[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbSE016DOzZiI3ZVmNf_JSzws_iE6ZmW8H3yk0cP4suM":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":24,"download_link":25,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29,"vulnerabilities":30,"developer":31,"crawl_stats":28,"alternatives":37,"analysis":124,"fingerprints":232},"most-popular-posts","Most Popular Posts","1.6.2","wesg","https:\u002F\u002Fprofiles.wordpress.org\u002Fwesg\u002F","\u003Cp>Most Popular Posts is a basic widget for your sidebar that creates a list of links to the top posts on your blog according to the number of comments on the post. You can customize many aspects of the plugin to fit in your blog.\u003C\u002Fp>\n\u003Cp>Updates include including and excluding categories, reverse the order of comments and incorporation of WordPress widget standards.\u003C\u002Fp>\n\u003Cp>For a complete list of the changes from each version, please visit \u003Ca href=\"http:\u002F\u002Fwww.wesg.ca\u002F2008\u002F08\u002Fwordpress-widget-most-popular\u002F#changelog\" rel=\"nofollow ugc\">the plugin homepage\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>For examples and tips on using the plugin, please check \u003Ca href=\"http:\u002F\u002Fwww.wesg.ca\u002F2008\u002F08\u002Fwordpress-widget-most-popular\u002F#examples\" rel=\"nofollow ugc\">the examples\u003C\u002Fa> on the plugin homepage.\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cp>Used exclusively as a widget at the current time.\u003C\u002Fp>\n","This is a very simple widget that displays a link to the top commented posts on your blog.",300,51094,40,1,"2013-02-14T04:23:00.000Z","3.5.2","2.8","",[20,21,22,23],"comments","most-popular","sidebar","widget","http:\u002F\u002Fwww.wesg.ca\u002F2008\u002F08\u002Fwordpress-widget-most-popular\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmost-popular-posts.1.6.2.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":33,"avg_security_score":26,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},3,330,30,84,"2026-04-04T03:48:22.458Z",[38,57,74,92,110],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":48,"num_ratings":49,"last_updated":50,"tested_up_to":51,"requires_at_least":17,"requires_php":18,"tags":52,"homepage":55,"download_link":56,"security_score":48,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"top-commentators-widget","Top Commentators Widget","1.7","Lorna Timbah","https:\u002F\u002Fprofiles.wordpress.org\u002Fwebgrrrl\u002F","\u003Cp>This plugin creates a widget to show the top commentators in your WP site. Always go back to the Widget settings after each version update to Save your settings. Demo can be found at http:\u002F\u002Fdemo.webgrrrl.net\u003C\u002Fp>\n\u003Cp>The Top Commentators Widget plugin is adapted from Show Top Commentators plugin at Personal Financial Advice, this widget is easier to manage via the control form (no need to edit the PHP file); additional options are also available to make it more flexible. Read the FAQ section on how to customize the widget. Read the Changelog as well as http:\u002F\u002Fwebgrrrl.net\u002Ftags\u002Ftcw for the latest news on this widget.\u003C\u002Fp>\n\u003Cp>This widget is extensively tested with the following settings: Google Chrome 13.0.782.215 m, PHP 5.2.13, Apache 2.2.15 (Win32), MySQL 5.0.51a, WordPress 3.2.1. Further testing and bug report on this widget is greatly welcomed and appreciated.\u003C\u002Fp>\n","Adds a sidebar widget to show the top commentators in your WP site. Demo: http:\u002F\u002Fdemo.webgrrrl.net",200,156008,100,2,"2025-12-20T13:00:00.000Z","6.6.5",[20,53,54,22,23],"gravatar","seo","http:\u002F\u002Fwebgrrrl.net\u002Farchives\u002Fmy-top-commentators-widget-quick-dirty.htm","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftop-commentators-widget.1.7.zip",{"slug":58,"name":59,"version":60,"author":61,"author_profile":62,"description":63,"short_description":64,"active_installs":48,"downloaded":65,"rating":66,"num_ratings":67,"last_updated":68,"tested_up_to":69,"requires_at_least":70,"requires_php":18,"tags":71,"homepage":18,"download_link":73,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"disqus-recent-comments-widget","Disqus Recent Comments Widget","1.2","Andrew Bartel","https:\u002F\u002Fprofiles.wordpress.org\u002Fandrew-bartel\u002F","\u003Cp>The Disqus Recent Comments Widget plugin will create a configurable widget that will allow you to display comments in any widgetized area of your theme like sidebars and footers.