[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffH-oUbXF43zJK2GawZfyl2DdTkzwMl8rK-qUV7v8PZ0":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":7,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27,"vulnerabilities":28,"developer":29,"crawl_stats":26,"alternatives":35,"analysis":119,"fingerprints":259},"noio-iconized-bookmarks","Noio Iconized Bookmarks","1.0.1","","https:\u002F\u002Fprofiles.wordpress.org\u002Fnoiodotnl\u002F","\u003Cp>Noio Iconized Bookmarks has 3 functions:\u003C\u002Fp>\n\u003Ch4>List bookmarks with favicons\u003C\u002Fh4>\n\u003Cp>Upon activation there is a function available that works just like WordPress’ built-in \u003Ccode>wp_list_bookmarks\u003C\u002Fcode>. The function is called \u003Ccode>list_iconized_bookmarks()\u003C\u002Fcode>, and it takes the same arguments as the original. The function takes images from the \u003Cem>link_image\u003C\u002Fem> field of each link. The images are displayed in front of the link, with \u003Ccode>class=\"favicon\"\u003C\u002Fcode>, and it is up to the user to define a proper style.\u003C\u002Fp>\n\u003Ch4>Iconized Links Widget\u003C\u002Fh4>\n\u003Cp>There is also a replacement Links widget available, to get iconized bookmarks into your blogroll. This widget has one option, which is the arguments string, with the same \u003Ca href=\"https:\u002F\u002Fcodex.wordpress.org\u002FTemplate_Tags\u002Fwp_list_bookmarks\"\" rel=\"nofollow ugc\">arguments\u003C\u002Fa> that are passed to \u003Ccode>wp_list_bookmarks\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch4>Iconizing\u003C\u002Fh4>\n\u003Cp>Iconizing might be a bit of a stupid name, but what this function does is add favicon-URLs to each of your links’ image fields! So you can just add a bunch of links to your blogroll, then run the plugin, and all favicons will be correctly set. You can start the plugin from the N.I.B. (Noio Iconized Bookmarks) panel in the settings panel.\u003C\u002Fp>\n","Plugin that allows you to automatically add favicons to your blog's links.",10,4541,0,"2011-02-20T01:41:00.000Z","3.0.5","2.8",[18,19,20,21,22],"blogroll","bookmarks","favicons","icons","links","http:\u002F\u002Fwww.noio.nl\u002F2009\u002F05\u002Fversion-one-of-nib\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fnoio-iconized-bookmarks.1.0.1.zip",85,null,"2026-03-15T15:16:48.613Z",[],{"slug":30,"display_name":30,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},"noiodotnl",1,30,84,"2026-04-04T05:39:58.987Z",[36,53,67,85,102],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":13,"num_ratings":13,"last_updated":7,"tested_up_to":46,"requires_at_least":47,"requires_php":7,"tags":48,"homepage":49,"download_link":50,"security_score":51,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":52},"faviroll","FAVIROLL – FAVIcons for blogROLL","0.6","UnderWordPressure","https:\u002F\u002Fprofiles.wordpress.org\u002Funderwordpressure\u002F","\u003Cp>This plugin convert the favicon.ico from the blogroll sites into PNG images and save this in a local cache file. The conversion process works just on the admin-page, visitors don’t have to waste time to wait for favicons from remote websites. If a blogroll entry was added or modified this single Link will be updated.\u003C\u002Fp>\n\u003Cp>All cached icons can conveniently be assigned to any of the bookmarks, just a mouse click.\u003C\u002Fp>\n\u003Cp>The plugin fallback to a default icon, if on the remote websites cannot be detected a valid favicon. The default icon can be configured like any other bookmark.