[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFv2TA9UnZ23cie8xq4n1WmQx4AtmZsSvUPw497AZOe4":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"vulnerabilities":31,"developer":32,"crawl_stats":29,"alternatives":38,"analysis":138,"fingerprints":242},"ostoolbar","OSToolbar","3.0.3","OSTraining","https:\u002F\u002Fprofiles.wordpress.org\u002Falledia\u002F","\u003Cp>OSToolbar shows training videos inside your WordPress admin panel.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"http:\u002F\u002Fostraining.com\u002F\" title=\"OSTraining WordPress Training\" rel=\"nofollow ugc\">OSTraining.com\u003C\u002Fa> produces hundreds of training videos every year. We wanted to make it easier for WordPress users to see those videos without coming to our site each time.\u003C\u002Fp>\n\u003Cp>Using the OSToolbar is as easy as: Install, Activate, Watch. With three clicks you can have WordPress videos directly inside your WordPress admin panel.\u003C\u002Fp>\n\u003Cp>There is also a Pro version available. Features include:\u003C\u002Fp>\n\u003Col>\n\u003Cli>More videos\u003C\u002Fli>\n\u003Cli>Choose which videos to show\u003C\u002Fli>\n\u003Cli>Choose what order the videos appear in\u003C\u002Fli>\n\u003Cli>Choose which users can see the videos\u003C\u002Fli>\n\u003C\u002Fol>\n","OSToolbar is a plugin that shows training videos inside your WordPress admin panel.",10,2526,100,2,"2016-01-27T18:16:00.000Z","4.4.34","4.0","",[20,21,22,23,24],"documentation","help","support","tutorials","video","http:\u002F\u002Fwww.ostraining.com\u002Fostoolbar\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fostoolbar.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":33,"display_name":7,"profile_url":8,"plugin_count":34,"total_installs":11,"avg_security_score":27,"avg_patch_time_days":35,"trust_score":36,"computed_at":37},"alledia",1,30,84,"2026-04-04T02:11:00.344Z",[39,60,81,103,123],{"slug":40,"name":41,"version":42,"author":43,"author_profile":44,"description":45,"short_description":46,"active_installs":47,"downloaded":48,"rating":49,"num_ratings":50,"last_updated":51,"tested_up_to":52,"requires_at_least":53,"requires_php":54,"tags":55,"homepage":57,"download_link":58,"security_score":59,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"wp101","WP101 Video Tutorial Plugin","5.4.1","Syed Balkhi","https:\u002F\u002Fprofiles.wordpress.org\u002Fsmub\u002F","\u003Cp>The WP101® Video Tutorial Plugin is simply the easiest way to teach your clients WordPress basics, cutting your support costs while providing an invaluable resource for your clients. It delivers a library of professionally-produced, WordPress 101 tutorial videos directly within your client’s own dashboard.\u003C\u002Fp>\n\u003Cp>In addition to video tutorials for WordPress (both Gutenberg and Classic Editor), we’re continually expanding our library with video tutorials for the most popular WordPress plugins, including WooCommerce, Elementor, Beaver Builder, Ninja Forms, and WPForms.\u003C\u002Fp>\n\u003Cp>Simply enter your \u003Ca href=\"https:\u002F\u002Fwp101plugin.com\u002F\" rel=\"nofollow ugc\">WP101Plugin.com\u003C\u002Fa> API key to display our WordPress tutorial videos within your client’s WordPress administration panel.\u003C\u002Fp>\n\u003Cp>You can choose which tutorial videos to show in the list, or even embed your own custom videos.\u003C\u002Fp>\n\u003Cp>Stop wasting your valuable time teaching WordPress to your clients. Let the WP101 Plugin free your time to do what you do best!\u003C\u002Fp>\n","Professional video tutorials for WordPress, WooCommerce, Elementor, and more, right in the dashboard of your WordPress site. Perfect for beginners.",10000,324945,86,11,"2024-12-06T18:01:00.000Z","6.7.5","5.1","5.4",[21,56,23,24,40],"learn","https:\u002F\u002Fwp101plugin.