\u003C\u002Fp>\n\u003Cp>You can customize the comment length and date format, filter users and choose from three different markup templates, among other things.  The plugin has full support for custom markup defined with register_sidebars() and should integrate smoothly with most themes in the wp.org repository.\u003C\u002Fp>\n\u003Cp>We try to be very proactive and responsive with support.  So, if you have any issues, please post in the support forums and we’ll do our best to resolve your issue promptly.\u003C\u002Fp>\n\u003Cp>You can follow development here: https:\u002F\u002Fgithub.com\u002Fandrewbartel\u002FDisqus_Recent_Comments\u003C\u002Fp>\n","Disqus has dropped support for their recent comments widget.  This plugin creates a configurable widget that will display your latest Disqus comments.",25099,86,7,"2014-09-22T01:54:00.000Z","4.0.38","3.4.1",[20,72,22,23],"disqus","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdisqus-recent-comments-widget.zip",{"slug":75,"name":76,"version":77,"author":78,"author_profile":79,"description":80,"short_description":81,"active_installs":48,"downloaded":82,"rating":83,"num_ratings":32,"last_updated":18,"tested_up_to":84,"requires_at_least":85,"requires_php":18,"tags":86,"homepage":89,"download_link":90,"security_score":48,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":91},"os-emi-calculator","EMI Calculator","1.0","vkt005","https:\u002F\u002Fprofiles.wordpress.org\u002Fvkt005\u002F","\u003Cp>Use EMI calculator as shortcode in post content or widget area without editing your theme files\u003C\u002Fp>\n\u003Cp>USAGE:\u003Cbr \u002F>\nUse [emicalc format=”full”][\u002Femicalc] OR [emicalc format=”sidebar”][\u002Femicalc] shortcode in your post content to show the EMI calculator without editing your theme files\u003Cbr \u002F>\nEXAMPLE:\u003Cbr \u002F>\n[emicalc format=”full”][\u002Femicalc] OR\u003Cbr \u002F>\nOR\u003Cbr \u002F>\n[emicalc format=”sidebar”][\u002Femicalc]\u003C\u002Fp>\n","Use EMI calculator as shortcode in post content or widget area without editing your theme files",7269,74,"3.7.41","2.0.5",[87,20,88,22,23],"calculator","match","http:\u002F\u002Fopensum.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fos-emi-calculator.zip","2026-03-15T10:48:56.248Z",{"slug":93,"name":94,"version":95,"author":96,"author_profile":97,"description":98,"short_description":99,"active_installs":100,"downloaded":101,"rating":102,"num_ratings":32,"last_updated":103,"tested_up_to":84,"requires_at_least":104,"requires_php":18,"tags":105,"homepage":108,"download_link":109,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"ff-tab-widget","FF Tab Widget","1.1","Kharis Sulistiyono","https:\u002F\u002Fprofiles.wordpress.org\u002Fkharisblank\u002F","\u003Cp>FF Tab Widget is a great solution for you to display different contents in a single widget. You can display popular posts, recent posts, recent commets, and tags in an animated tabs.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Easy to install, just drag the widget into your widgetized sidebar.\u003C\u002Fli>\n\u003Cli>Has widget options: Label name, limit tab content and show\u002Fhide tab item.\u003C\u002Fli>\n\u003Cli>Uses jQuery Tabs \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FamazingSurge\u002Fjquery-tabs\" rel=\"nofollow ugc\">script\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>If you’d like to contribute to the plugin you can find it on \u003Ca href=\"http:\u002F\u002Fgithub.com\u002Fkharissulistiyo\u002FFF-Tab-Widget\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>FF doesn’t stand for anything.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"http:\u002F\u002Fwww.kharissulistiyono.com\u002Fff-tab-widget-pro\u002F\" rel=\"nofollow ugc\">PRO version\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cp>Simply go to Appearance > Widgets and drag “FF Tab Widget” instance to the sidebar of your choice. Within the widget are several options where you can show\u002Fhide tab item and specifify the content limit. See the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fff-tab-widget\u002Fscreenshots\" rel=\"ugc\">screenshots\u003C\u002Fa> for more details.