[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCfaH7bkWWWXVfHwgzH-coTsBxG0jp7TV9sHZln07zHI":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"vulnerabilities":31,"developer":32,"crawl_stats":29,"alternatives":37,"analysis":144,"fingerprints":204},"mixpanel-integration","MixPanel","1.5.1","jittarao","https:\u002F\u002Fprofiles.wordpress.org\u002Fjittarao\u002F","\u003Cp>This plugin adds a meta box to the bottom of every page, which will allow you to mark the event of the page landing in MixPanel accordingly.\u003Cbr \u002F>\nYou no longer need to add the mixpanel.track() javascript snippet in your theme files.\u003C\u002Fp>\n\u003Cp>Updated to Version 1.5.1\u003Cbr \u002F>\n– Tracking code updated to latest version.\u003Cbr \u002F>\n– Now you can custom label posts too.\u003Cbr \u002F>\n– Event tracking code has been moved to wp_footer.php for speed improvements.\u003C\u002Fp>\n","This is a plugin that allows you to get MixPanel analytics up and running on WordPress very easily.",100,14336,52,5,"2015-03-27T14:50:00.000Z","4.1.42","3.3","",[20,21,22,23,24],"analytics","funnels","kissmetrics","metrics","mixpanel","https:\u002F\u002Fgithub.com\u002Fjittarao","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmixpanel-integration.1.5.1.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":27,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},1,30,84,"2026-04-04T19:05:02.157Z",[38,59,79,99,122],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":48,"num_ratings":49,"last_updated":50,"tested_up_to":51,"requires_at_least":52,"requires_php":18,"tags":53,"homepage":57,"download_link":58,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"segmentio","Analytics for WordPress — by Segment","1.0.13","Segment","https:\u002F\u002Fprofiles.wordpress.org\u002Fsegmentio\u002F","\u003Cp>Analytics for WordPress is the easiest way to integrate analytics and marketing tools into your WordPress site.\u003C\u002Fp>\n\u003Cp>Instead of installing each tool individually, just install Segment’s WordPress plugin and use Segment to integrate third-party analytics and marketing tools.   Once you’re setup, you can swap and add new analytics services with the flick of a switch!\u003C\u002Fp>\n\u003Cp>Here’s how it works:\u003Cbr \u002F>\n* Install the Segment plugin\u003Cbr \u002F>\n* Segment will automatically start tracking how people are using your site – what pages they view and the information they provide to you, like their emails\u003Cbr \u002F>\n* Go to the Segment control panel, and toggle on any tool you want to try like Google Analytics, KISSmetrics and Facebook Audiences\u003Cbr \u002F>\n* Segment will send this data along to each tool\u003Cbr \u002F>\n* The service is fully integrated into your site–zero code required!\u003C\u002Fp>\n\u003Cp>You can use Segment to try out more than a hundred vendors in a number of categories. Here are just a few of our most popular integrations:\u003Cbr \u002F>\n* \u003Cstrong>Advertising\u003C\u002Fstrong> – AdRoll, Google Adwords, Facebook Audiences, Twitter Ads, Quantcast, AppNexus\u003Cbr \u002F>\n* \u003Cstrong>Analytics\u003C\u002Fstrong> – Google Analytics, KISSmetrics, Mixpanel, Amplitude, Chartbeat, Go Squared\u003Cbr \u002F>\n* \u003Cstrong>CRM\u003C\u002Fstrong> – Salesforce, Zendesk, Gainsight, Frontleaf\u003Cbr \u002F>\n* \u003Cstrong>Email\u003C\u002Fstrong> – Customer.io, Outbound, Vero, Marketo, MailChimp, Hubspot\u003Cbr \u002F>\n* \u003Cstrong>Optimization\u003C\u002Fstrong> – Optimizely, CrazyEgg, Visual Website Optimizer\u003C\u002Fp>\n\u003Cp>Get started with Analytics for WordPress today!