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp101.5.4.1.zip",92,{"slug":61,"name":62,"version":63,"author":64,"author_profile":65,"description":66,"short_description":67,"active_installs":68,"downloaded":69,"rating":49,"num_ratings":70,"last_updated":71,"tested_up_to":72,"requires_at_least":73,"requires_php":18,"tags":74,"homepage":77,"download_link":78,"security_score":79,"vuln_count":34,"unpatched_count":28,"last_vuln_date":80,"fetched_at":30},"help-scout","Help Scout","6.5.7","BoldGrid","https:\u002F\u002Fprofiles.wordpress.org\u002Fboldgrid\u002F","\u003Ch4>Help Scout for WordPress\u003C\u002Fh4>\n\u003Cp>Thousands of businesses in more than 140 countries use Help Scout to make every customer support interaction more human & more helpful.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cp>This simple plugin takes only a few minutes to setup. It enables you to do a couple important things:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Add a contact form to your site, which submits inquiriest to Help Scout\u003C\u002Fli>\n\u003Cli>Add a \u003Ca href=\"https:\u002F\u002Fwww.helpscout.net\u002Fembed-tools\u002F\" rel=\"nofollow ugc\">Help Scout Beacon\u003C\u002Fa> to your site. Just paste your embed code and save.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cblockquote>\n\u003Cp>\u003Cstrong>Looking for more horsepower? Try Help Scout Desk.\u003C\u002Fstrong>\u003Cbr \u002F>\n  \u003Ca href=\"https:\u002F\u002Fwphelpscout.com\u002F?utm_medium=link&utm_campaign=hsfree&utm_source=wordpress.org\" rel=\"nofollow ugc\">Help Scout Desk\u003C\u002Fa> is a premium plugin that adds a full-featured customer portal to your WordPress site. Customers can submit inquiries, see their complete history and more.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n","Release 6.5.7 License: GPLv2 or later License URI: http:\u002F\u002Fwww.gnu.org\u002Flicenses\u002Fgpl-2.0.html Add a contact form to your website, or embed Help Scout Be &hellip;",400,22995,6,"2025-12-01T21:12:00.000Z","6.9.4","4.5",[75,20,76,22],"contact-form-help-desk","helpdesk","https:\u002F\u002Fwphelpscout.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhelp-scout.6.5.7.zip",99,"2025-01-07 00:00:00",{"slug":82,"name":83,"version":84,"author":85,"author_profile":86,"description":87,"short_description":88,"active_installs":13,"downloaded":89,"rating":13,"num_ratings":90,"last_updated":91,"tested_up_to":92,"requires_at_least":93,"requires_php":94,"tags":95,"homepage":101,"download_link":102,"security_score":13,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"chipbot","ChipBot – Video, Live Chat, & AI Help Desk","2.0.5","Matt Lo","https:\u002F\u002Fprofiles.wordpress.org\u002Fmattlo\u002F","\u003Ch4>Overview\u003C\u002Fh4>\n\u003Cp>🤔 Wondering why your traffic isn’t converting or spending too much on live chat for little in return? There’s not enough time in the day to solve this if you’re alone or in a small team. So we built ChipBot to help.\u003C\u002Fp>\n\u003Cp>👉 ChipBot is a new kind of plugin that improves the customer experience while reducing your time from doing so. ChipBot is built to elevate sales and reduce support tickets.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>✅ Use a \u003Ca href=\"https:\u002F\u002Fgetchipbot.com\" rel=\"nofollow ugc\">pop up video\u003C\u002Fa> to improve lead generation, sales, or conversion rates on your WordPress website.\u003C\u002Fli>\n\u003Cli>✅ Connect multiple videos together in a TikTok-style format for unlimited scrolling.\u003C\u002Fli>\n\u003Cli>✅ Close sales and qualify leads with built-in live chat.\u003C\u002Fli>\n\u003Cli>✅ Get customer notifications with our mobile app (iOS and Android).\u003C\u002Fli>\n\u003Cli>✅ Automate customer support with our integrated AI help desk.\u003C\u002Fli>\n\u003Cli>✅ Leverage our built-in AI tools to generate support documentation and respond to customer live chat questions automatically.\u003C\u002Fli>\n\u003Cli>✅ Analyze video retention and customer engagement.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What is ChipBot Video\u003C\u002Fh4>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FY__fOdT6nNw?