[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fB5hYaOddCHCTNUv1u0gFCe8JeY_ByeqLCPxQeO8yCzY":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":14,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27,"vulnerabilities":28,"developer":29,"crawl_stats":26,"alternatives":34,"analysis":60,"fingerprints":106},"localizaciones-fotografia","Localizaciones Fotografía","0.1","subexpuestaweb","https:\u002F\u002Fprofiles.wordpress.org\u002Fsubexpuestaweb\u002F","\u003Cp>Inserta en tu web de una manera rápida y sencilla un mapa con todas aquellas localizaciones de fotografía nocturna que tengas alojadas en www.subexpuesta.com\u003C\u002Fp>\n","Inserta en tu web un mapa todas las localizaciones que tengas subidas en www.subexpuesta.com",10,1863,0,"","4.2.39","3.0.1",[18,19,20,21,22],"fotografia","localizaciones","mapa","mapa-con-localizaciones","subexpuesta","http:\u002F\u002Fwww.subexpuesta.com\u002Fplugin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flocalizaciones-fotografia.zip",100,null,"2026-03-15T10:48:56.248Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":30,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":31,"trust_score":32,"computed_at":33},1,30,94,"2026-04-04T15:15:24.182Z",[35],{"slug":36,"name":37,"version":38,"author":39,"author_profile":40,"description":41,"short_description":42,"active_installs":43,"downloaded":44,"rating":25,"num_ratings":45,"last_updated":46,"tested_up_to":47,"requires_at_least":48,"requires_php":49,"tags":50,"homepage":54,"download_link":55,"security_score":56,"vuln_count":57,"unpatched_count":13,"last_vuln_date":58,"fetched_at":59},"wp-mapa-politico-spain","WP Mapa Politico España","3.8.1","Juan Carlos","https:\u002F\u002Fprofiles.wordpress.org\u002Fjcglp\u002F","\u003Cp>Este plugin permite insertar un mapa político de España en post o páginas.\u003C\u002Fp>\n\u003Cp>En la página del plugin se pueden definir los titles e hipervínculos de cada una de las provincias.\u003C\u002Fp>\n","Inserta una imagen de un mapa político de España, con áreas definidas sobre las provincias sobre las que se pueden definir hipervínculos.",400,16550,26,"2025-05-07T06:30:00.000Z","6.8.5","4.6","5.2.4",[51,52,20,53],"comunidades","espana","provincias","https:\u002F\u002Fpisanowp.com\u002Fmapa-de-provincias\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-mapa-politico-spain.zip",98,2,"2025-05-19 00:00:00","2026-03-15T15:16:48.613Z",{"attackSurface":61,"codeSignals":73,"taintFlows":95,"riskAssessment":96,"analyzedAt":105},{"hooks":62,"ajaxHandlers":69,"restRoutes":70,"shortcodes":71,"cronEvents":72,"entryPointCount":13,"unprotectedCount":13},[63],{"type":64,"name":65,"callback":66,"file":67,"line":68},"action","admin_init","settings","localizaciones-fotografia.php",154,[],[],[],[],{"dangerousFunctions":74,"sqlUsage":75,"outputEscaping":77,"fileOperations":30,"externalRequests":93,"nonceChecks":13,"capabilityChecks":13,"bundledLibraries":94},[],{"prepared":13,"raw":13,"locations":76},[],{"escaped":78,"rawEcho":79,"locations":80},22,5,[81,85,87,89,91],{"file":82,"line":83,"context":84},"class.MapBuilder.php",1145,"raw output",{"file":67,"line":86,"context":84},136,{"file":67,"line":88,"context":84},137,{"file":67,"line":90,"context":84},138,{"file":67,"line":92,"context":84},264,3,[],[],{"summary":97,"deductions":98},"The \"localizaciones-fotografia\" plugin version 0.1 exhibits a strong security posture in several key areas, particularly concerning the absence of known vulnerabilities and a complete lack of critical or high-severity taint flows. The static analysis indicates a disciplined approach to SQL queries, with 100% using prepared statements, which is a significant strength against injection attacks. Additionally, the plugin has a relatively low number of external HTTP requests and file operations, minimizing potential attack vectors.