\u003C\u002Fp>\n","Analytics for WordPress lets you integrate more than 100 analytics and marketing tools with the flick of a switch.",400,46456,86,6,"2016-02-22T23:54:00.000Z","4.0.38","3.6",[20,54,22,55,56],"google-analytics","segment-io","web-analytics","https:\u002F\u002Fsegment.io\u002Fplugins\u002Fwordpress","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsegmentio.1.0.13.zip",{"slug":60,"name":61,"version":62,"author":63,"author_profile":64,"description":65,"short_description":66,"active_installs":67,"downloaded":68,"rating":28,"num_ratings":28,"last_updated":69,"tested_up_to":70,"requires_at_least":71,"requires_php":72,"tags":73,"homepage":77,"download_link":78,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"quick-analytics","Quick Analytics","1.0.0","Thibault Crouzet","https:\u002F\u002Fprofiles.wordpress.org\u002Fthibaultcrouzet\u002F","\u003Cp>This plugin allows you adding the analytics tracking for: Google Analytics, Yandex Metrika, Mixpanel, Kissmetrics, Woopra, Heap, GoSquared, Statcounter.\u003Cbr \u002F>\nMore will be added later.\u003C\u002Fp>\n","A simple plugin that helps you to integrate quickly your analytics tracking IDs.",10,1119,"2018-09-29T10:24:00.000Z","4.9.29","3.0","5.6",[74,22,24,75,76],"google","woopra","yandex-metrika","http:\u002F\u002Fthibaultcrouzet.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fquick-analytics.zip",{"slug":80,"name":81,"version":82,"author":83,"author_profile":84,"description":85,"short_description":86,"active_installs":87,"downloaded":88,"rating":89,"num_ratings":90,"last_updated":91,"tested_up_to":92,"requires_at_least":52,"requires_php":18,"tags":93,"homepage":96,"download_link":97,"security_score":11,"vuln_count":33,"unpatched_count":28,"last_vuln_date":98,"fetched_at":30},"metricool","Metricool","1.26","juan.pablo.tejela","https:\u002F\u002Fprofiles.wordpress.org\u002Fjuanpablotejela\u002F","\u003Cp>This plugin allows you to connect your blog or web based on WordPress with Metricool. Metricool is a tool that provides metrics and analytics about your blog and your social profiles. Using Metricool you can schedule your tweets or your posts in Facebook.\u003C\u002Fp>\n\u003Cp>This plugin installs a Javascript tracking code in the footer of your public pages. This code registers the pages viewed by your visitors in Metricool. If you want to interrupt the conexion between your blog and Metricool, you can disable the plugin or remove the Metricool identifier configured in the plugin settings window.\u003C\u002Fp>\n\u003Cp>To use this plugin it is required to be a registered user of Metricool (http:\u002F\u002Fmetricool.com\u002F).\u003C\u002Fp>\n\u003Cp>You can follow us on Twitter: http:\u002F\u002Ftwitter.com\u002Fmetricool\u002F\u003C\u002Fp>\n","Metricool is the first tool designed to measure #Blog impact and #SocialMedia activity.",80000,780312,78,7,"2026-02-02T15:17:00.000Z","6.9.4",[20,94,80,23,95],"blog","tracking","https:\u002F\u002Fmetricool.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmetricool.zip","2022-12-20 00:00:00",{"slug":75,"name":100,"version":101,"author":102,"author_profile":103,"description":104,"short_description":105,"active_installs":106,"downloaded":107,"rating":108,"num_ratings":49,"last_updated":109,"tested_up_to":110,"requires_at_least":111,"requires_php":112,"tags":113,"homepage":117,"download_link":118,"security_score":119,"vuln_count":120,"unpatched_count":28,"last_vuln_date":121,"fetched_at":30},"Woopra Analytics Plugin","3.3.2","eliekhoury","https:\u002F\u002Fprofiles.wordpress.org\u002Feliekhoury\u002F","\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.woopra.com\u002F\" rel=\"nofollow ugc\">Woopra\u003C\u002Fa> is an end-to-end Customer Journey Analytics solution built for teams. Unify your customer data within the platform to analyze, optimize and engage across every customer touchpoint. Among the features, you’ll find:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.woopra.com\u002Fintegrations\u002F\" rel=\"nofollow ugc\">AppConnect\u003C\u002Fa>: A suite of 40+ one-click integrations to seamlessly integrate data from your CRM, email, chat, social, support tools and more!\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.woopra.com\u002Fplatform\u002F#customer-profiles\" rel=\"nofollow ugc\">Customer Profiles\u003C\u002Fa>: As data syncs to Woopra from every touchpoint, Customer Profiles display a true to life view of user engagement, down to the individual-level. So whether you’re solving a support request or getting a pulse on customer health, you – and your team – will have clarity at your fingertips.