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n","ChipBot turns your website into a face-to-face story experience powered by AI, video, and chat.",7976,3,"2025-10-13T20:28:00.000Z","6.8.5","6.0","7.0",[96,97,98,99,100],"ai","customer-support","help-desk","leads","videos","https:\u002F\u002Fgetchipbot.com\u002F?utm_source=wordpress&utm_medium=plugin-link","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fchipbot.2.0.5.zip",{"slug":104,"name":105,"version":106,"author":107,"author_profile":108,"description":109,"short_description":110,"active_installs":11,"downloaded":111,"rating":28,"num_ratings":28,"last_updated":18,"tested_up_to":112,"requires_at_least":113,"requires_php":18,"tags":114,"homepage":118,"download_link":119,"security_score":120,"vuln_count":34,"unpatched_count":34,"last_vuln_date":121,"fetched_at":122},"wp-dashboard-beacon","Dashboard Beacon","1.2.0","janhenckens","https:\u002F\u002Fprofiles.wordpress.org\u002Fjanhenckens\u002F","\u003Cp>This plugin makes it fast and easy to integrate Help Scout’s Beacon feature into your WordPress dashboard. That way, your client has easy access to your documentation and\u002For has an easy way of contacting you in case they encounter a problem.\u003C\u002Fp>\n\u003Cp>Read more about Help Scout Beaon \u003Ca href=\"http:\u002F\u002Fwww.helpscout.net\u002Fblog\u002Fintroducing-beacon\u002F\" rel=\"nofollow ugc\">here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Note: the plugin or it’s author are not affiliated with Help Scout in any way.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>After installation, you can customize the beacon’s options, icon and colour.\u003Cbr \u002F>\nYou can also enable the plugin for selected member roles, giving you control over which of your users has access to the beacon and can contact you.\u003C\u002Fp>\n","Easily integrate a Help Scout beacon in your site's dashboard.",1843,"4.5.33","3.5.0",[115,116,20,117,22],"client","dashboard","helpscout","http:\u002F\u002Fonedge.be","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-dashboard-beacon.1.2.0.zip",78,"2025-12-31 00:00:00","2026-03-15T10:48:56.248Z",{"slug":124,"name":125,"version":126,"author":127,"author_profile":128,"description":129,"short_description":130,"active_installs":28,"downloaded":131,"rating":28,"num_ratings":28,"last_updated":18,"tested_up_to":132,"requires_at_least":133,"requires_php":94,"tags":134,"homepage":18,"download_link":137,"security_score":13,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":122},"admin-notes-wp","Admin Notes WP","1.1.0","Steve Puddick","https:\u002F\u002Fprofiles.wordpress.org\u002Fstevepuddick\u002F","\u003Cp>Admin Notes WP allows you to embed instructional ‘how to’ videos and other \u003Ca href=\"https:\u002F\u002Fwww.wpbeginner.com\u002Fbeginners-guide\u002Fhow-to-easily-embed-videos-in-wordpress-blog-posts\u002F\" rel=\"nofollow ugc\">embeddable media from major platforms\u003C\u002Fa> directly in the WordPress admin help tabs. Useful, instructional videos can be included on the relevant admin pages to help website admin users learn how your plugins and theme work.\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FYlhb-SmepJM?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002F3sqjw-nN7Bc?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Cp>For more quick videos on the features of Admin Notes WP visit the \u003Ca href=\"https:\u002F\u002Fwww.youtube.com\u002Fchannel\u002FUCxAgzitpxI9kPZdFI3Z2ZmA\" rel=\"nofollow ugc\">Web Rockstar YouTube channel\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Other features include:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Along with embedded media, rich text can also be included in help tab content to explain how features work\u003C\u002Fli>\n\u003Cli>Custom notices can be placed on any admin screen, communicating important information about the page and how it works\u003C\u002Fli>\n\u003Cli>The custom admin footer text provide a subtle and unobtrusive information about about the company or person who setup\u002Fcreated the site\u003C\u002Fli>\n\u003Cli>Some users are not aware of the WordPress help tab. A bounce animation (similar to MacOS icon bounce) displays once per user until clicked to help them discover it for the first time\u003C\u002Fli>\n\u003Cli>Determining what ‘screen id’ a help tab should display on can be tricky. The Admin Screen ID Identifier Tool allows you to copy the screen id with the click of a button\u003C\u002Fli>\n\u003Cli>A default WordPress install comes with many built in help tabs that may not be relevant for your website and cause confusion. These default help tabs can be hidden if desired.