[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkJnVaFJWHrIZff9xYaDnhCUgkZs3XfZtdEyi1vwc8DU":3,"$fQ6nw7OCvcCgNEiZShHEgFM5aL7O3eOPuMlDnkpNVGIc":139,"$f9vFkMUbUJ3H0of83D7vvF9WvUMzeJsRnxTZZNK9po40":143},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":23,"download_link":24,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":38,"analysis":39,"fingerprints":113},"iwsm-customize-background-images","Clickable Background Image","1.0","georget777","https:\u002F\u002Fprofiles.wordpress.org\u002Fgeorget777\u002F","\u003Cp>A great way to monetize your blog by adding an advertisement in the background.\u003C\u002Fp>\n\u003Cp>The plugin allows you to add a clickable background to any narrow or boxed WordPress theme. You have the option to select what image goes to the left, what image goes to the right and their links.\u003C\u002Fp>\n\u003Cp>You can also adjust the image margin, height and z-index.\u003C\u002Fp>\n\u003Cp>There is also an option to make the image sticky.\u003C\u002Fp>\n","Adds a clickable background to a wordpress blog",10,1241,100,1,"2019-10-16T12:05:00.000Z","5.2.24","4.0","5.6",[20,21,22],"advertisement-background","blog-background","clickable-background","http:\u002F\u002Fco.soft-master.eu\u002F2018\u002F05\u002F25\u002Fcustomize-background-images-wordpress-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fiwsm-customize-background-images.zip",85,0,null,"2026-04-06T09:54:40.288Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":33,"avg_security_score":34,"avg_patch_time_days":35,"trust_score":36,"computed_at":37},2,310,93,30,89,"2026-08-29T02:55:55.626Z",[],{"attackSurface":40,"codeSignals":64,"taintFlows":100,"riskAssessment":101,"analyzedAt":112},{"hooks":41,"ajaxHandlers":60,"restRoutes":61,"shortcodes":62,"cronEvents":63,"entryPointCount":26,"unprotectedCount":26},[42,48,52,56],{"type":43,"name":44,"callback":45,"priority":13,"file":46,"line":47},"action","wp_head","iwsm_manage_bg_images","iwsm-bg-images.php",404,{"type":43,"name":49,"callback":50,"file":46,"line":51},"after_setup_theme","iwsm_add_cb_support",464,{"type":43,"name":53,"callback":54,"file":46,"line":55},"admin_menu","iwsm_bckgrd_img_add_admin_menu",832,{"type":43,"name":57,"callback":58,"file":46,"line":59},"admin_init","iwsm_bckgrd_img_options_init",833,[],[],[],[],{"dangerousFunctions":65,"sqlUsage":66,"outputEscaping":68,"fileOperations":26,"externalRequests":26,"nonceChecks":26,"capabilityChecks":26,"bundledLibraries":99},[],{"prepared":26,"raw":26,"locations":67},[],{"escaped":26,"rawEcho":69,"locations":70},17,[71,74,76,77,79,80,82,83,85,86,88,89,91,92,94,95,97],{"file":46,"line":72,"context":73},396,"raw output",{"file":46,"line":75,"context":73},661,{"file":46,"line":75,"context":73},{"file":46,"line":78,"context":73},670,{"file":46,"line":78,"context":73},{"file":46,"line":81,"context":73},684,{"file":46,"line":81,"context":73},{"file":46,"line":84,"context":73},697,{"file":46,"line":84,"context":73},{"file":46,"line":87,"context":73},710,{"file":46,"line":87,"context":73},{"file":46,"line":90,"context":73},742,{"file":46,"line":90,"context":73},{"file":46,"line":93,"context":73},751,{"file":46,"line":93,"context":73},{"file":46,"line":96,"context":73},774,{"file":46,"line":98,"context":73},806,[],[],{"summary":102,"deductions":103},"The \"iwsm-customize-background-images\" plugin v1.0 exhibits a concerning security posture primarily due to a complete lack of output escaping. While the static analysis shows no immediately exploitable entry points like unprotected AJAX handlers, REST API routes, or shortcodes, and no dangerous functions or file operations are present, the absence of output escaping is a significant weakness. This means that any data displayed to users could potentially be rendered in an unsafe manner, opening the door for cross-site scripting (XSS) attacks.  The plugin also lacks nonce and capability checks, which are fundamental security measures for preventing unauthorized actions and CSRF attacks, even if no direct entry points were identified in this analysis. The vulnerability history is clean, which is a positive sign, but this can be misleading if the plugin has not been extensively tested or if the identified weaknesses have simply not been exploited yet. In conclusion, while the plugin avoids common pitfalls like raw SQL or known vulnerabilities, the severe deficiency in output escaping presents a high risk of XSS vulnerabilities. Further, the absence of critical security checks like nonces and capability checks indicates a fundamental lack of secure coding practices, making it susceptible to other attacks if any entry points are ever introduced or discovered.",[104,107,110],{"reason":105,"points":106},"0% output escaping",16,{"reason":108,"points":109},"0 Nonce checks",5,{"reason":111,"points":109},"0 Capability checks","2026-03-17T00:24:57.117Z",{"wat":114,"direct":123},{"assetPaths":115,"generatorPatterns":118,"scriptPaths":119,"versionParams":120},[116,117],"\u002Fwp-content\u002Fplugins\u002Fiwsm-customize-background-images\u002Fstyle.css","\u002Fwp-content\u002Fplugins\u002Fiwsm-customize-background-images\u002Fjs\u002Fadmin.js",[],[117],[121,122],"iwsm-customize-background-images\u002Fstyle.css?ver=","iwsm-customize-background-images\u002Fjs\u002Fadmin.js?ver=",{"cssClasses":124,"htmlComments":126,"htmlAttributes":127,"restEndpoints":136,"jsGlobals":137,"shortcodeOutput":138},[125],"smcolumn",[],[128,129,130,131,132,133,134,135],"id=\"iwsm-bg\"","id=\"iwsm-bgimgl\"","id=\"iwsm-bgimgr\"","id=\"iwsm-bglinkl\"","id=\"iwsm-bglinkr\"","id=\"iwsm-content\"","id=\"custom-background-css-override\"","id=\"mylink\"",[],[],[],{"error":140,"url":141,"statusCode":47,"statusMessage":142,"message":142},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fiwsm-customize-background-images\u002Fbundle","no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":26,"versions":144},[]]