\n\nHowever, several concerning aspects warrant attention. The complete absence of nonce checks and capability checks on any identified entry points, despite the presence of file operations and external HTTP requests, creates a significant risk. Any of these operations, if triggered maliciously without proper authorization, could lead to unintended consequences. While the output escaping rate is high (81%), the remaining unescaped outputs could still be a vector for cross-site scripting (XSS) vulnerabilities, especially if they handle user-supplied data.\n\nThe plugin's vulnerability history being entirely clear is a positive indicator, suggesting either a history of secure development or a lack of historical scrutiny. Given the current static analysis findings, especially the lack of authorization checks, this positive history might be more a reflection of its limited exposure or attack surface rather than inherent robustness against all potential threats. The focus should be on addressing the identified weaknesses in authorization and output sanitization to strengthen its overall security.",[99,101,103],{"reason":100,"points":11},"No nonce checks on entry points",{"reason":102,"points":11},"No capability checks on entry points",{"reason":104,"points":93},"Unescaped output found","2026-03-16T23:29:36.175Z",{"wat":107,"direct":113},{"assetPaths":108,"generatorPatterns":110,"scriptPaths":111,"versionParams":112},[109],"\u002Fwp-content\u002Fplugins\u002Flocalizaciones-fotografia\u002Fclass.MapBuilder.php",[],[],[],{"cssClasses":114,"htmlComments":116,"htmlAttributes":117,"restEndpoints":120,"jsGlobals":123,"shortcodeOutput":125},[115],"firstHeading",[],[118,119],"data-plugin-name=\"Subexpuesta\"","data-plugin-version=\"0.1\"",[121,122],"\u002Fwp-json\u002Fsubexpuesta\u002Fv1\u002Flocalizaciones\u002F","\u002Fwp-json\u002Fsubexpuesta\u002Fv1\u002Flocalizaciones\u002Fautor\u002F",[124],"Subexpuesta",[126,127,128,129,130,131,132,133,131,134,135,136,128,137,138,128,139,140,141,142,143,144,144],"\u003Cp>pruebaParametros\u003C\u002Fp>","\u003Cp>height:","\u003C\u002Fp>","\u003Cp>width:","\u003Cp>pruebaParametros Option:","\u003Cdiv>","\u003Cp>\u003Cstrong id=\"firstHeading\" class=\"firstHeading\">","\u003C\u002Fstrong>\u003C\u002Fp>","\u003Cdiv style=\"float:left;\">\u003Cp>\u003Ca href=\"http:\u002F\u002Fres.cloudinary.com\u002Fdjhqderty\u002Fimage\u002Fupload\u002Fv1438939574\u002F","\" target=\"_blank\">\u003Cimg align=\"left\" style=\"margin-right: 15px;\" src=\"http:\u002F\u002Fres.cloudinary.com\u002Fdjhqderty\u002Fimage\u002Fupload\u002Fc_thumb,h_80,w_160\u002Fv1438939574\u002F","\" \u002F>\u003C\u002Fa>\u003C\u002Fdiv>","\u003Cdiv style=\"float:left; margin-top:15px;\">\u003Cp style=\"margin: 0px;\">\u003Cstrong>Latitud:\u003C\u002Fstrong>"," \u003Cstrong>Longitud:\u003C\u002Fstrong>","\u003Cp>\u003Cstrong>Peligrosidad de la zona:\u003C\u002Fstrong>","\u002F10   \u003Cstrong>Contaminación lumnínica:\u003C\u002Fstrong>","\u002F10\u003C\u002Fp>","\u003Ca href=\"http:\u002F\u002Fres.cloudinary.com\u002Fdjhqderty\u002Fimage\u002Fupload\u002Fv1438939574\u002F","\" target=\"_blank\">Ver en grande\u003C\u002Fa>\u003C\u002Fdiv>","\u003C\u002Fdiv>"]