\u003C\u002Fp>\n","This plugin convert the favicon.ico from the blogroll sites into PNG images and save this in a local cache file. The conversion process works just on  &hellip;",40,10895,"4.2.39","3.x",[18,19,20,21,22],"http:\u002F\u002Fwww.andurban.de\u002Fwordpress-stuff\u002Fplugins\u002Ffaviroll","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffaviroll.zip",100,"2026-03-15T10:48:56.248Z",{"slug":54,"name":55,"version":56,"author":57,"author_profile":58,"description":59,"short_description":60,"active_installs":61,"downloaded":62,"rating":13,"num_ratings":13,"last_updated":7,"tested_up_to":15,"requires_at_least":63,"requires_php":7,"tags":64,"homepage":65,"download_link":66,"security_score":51,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":52},"blogroll-links-favicons","Blogroll Links Favicons","2.0.4","Josh Betz","https:\u002F\u002Fprofiles.wordpress.org\u002Fbetzster\u002F","\u003Cp>Automatically adds favicons next to links in your blogroll. Also adds favicons to the links admin area.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Automatically caches favicon files locally.\u003C\u002Fli>\n\u003Cli>Icons in admin area\u003C\u002Fli>\n\u003Cli>Refresh Cache Button\u003C\u002Fli>\n\u003Cli>Adds \u003Ccode>class=\"blogroll-favicon\"\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Add a default favicon if link has no favicon\u003C\u002Fli>\n\u003C\u002Ful>\n","Automatically adds favicons to blogroll\u002Fbookmark links.",20,12639,"2.5",[18,19,20,21,22],"http:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fblogroll-links-favicons\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fblogroll-links-favicons.2.0.4.zip",{"slug":68,"name":69,"version":70,"author":71,"author_profile":72,"description":73,"short_description":74,"active_installs":75,"downloaded":76,"rating":13,"num_ratings":13,"last_updated":77,"tested_up_to":78,"requires_at_least":79,"requires_php":80,"tags":81,"homepage":83,"download_link":84,"security_score":51,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27},"blogroll-links","Blogroll Links","3.0.0","rajivpant","https:\u002F\u002Fprofiles.wordpress.org\u002Frajivpant\u002F","\u003Cp>Blogroll Links is a WordPress plugin that displays your site’s link bookmarks (formerly called “blogroll”) within posts and pages using a simple shortcode.\u003C\u002Fp>\n\u003Cp>For people who maintain their website or blog using the WordPress content management system, Blogroll Links uses WordPress’ built-in Links feature and presents links to friends’ pages, resources, and social networking profiles.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Display links by category using the category slug\u003C\u002Fli>\n\u003Cli>Customizable sorting (by name, URL, rating, or ID)\u003C\u002Fli>\n\u003Cli>Honors link visibility settings (show\u002Fhidden)\u003C\u002Fli>\n\u003Cli>Respects target window settings for each link\u003C\u002Fli>\n\u003Cli>Displays link descriptions and images if available\u003C\u002Fli>\n\u003Cli>Works with WordPress’ built-in Links Manager\u003C\u002Fli>\n\u003Cli>Supports XFN (XHTML Friends Network) relationship tags\u003C\u002Fli>\n\u003Cli>Full PHP 8+ compatibility\u003C\u002Fli>\n\u003Cli>Secure: Protected against SQL injection, XSS, and CSRF attacks\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cp>Add this shortcode to any post or page:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>[blogroll-links categoryslug=\"my-links\"]\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>Full Shortcode Options\u003C\u002Fh4>\n\u003Cpre>\u003Ccode>[blogroll-links categoryslug=\"my-links\" sortby=\"link_name\" sortorder=\"asc\"]\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>Parameters\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>categoryslug\u003C\u002Fcode> – The slug of the link category to display (required)\u003C\u002Fli>\n\u003Cli>\u003Ccode>sortby\u003C\u002Fcode> – Sort