\u003C\u002Fp>\n\u003Ch4>Tabs Widget Style\u003C\u002Fh4>\n\u003Cp>The tab widget style tested on “Twenty Twelve” theme (see the plugin screenshot). It may look different on other themes. You can adjust its style by modifying CSS file (fftw.css) inside the plugin folder. To make developers easy to make modification I also profide the LESS file (fftw.less).\u003C\u002Fp>\n\u003Cp>If you do not have time to make your tabs widget looks beautiful on your theme, you can \u003Ca href=\"mailto:kharisblank@gmail.com\" rel=\"nofollow ugc\">contact me\u003C\u002Fa> for plugin customization service.\u003C\u002Fp>\n\u003Cp>Contact this \u003Ca href=\"http:\u002F\u002Fkharissulistiyo.com\" rel=\"nofollow ugc\">plugin author\u003C\u002Fa>.\u003C\u002Fp>\n","Display popular posts, recent posts, recent commets, and tags in an animated tabs in a single widget.",80,7765,46,"2014-01-09T17:16:00.000Z","3.0",[20,106,22,107,23],"posts","tags","https:\u002F\u002Fgithub.com\u002Fkharissulistiyo\u002FFF-Tab-Widget","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fff-tab-widget.zip",{"slug":111,"name":112,"version":113,"author":114,"author_profile":115,"description":116,"short_description":117,"active_installs":13,"downloaded":118,"rating":48,"num_ratings":14,"last_updated":119,"tested_up_to":120,"requires_at_least":104,"requires_php":18,"tags":121,"homepage":18,"download_link":123,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"simple-top-commenters","Simple Top Commenters","1.5.2","mrengy","https:\u002F\u002Fprofiles.wordpress.org\u002Fmrengy\u002F","\u003Cp>A sidebar widget that displays a list of top commenters across a site, showing the number of comments for each. Inspired by and extended from the Top Commentators Widget by WebGrrrl.\u003C\u002Fp>\n\u003Ch3>Supported Languages:\u003C\u002Fh3>\n\u003Col>\n\u003Cli>\n\u003Cp>English\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Slovene: Thanks to Mitja Mihelič: mitja.mihelic@arnes.si http:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fmmihelic\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Romanian: Thanks to Alexander Ovsov: \u003Ca href=\"http:\u002F\u002Fwebhostinggeeks.com\u002F\" rel=\"nofollow ugc\">Web Hosting Geeks\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Ukranian: Thanks to Michael Yunat: \u003Ca href=\"http:\u002F\u002Fgetvoip.com\u002Fblog\" rel=\"nofollow ugc\">http:\u002F\u002Fgetvoip.com\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Options:\u003C\u002Fh3>\n\u003Col>\n\u003Cli>\n\u003Cp>“Title”: customizable title that is displayed in the sidebar for this widget.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>“Define Commenters by”: choose whether to define an individual by email address or by name entered in the comment form\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>“Commenters to Exclude”: a list of people to exclude from the count. Can enter names and\u002For email addresses here. Separate each with a comma.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>“# of Commenters to List”: determines the number of top commenters to list.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>“Show ‘comments’ Label?”: If checked, a top commenter will appear as “mike: 10 comments”. If unchecked, he\u002Fshe will appear simply as “mike: 10”.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n","A sidebar widget that displays a list of top commenters across a site, showing the number of comments for each.",7108,"2017-10-01T19:57:00.000Z","4.8.28",[20,122,22,23],"counter","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsimple-top-commenters.zip",{"attackSurface":125,"codeSignals":137,"taintFlows":216,"riskAssessment":217,"analyzedAt":231},{"hooks":126,"ajaxHandlers":133,"restRoutes":134,"shortcodes":135,"cronEvents":136,"entryPointCount":27,"unprotectedCount":27},[127],{"type":128,"name":129,"callback":130,"file":131,"line":132},"action","widgets_init","anonymous","most-popular.php",13,[],[],[],[],{"dangerousFunctions":138,"sqlUsage":142,"outputEscaping":144,"fileOperations":27,"externalRequests":27,"nonceChecks":27,"capabilityChecks":27,"bundledLibraries":215},[139],{"fn":140,"file":131,"line":132,"context":141},"create_function","add_action(\"widgets_init\", create_function('', 