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.woopra.com\u002Fanalytics\" rel=\"nofollow ugc\">Customer Analytics\u003C\u002Fa>: Whatever questions you have, there’s an analytics report waiting with answers. Full-funnel attribution, onboarding optimization, feature usage, retention reports, cohort analysis and so much more. Regardless of how you measure success, you’re covered.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.woopra.com\u002Fautomations\" rel=\"nofollow ugc\">Automations\u003C\u002Fa>: Powerful triggers packed into each native integrations. Send a message to users based on any engagement criteria, personalize a live chat when customers experience an issue or instantly update a lead status when a prospect calls. Open the door to personalization at scale! \u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Break free from the data siloes of mobile, app, product or web analytics. Combine them – and every other essential touchpoint – to see the world as your customers do with the Woopra platform.\u003C\u002Fp>\n","Track who is on your website, what pages they're browsing, actions they're taking, articles they're reading and more.",1000,215029,74,"2025-07-23T05:36:00.000Z","6.8.5","2.7.0","7.4",[20,21,114,115,116],"real-time","statistics","stats","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwoopra\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwoopra.3.3.2.zip",97,2,"2013-10-07 00:00:00",{"slug":123,"name":124,"version":125,"author":126,"author_profile":127,"description":128,"short_description":129,"active_installs":46,"downloaded":130,"rating":28,"num_ratings":28,"last_updated":131,"tested_up_to":110,"requires_at_least":132,"requires_php":133,"tags":134,"homepage":140,"download_link":141,"security_score":142,"vuln_count":33,"unpatched_count":28,"last_vuln_date":143,"fetched_at":30},"seo-metrics-helper","SEO Metrics","1.0.18","seometricsplugin","https:\u002F\u002Fprofiles.wordpress.org\u002Fseometricsplugin\u002F","\u003Cp>Connect your WordPress website to the SEO Metrics Dashboard and efficiently manage all SEO Metrics products and services.\u003C\u002Fp>\n\u003Cp>Discover the magical components the SEO Metrics platform offers through one unified dashboard!\u003C\u002Fp>\n\u003Ch4>Unified dashboard for all your WordPress websites\u003C\u002Fh4>\n\u003Cp>SEO Metrics offers a convenient and elegant way to the analytics for your WordPress website and provide one-click secure login to WP.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Update WordPress core to keep your websites secure and supporting the latest versions of all premium plugins and themes.\u003C\u002Fli>\n\u003Cli>Installing and managing your websites plugins & themes is not an everyday hassle anymore.\u003C\u002Fli>\n\u003Cli>Access all your WordPress websites from the dashboard with 1 click.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>SEO Metrics Helper asks for your consent when signing up and connecting your website to SEO Metrics services. \u003Ca href=\"https:\u002F\u002Fwww.seometrics.net\u002Fprivacy-policy\u002F\" rel=\"nofollow ugc\">Read our GDPR Compliant Privacy Policy\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Explanation of User Creation\u003C\u002Fh3>\n\u003Cp>The creation of a user within the context of the SEO Metrics plugin is aimed at enhancing user experience and security within the SEO Reporting Automation Software ecosystem. This feature was implemented in response to identified demand for passwordless login functionality.\u003C\u002Fp>\n\u003Cp>When a user initiates a connection with the SEO Metrics plugin through the WordPress dashboard, they are presented with a consent form. Upon agreement, a user account is created for them with the username ‘seo-metrics’ and the email ‘helper@seometrics.net’. The password is randomly generated using WordPress’s default \u003Ccode>wp_generate_password()\u003C\u002Fcode> function.