field: link_name, link_url, link_rating, link_id (default: link_name)\u003C\u002Fli>\n\u003Cli>\u003Ccode>sortorder\u003C\u002Fcode> – Sort direction: asc or desc (default: asc)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Examples\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Display friends’ websites sorted by name:\u003C\u002Fstrong>\u003Cbr \u002F>\n    [blogroll-links categoryslug=”friends” sortby=”link_name” sortorder=”asc”]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Display resources sorted by rating (highest first):\u003C\u002Fstrong>\u003Cbr \u002F>\n    [blogroll-links categoryslug=”resources” sortby=”link_rating” sortorder=”desc”]\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Display social media profiles:\u003C\u002Fstrong>\u003Cbr \u002F>\n    [blogroll-links categoryslug=”social-profiles”]\u003C\u002Fp>\n\u003Ch4>Live Examples\u003C\u002Fh4>\n\u003Cp>See this plugin in action:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.rajiv.com\u002Ffriends\u002F\" rel=\"nofollow ugc\">www.rajiv.com\u002Ffriends\u002F\u003C\u002Fa> – Social networking links with XFN tags\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.rajiv.com\u002Fcharity\u002F\" rel=\"nofollow ugc\">www.rajiv.com\u002Fcharity\u002F\u003C\u002Fa> – Charitable organizations list\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Credits\u003C\u002Fh4>\n\u003Cp>Thanks to Dave Grega and Adam E. Falk (xenograg) for their contributions to this code.\u003C\u002Fp>\n\u003Cp>Version 3.0 was modernized using \u003Ca href=\"https:\u002F\u002Frajiv.com\u002Fblog\u002F2025\u002F11\u002F09\u002Fsynthesis-engineering-with-claude-code-technical-implementation-and-workflows\u002F\" rel=\"nofollow ugc\">Synthesis Coding\u003C\u002Fa> with Claude Code – a human-AI collaborative development approach.\u003C\u002Fp>\n","Display your blogroll links anywhere in posts or pages using a simple shortcode.",300,33136,"2025-11-29T18:37:00.000Z","6.7.5","5.0","7.4",[18,19,22,82],"shortcode","https:\u002F\u002Fgithub.com\u002Frajivpant\u002Fblogroll-links","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fblogroll-links.3.0.0.zip",{"slug":86,"name":87,"version":88,"author":89,"author_profile":90,"description":91,"short_description":92,"active_installs":93,"downloaded":94,"rating":51,"num_ratings":31,"last_updated":95,"tested_up_to":96,"requires_at_least":16,"requires_php":7,"tags":97,"homepage":100,"download_link":101,"security_score":25,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27},"blogroll-rss-widget","Blogroll Widget with RSS Feeds","2.2","Jan Teriete","https:\u002F\u002Fprofiles.wordpress.org\u002Fleisurelarry\u002F","\u003Cp>This WordPress Widget allows you to display the recent posts of your blogroll links via RSS Feeds as a sidebar widget.\u003Cbr \u002F>\nThe Plugin works without Javascript and without AJAX. It uses the WordPress standard links database and honors the\u003Cbr \u002F>\nvisible and target settings as defined for each link (private links are not shown, links are displayed in the same or\u003Cbr \u002F>\nin a new window as specified). The Plugin is easy to install, the Widget is simple to use and highly customizable.\u003Cbr \u002F>\nYou can simply switch on \u002F off, select or type in the various configurations and settings.\u003C\u002Fp>\n\u003Cp>You can configure this Widget in the WordPress Appearance Widgets SubPanel as follows:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>add an own title to the sidebar widget\u003C\u002Fli>\n\u003Cli>define how many items you want to display \u003C\u002Fli>\n\u003Cli>choose the link category of the items (all links or one of your link categories)\u003C\u002Fli>\n\u003Cli>select the item order (link name ascending, link name descending, link id ascending, link id descending, random order)\u003C\u002Fli>\n\u003Cli>show the images entered to the respective links or let the plugin generate website thumbnails (via m-software.de) – NOT RECOMMENDED, as this service does not work properly anymore!