","https:\u002F\u002Fprofiles.wordpress.org\u002Fmaheshbisen\u002F","\u003Ch4>Overview\u003C\u002Fh4>\n\u003Cp>Display real time JSON data on Page\u002FPost using simple ShortCode. It can be used for displaying real time event, data from third party site or application.\u003Cbr \u002F>\nVery user friendly, easy to use and can easily work with nested JSON data as well. You can set auto refresh time to display actual real time data. It can be used to display current song playing on any channel, for displaying real time pricing of any third party portal, real time event price etc.\u003C\u002Fp>\n\u003Ch4>Display Real Time JSON data with Auto update Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Display real time JSON data in preformatted HTML using format string.\u003C\u002Fli>\n\u003Cli>Able to render nested JSON data in simple way.\u003C\u002Fli>\n\u003Cli>Refresh data through AJAX in specified interval.\u003C\u002Fli>\n\u003C\u002Ful>\n","Display real time JSON data on Page\u002FPost using simple ShortCode. It can be used for displaying real time event, data from third party site or applicat &hellip;",1447,"2018-05-23T05:37:00.000Z","4.9.29","3.0",[133,134,135,136,137],"display-real-time-event-information","display-real-time-feed","json-data","show-json-data-with-html-formatting","third-party-json-data","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdisplay-realtime-json-data-through-ajax.zip",{"attackSurface":140,"codeSignals":178,"taintFlows":188,"riskAssessment":189,"analyzedAt":201},{"hooks":141,"ajaxHandlers":159,"restRoutes":160,"shortcodes":161,"cronEvents":177,"entryPointCount":167,"unprotectedCount":11},[142,148,152,156],{"type":143,"name":144,"callback":145,"file":146,"line":147},"action","spmc_language","spmc_sprache","spmc-main.php",18,{"type":143,"name":149,"callback":150,"file":146,"line":151},"admin_menu","spmc_adminmenu",19,{"type":143,"name":153,"callback":154,"file":146,"line":155},"admin_init","spmc_settings",34,{"type":143,"name":157,"callback":157,"file":146,"line":158},"spmc_default_values",73,[],[],[162,165,168,171,174],{"tag":163,"callback":163,"file":164,"line":30},"spmcauthor","spmc-shortcodes.php",{"tag":166,"callback":166,"file":164,"line":167},"spmcversion",5,{"tag":169,"callback":169,"file":164,"line":170},"spmcupdatetitle",6,{"tag":172,"callback":172,"file":164,"line":173},"spmcplugindownloads",7,{"tag":175,"callback":175,"file":164,"line":176},"spmcpluginprice",8,[],{"dangerousFunctions":179,"sqlUsage":180,"outputEscaping":182,"fileOperations":11,"externalRequests":167,"nonceChecks":11,"capabilityChecks":11,"bundledLibraries":187},[],{"prepared":11,"raw":11,"locations":181},[],{"escaped":11,"rawEcho":70,"locations":183},[184],{"file":146,"line":185,"context":186},51,"raw output",[],[],{"summary":190,"deductions":191},"The \"informationsabfrage-spigotmc\" plugin v1.0 demonstrates several good security practices in its static analysis. Notably, it avoids dangerous functions, exclusively uses prepared statements for SQL queries, and has no recorded vulnerability history, indicating a potentially stable and secure codebase. The absence of critical or high severity taint flows and a clean vulnerability record are positive signs. However, significant concerns arise from the lack of output escaping and the complete absence of capability and nonce checks. While the attack surface is primarily through shortcodes, the lack of any authorization checks on these entry points is a critical oversight. This means that any user, regardless of their role or permissions, could potentially trigger the plugin's functionality. The presence of external HTTP requests without apparent validation also poses a risk if not handled securely. The plugin's overall security posture is a mix of strong foundational practices (SQL, no known vulnerabilities) and critical weaknesses (output escaping, authorization).\n\nGiven the identified weaknesses, particularly the lack of authorization and output escaping on shortcode entry points, there is a considerable risk of unauthorized actions and potential cross-site scripting (XSS) vulnerabilities. The static analysis indicates that the 5 shortcodes are the primary entry points and none have capability checks. This means that potentially sensitive information could be exposed or actions could be performed by unauthenticated users. The external HTTP requests also represent a potential attack vector if they lead to the execution of unsanitized data or if the plugin is susceptible to SSRF attacks. The vulnerability history being clean is a good sign, but it does not mitigate the risks identified in the current codebase. The plugin needs immediate attention to implement proper authorization and output escaping to secure its entry points.",[192,195,197,199],{"reason":193,"points":194},"Missing capability checks on entry points",15,{"reason":196,"points":170},"Unescaped output",{"reason":198,"points":167},"External HTTP requests without apparent checks",{"reason":200,"points":167},"Missing nonce checks on shortcodes","2026-03-17T06:13:06.588Z",{"wat":203,"direct":208},{"assetPaths":204,"generatorPatterns":205,"scriptPaths":206,"versionParams":207},[],[],[],[],{"cssClasses":209,"htmlComments":211,"htmlAttributes":212,"restEndpoints":215,"jsGlobals":216,"shortcodeOutput":217},[210],"form_text",[],[213,214],"id=\"spmc-daten\"","name=\"spmc_id\"",[],[],[218,219,220,221,222],"[spmcauthor]","[spmcversion]","[spmcupdatetitle]","[spmcplugindownloads]","[spmcpluginprice]",{"error":224,"url":225,"statusCode":226,"statusMessage":227,"message":227},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Finformationsabfrage-spigotmc\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":70,"versions":229},[230],{"version":6,"download_url":23,"svn_tag_url":231,"released_at":25,"has_diff":232,"diff_files_changed":233,"diff_lines":25,"trac_diff_url":25,"vulnerabilities":234,"is_current":224},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Finformationsabfrage-spigotmc\u002Ftags\u002F1.0\u002F",false,[],[]]