\u003C\u002Fp>\n\u003Cp>The primary purpose of creating an administrative user is to streamline the login process for SEO Metrics users by eliminating the need for passwords. Additionally, it facilitates the provision of temporary, passwordless access to selected users or developers via the SEO Metrics Dashboard. This functionality empowers website owners to exercise precise control over access permissions, determining who can access the system and for how long. Ultimately, the objective is to enable SEO executives to efficiently perform website-related tasks within a specified timeframe, all while maintaining stringent security measures.\u003C\u002Fp>\n","Connect your WordPress website to the SEO Metrics Dashboard and efficiently manage all SEO Metrics products and services.",2760,"2025-09-16T04:47:00.000Z","4.7","7.0",[135,136,137,138,139],"analytics-seometrics","hosting","performance","seo","service","https:\u002F\u002Fwww.seometrics.net\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fseo-metrics-helper.zip",98,"2025-08-01 18:49:47",{"attackSurface":145,"codeSignals":175,"taintFlows":192,"riskAssessment":193,"analyzedAt":203},{"hooks":146,"ajaxHandlers":171,"restRoutes":172,"shortcodes":173,"cronEvents":174,"entryPointCount":28,"unprotectedCount":28},[147,152,156,160,164,168],{"type":148,"name":149,"callback":150,"file":151,"line":120},"action","admin_menu","mixpanel_create_meta_box","meta-box.php",{"type":148,"name":153,"callback":154,"file":151,"line":155},"save_post","mixpanel_update_event_label",3,{"type":148,"name":149,"callback":157,"file":158,"line":159},"add_settings_page","mixpanel.php",22,{"type":148,"name":161,"callback":162,"file":158,"line":163},"admin_init","mixpanel_init",23,{"type":148,"name":165,"callback":166,"file":167,"line":120},"wp_head","insert_tracker","page.php",{"type":148,"name":169,"callback":170,"file":167,"line":155},"wp_footer","insert_event",[],[],[],[],{"dangerousFunctions":176,"sqlUsage":177,"outputEscaping":179,"fileOperations":28,"externalRequests":28,"nonceChecks":28,"capabilityChecks":28,"bundledLibraries":191},[],{"prepared":28,"raw":28,"locations":178},[],{"escaped":120,"rawEcho":180,"locations":181},4,[182,185,187,189],{"file":151,"line":183,"context":184},19,"raw output",{"file":158,"line":186,"context":184},65,{"file":188,"line":180,"context":184},"mixpaneljs.php",{"file":167,"line":190,"context":184},40,[],[],{"summary":194,"deductions":195},"The mixpanel-integration plugin v1.5.1 exhibits a seemingly strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history is a significant positive indicator, suggesting a history of responsible development or a lack of past exploitation. The static analysis reveals a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, meaning there are no direct entry points for attackers. Furthermore, the code utilizes prepared statements for all its SQL queries and appears to have no file operations or external HTTP requests, all of which are excellent security practices.  However, a notable concern arises from the output escaping. With only 33% of outputs properly escaped, this presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through data displayed by the plugin, leading to session hijacking or other malicious actions. The lack of capability checks and nonce checks, combined with the unescaped output, creates a latent risk that could be exploited if any part of the plugin's functionality were to become an entry point in the future. While the current lack of attack surface is reassuring, the unescaped output is a critical weakness that needs immediate attention.",[196,199,201],{"reason":197,"points":198},"Low percentage of properly escaped output",8,{"reason":200,"points":14},"No capability checks",{"reason":202,"points":14},"No nonce checks","2026-03-16T20:52:03.480Z",{"wat":205,"direct":211},{"assetPaths":206,"generatorPatterns":208,"scriptPaths":209,"versionParams":210},[207],"\u002Fwp-content\u002Fplugins\u002Fmixpanel-integration\u002Fmixpaneljs.php",[],[],[],{"cssClasses":212,"htmlComments":214,"htmlAttributes":216,"restEndpoints":218,"jsGlobals":219,"shortcodeOutput":220},[213],"form_table",[215],"\u003C!-- No MixPanel Token Defined -->",[217],"for=\"mixpanel_event_label\"",[],[24,7],[]]