'return register_widget(\"Most_Popular_Posts\");'));",{"prepared":32,"raw":27,"locations":143},[],{"escaped":145,"rawEcho":146,"locations":147},12,37,[148,151,153,154,156,158,159,161,162,164,166,167,169,171,172,174,176,178,179,181,183,185,187,189,191,193,195,196,198,200,202,203,205,207,209,211,213],{"file":131,"line":149,"context":150},67,"raw output",{"file":131,"line":152,"context":150},68,{"file":131,"line":152,"context":150},{"file":131,"line":155,"context":150},72,{"file":131,"line":157,"context":150},73,{"file":131,"line":157,"context":150},{"file":131,"line":160,"context":150},77,{"file":131,"line":160,"context":150},{"file":131,"line":163,"context":150},78,{"file":131,"line":165,"context":150},82,{"file":131,"line":165,"context":150},{"file":131,"line":168,"context":150},83,{"file":131,"line":170,"context":150},88,{"file":131,"line":170,"context":150},{"file":131,"line":173,"context":150},89,{"file":131,"line":175,"context":150},93,{"file":131,"line":177,"context":150},96,{"file":131,"line":177,"context":150},{"file":131,"line":180,"context":150},97,{"file":131,"line":182,"context":150},101,{"file":131,"line":184,"context":150},105,{"file":131,"line":186,"context":150},106,{"file":131,"line":188,"context":150},114,{"file":131,"line":190,"context":150},117,{"file":131,"line":192,"context":150},124,{"file":131,"line":194,"context":150},129,{"file":131,"line":194,"context":150},{"file":131,"line":197,"context":150},130,{"file":131,"line":199,"context":150},135,{"file":131,"line":201,"context":150},136,{"file":131,"line":201,"context":150},{"file":131,"line":204,"context":150},206,{"file":131,"line":206,"context":150},207,{"file":131,"line":208,"context":150},213,{"file":131,"line":210,"context":150},218,{"file":131,"line":212,"context":150},228,{"file":131,"line":214,"context":150},239,[],[],{"summary":218,"deductions":219},"The \"most-popular-posts\" plugin v1.6.2 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, coupled with the lack of identified vulnerabilities in past records, suggests a well-maintained and secure codebase.  Furthermore, the plugin demonstrates good practices by exclusively using prepared statements for all SQL queries and avoiding external HTTP requests, significantly reducing common attack vectors.\n\nHowever, a notable concern arises from the use of the `create_function` dangerous function. While the attack surface is currently zero in terms of entry points, the presence of this function could potentially lead to security issues if it were to process user-supplied input without proper sanitization. Additionally, a significant portion of the output (76%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if dynamic content is rendered directly without sanitization.  The lack of nonce checks and capability checks, while not immediately exploitable given the zero attack surface, represents a potential weakness if new entry points are introduced in future versions.\n\nIn conclusion, the plugin is currently in a strong security position due to its clean history and secure handling of SQL and external requests. The primary weaknesses lie in the use of `create_function` and the unescaped output. Addressing these areas would further strengthen the plugin's security and mitigate potential risks, especially if the attack surface were to expand in the future.",[220,223,226,229],{"reason":221,"points":222},"Use of dangerous function create_function",10,{"reason":224,"points":225},"High percentage of unescaped output",8,{"reason":227,"points":228},"No nonce checks",5,{"reason":230,"points":228},"No capability checks","2026-03-16T20:02:26.122Z",{"wat":233,"direct":240},{"assetPaths":234,"generatorPatterns":236,"scriptPaths":237,"versionParams":238},[235],"\u002Fwp-content\u002Fplugins\u002Fmost-popular-posts\u002Fcss\u002Fmost-popular-posts.css",[],[],[239],"most-popular-posts\u002Fcss\u002Fmost-popular-posts.css?ver=",{"cssClasses":241,"htmlComments":243,"htmlAttributes":244,"restEndpoints":246,"jsGlobals":247,"shortcodeOutput":248},[242],"widget_most_popular_posts",[],[245],"id=\"widget-most_popular_posts\"",[],[],[]]