\u003C\u002Fli>\n\u003Cli>define the image size\u003C\u002Fli>\n\u003Cli>show blogroll links\u003C\u002Fli>\n\u003Cli>add the ‘rel=nofollow’ attribute to the blogroll links\u003C\u002Fli>\n\u003Cli>define how many feed post links you want to display\u003C\u002Fli>\n\u003Cli>choose if you want to shorten the feed post link text and define the length in characters\u003C\u002Fli>\n\u003Cli>add the ‘rel=nofollow’ attribute to the feed post links\u003C\u002Fli>\n\u003Cli>show feed post excerpts\u003C\u002Fli>\n\u003Cli>define how many characters of the feed post excerpt you want to display\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Before using the Blogroll Widget with RSS Feeds make sure, that you have entered the right RSS Addresses to your links in the Links\u003Cbr \u002F>\nSubpanel. Otherwise this Plugin will not work correctly. No item is shown when no RSS Address is entered! With this you\u003Cbr \u002F>\nhave a further possibility to configure the Widget output. When you do not enter a RSS Address to a link, it will not be\u003Cbr \u002F>\ndisplayed in the Widget.\u003C\u002Fp>\n\u003Cp>Alternative to the WordPress Appearance Widgets SubPanel you can add and configure the Blogroll Widget with RSS Feeds directly\u003Cbr \u002F>\nin your theme file (e.g. sidebar.php). For details please see the installation tab.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Blogroll Widget with RSS Feeds requires WordPress Version 2.8 or higher\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch4>Available Languages\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>Italian – Thanks to talksina\u003C\u002Fli>\n\u003Cli>French – Thanks to \u003Ca href=\"http:\u002F\u002Fmaitremo.fr\u002F\" title=\"Ma&icirc;tre M&ocirc;\" rel=\"nofollow ugc\">Ma&icirc;tre M&ocirc;\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Belorussian – Thanks to \u003Ca href=\"http:\u002F\u002Fpc.de\u002F\" title=\"Marcis G.\" rel=\"nofollow ugc\">Marcis G.\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Bulgarian – Thanks to \u003Ca href=\"http:\u002F\u002Fwebhostinggeeks.com\u002F\" title=\"Web Geek\" rel=\"nofollow ugc\">Web Geek\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Displays the recent posts of your blogroll links via RSS Feeds in a customizable sidebar widget",200,52814,"2013-08-03T17:14:00.000Z","3.4.2",[18,19,98,22,99],"last-post","recent-post","http:\u002F\u002Fwww.officetrend.de\u002F2684\u002Fwordpress-plugin-blogroll-widget-with-rss-feeds\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fblogroll-rss-widget.zip",{"slug":103,"name":104,"version":105,"author":106,"author_profile":107,"description":108,"short_description":109,"active_installs":110,"downloaded":111,"rating":13,"num_ratings":13,"last_updated":112,"tested_up_to":113,"requires_at_least":63,"requires_php":114,"tags":115,"homepage":117,"download_link":118,"security_score":25,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27},"bookmarks-shortcode","Bookmarks Shortcode","2.3.1","Shea Bunge","https:\u002F\u002Fprofiles.wordpress.org\u002Fbungeshea\u002F","\u003Cp>Creates three shortcodes – [bookmarks], [links] and [blogroll] – that will generate an unordered list of your WordPress links.\u003Cbr \u002F>\nPreforms the same function as \u003Ccode>wp_list_bookmarks()\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>You can any of the shortcodes within a post, page, media, text widget, etc.\u003Cbr \u002F>\nThis makes it much more flexible then using the default Links page template that may be included in your theme as you can add other content surrounding the list, also when you change themes there is no need to edit the page.\u003C\u002Fp>\n\u003Cp>You can customize the output of the list by using the same arguments that are accepted by the \u003Ca href=\"https:\u002F\u002Fdeveloper.wordpress.org\u002Freference\u002Ffunctions\u002Fwp_list_bookmarks\u002F\" rel=\"nofollow ugc\">wp_list_bookmarks()\u003C\u002Fa> function.\u003Cbr \u002F>\nExample: \u003Ccode>[bookmarks show_images=0 show_ratings=1 show_name=1 ]\u003C\u002Fcode>\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fsheabunge\u002Fbookmarks-shortcode\" rel=\"nofollow ugc\">Contribute at GitHub\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Update Notice\u003C\u002Fh3>\n\u003Ch4>2.2\u003C\u002Fh4>\n\u003Cp>Improved default bookmarks markup\u003C\u002Fp>\n","Creates shortcodes that will generate an unordered list of your WordPress links (bookmarks).",90,6387,"2020-12-01T15:59:00.000Z","5.6.17","5.2",[18,19,22,82,116],"wp_list_bookmarks","https:\u002F\u002Fgithub.com\u002Fsheabunge\u002Fbookmarks-shortcode","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbookmarks-shortcode.zip",{"attackSurface":120,"codeSignals":140,"taintFlows":214,"riskAssessment":242,"analyzedAt":258},{"hooks":121,"ajaxHandlers":136,"restRoutes":137,"shortcodes":138,"cronEvents":139,"entryPointCount":13,"unprotectedCount":13},[122,128,132],{"type":123,"name":124,"callback":125,"file":126,"line":127},"action","widgets_init","anonymous","noio_iconized_bookmarks.php",69,{"type":123,"name":129,"callback":130,"file":126,"line":131},"admin_head","noio_iconized_bookmarks_head",418,{"type":123,"name":133,"callback":134,"file":126,"line":135},"admin_menu","noio_iconize_bookmarks_add_options_page",419,[],[],[],[],{"dangerousFunctions":141,"sqlUsage":145,"outputEscaping":148,"fileOperations":31,"externalRequests":31,"nonceChecks":13,"capabilityChecks":13,"bundledLibraries":213},[142],{"fn":143,"file":126,"line":127,"context":144},"create_function","add_action('widgets_init', create_function('', 'return register_widget(\"IconizedBookmarksWidget\");')",{"prepared":146,"raw":13,"locations":147},6,[],{"escaped":13,"rawEcho":149,"locations":150},36,[151,154,156,158,159,161,163,165,166,168,170,171,173,175,176,178,180,181,183,185,186,188,189,191,192,194,195,196,198,199,201,203,205,207,209,211],{"file":126,"line":152,"context":153},62,"raw output",{"file":126,"line":155,"context":153},63,{"file":126,"line":157,"context":153},64,{"file":126,"line":157,"context":153},{"file":126,"line":160,"context":153},128,{"file":126,"line":162,"context":153},244,{"file":126,"line":164,"context":153},257,{"file":126,"line":164,"context":153},{"file":126,"line":167,"context":153},259,{"file":126,"line":169,"context":153},260,{"file":126,"line":169,"context":153},{"file":126,"line":172,"context":153},263,{"file":126,"line":174,"context":153},265,{"file":126,"line":174,"context":153},{"file":126,"line":177,"context":153},268,{"file":126,"line":179,"context":153},269,{"file":126,"line":179,"context":153},{"file":126,"line":182,"context":153},272,{"file":126,"line":184,"context":153},273,{"file":126,"line":184,"context":153},{"file":126,"line":187,"context":153},274,{"file":126,"line":187,"context":153},{"file":126,"line":190,"context":153},277,{"file":126,"line":190,"context":153},{"file":126,"line":193,"context":153},278,{"file":126,"line":193,"context":153},{"file":126,"line":193,"context":153},{"file":126,"line":197,"context":153},279,{"file":126,"line":197,"context":153},{"file":126,"line":200,"context":153},288,{"file":126,"line":202,"context":153},292,{"file":126,"line":204,"context":153},296,{"file":126,"line":206,"context":153},299,{"file":126,"line":208,"context":153},301,{"file":126,"line":210,"context":153},414,{"file":126,"line":212,"context":153},415,[],[215,234],{"entryPoint":216,"graph":217,"unsanitizedCount":31,"severity":233},"noio_iconize_bookmarks_options_page (noio_iconized_bookmarks.php:149)",{"nodes":218,"edges":230},[219,224],{"id":220,"type":221,"label":222,"file":126,"line":223},"n0","source","$_POST",178,{"id":225,"type":226,"label":227,"file":126,"line":228,"wp_function":229},"n1","sink","query() [SQLi]",187,"query",[231],{"from":220,"to":225,"sanitized":232},false,"high",{"entryPoint":235,"graph":236,"unsanitizedCount":31,"severity":233},"\u003Cnoio_iconized_bookmarks> (noio_iconized_bookmarks.php:0)",{"nodes":237,"edges":240},[238,239],{"id":220,"type":221,"label":222,"file":126,"line":223},{"id":225,"type":226,"label":227,"file":126,"line":228,"wp_function":229},[241],{"from":220,"to":225,"sanitized":232},{"summary":243,"deductions":244},"The \"noio-iconized-bookmarks\" plugin version 1.0.1 exhibits a concerning security posture despite having a seemingly small attack surface. While the static analysis reports zero AJAX handlers, REST API routes, shortcodes, or cron events without authentication, this lack of entry points might also contribute to the absence of built-in security checks like capability checks and nonce checks.  The plugin uses the `create_function` which is deprecated and considered a security risk due to its ability to execute arbitrary PHP code.  Furthermore, the taint analysis revealed two high-severity flows with unsanitized paths, indicating potential vulnerabilities related to file operations or external requests where input might not be properly validated before being used in a sensitive operation.  The lack of output escaping for all 36 outputs is a significant concern, as it opens the door for cross-site scripting (XSS) vulnerabilities if any user-controlled data is displayed without proper sanitization.  The complete absence of recorded CVEs is a positive sign, suggesting the plugin has not had publicly disclosed vulnerabilities. However, this does not negate the issues found in the static analysis. The overall security posture is weakened by the presence of dangerous functions, unsanitized taint flows, and universal output escaping failures, despite the limited attack surface and clean CVE history.",[245,248,250,253,256],{"reason":246,"points":247},"High severity taint flows with unsanitized paths",14,{"reason":249,"points":11},"Dangerous function 'create_function' used",{"reason":251,"points":252},"100% of outputs are not properly escaped",15,{"reason":254,"points":255},"No nonce checks",7,{"reason":257,"points":255},"No capability checks","2026-03-17T01:09:43.651Z",{"wat":260,"direct":274},{"assetPaths":261,"generatorPatterns":266,"scriptPaths":267,"versionParams":268},[262,263,264,265],"\u002Fwp-content\u002Fplugins\u002Fnoio-iconized-bookmarks\u002Fempty.png","\u002Fwp-content\u002Fplugins\u002Fnoio-iconized-bookmarks\u002Fnotfound.png","\u002Fwp-content\u002Fplugins\u002Fnoio-iconized-bookmarks\u002Fdefault.gif","\u002Fwp-content\u002Fplugins\u002Fnoio-iconized-bookmarks\u002Fselect.png",[],[],[269,270,271,272,273],"noio-iconized-bookmarks\u002Fempty.png?ver=","noio-iconized-bookmarks\u002Fnotfound.png?ver=","noio-iconized-bookmarks\u002Fdefault.gif?ver=","noio-iconized-bookmarks\u002Fselect.png?ver=","noio-iconized-bookmarks\u002Fnoio_iconized_bookmarks.php?ver=",{"cssClasses":275,"htmlComments":277,"htmlAttributes":278,"restEndpoints":280,"jsGlobals":281,"shortcodeOutput":282},[276],"iconized_bookmarks",[],[279],"widget_args",[],[],[]]