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Components that are not relevant for your unique needs can be easily deactivated, removing them from the admin menus.\u003C\u002Fp>\n\u003Ch3>Useful Third Party Plugins and Other Techniques\u003C\u002Fh3>\n\u003Cp>The following are some additional third party plugins and useful techniques which can nicely enhance the functionality\u003Cbr \u002F>\nof Admin Notes WP.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Post Expirator\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fpost-expirator\u002F\" rel=\"ugc\">Post Expirator\u003C\u002Fa> can allow you to set Help Tab and Notice\u003Cbr \u002F>\nposts to expire (not display) after a certain time or date.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Post Dating Posts\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Setting the Help Tab or Notice post published date in the future will cause that post to only start appearing once that\u003Cbr \u002F>\ndate and time has been reached.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User Role Editor\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The \u003Ca href=\"https:\u002F\u002Fen-ca.wordpress.org\u002Fplugins\u002Fuser-role-editor\u002F\" rel=\"nofollow ugc\">User Role Editor\u003C\u002Fa> plugin allows you to manage the user capabilities\u003Cbr \u002F>\nassociated with Admin Notes WP. Refer to the Frequently Asked Questions section for the full list.\u003C\u002Fp>\n","Add 'how to' instructional videos, slide shows, and more directly in individual WordPress admin pages.",1225,"5.7.15","3.5",[135,21,136,22,24],"admin","note","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadmin-notes-wp.1.1.0.zip",{"attackSurface":139,"codeSignals":160,"taintFlows":206,"riskAssessment":227,"analyzedAt":241},{"hooks":140,"ajaxHandlers":156,"restRoutes":157,"shortcodes":158,"cronEvents":159,"entryPointCount":28,"unprotectedCount":28},[141,147,151],{"type":142,"name":143,"callback":144,"file":145,"line":146},"action","admin_init","initSettings","library\\ostoolbar\\Application.php",22,{"type":142,"name":148,"callback":149,"file":145,"line":150},"admin_menu","initAdminLinks",23,{"type":142,"name":152,"callback":153,"file":154,"line":155},"admin_enqueue_scripts","enqueueScripts","library\\ostoolbar\\Configuration.php",27,[],[],[],[],{"dangerousFunctions":161,"sqlUsage":162,"outputEscaping":164,"fileOperations":204,"externalRequests":34,"nonceChecks":28,"capabilityChecks":28,"bundledLibraries":205},[],{"prepared":28,"raw":28,"locations":163},[],{"escaped":28,"rawEcho":165,"locations":166},19,[167,170,172,174,176,178,180,182,183,185,187,188,190,193,195,197,199,201,202],{"file":154,"line":168,"context":169},93,"raw output",{"file":154,"line":171,"context":169},123,{"file":154,"line":173,"context":169},129,{"file":154,"line":175,"context":169},131,{"file":154,"line":177,"context":169},142,{"file":154,"line":179,"context":169},154,{"file":154,"line":181,"context":169},179,{"file":154,"line":181,"context":169},{"file":154,"line":184,"context":169},185,{"file":154,"line":186,"context":169},208,{"file":154,"line":186,"context":169},{"file":154,"line":189,"context":169},220,{"file":191,"line":192,"context":169},"library\\ostoolbar\\Controller.php",31,{"file":191,"line":194,"context":169},66,{"file":191,"line":196,"context":169},67,{"file":191,"line":198,"context":169},69,{"file":191,"line":200,"context":169},91,{"file":191,"line":168,"context":169},{"file":191,"line":203,"context":169},96,13,[],[207],{"entryPoint":208,"graph":209,"unsanitizedCount":34,"severity":226},"\u003CSanitize> (library\\ostoolbar\\Sanitize.php:0)",{"nodes":210,"edges":223},[211,217],{"id":212,"type":213,"label":214,"file":215,"line":216},"n0","source","$_GET","library\\ostoolbar\\Sanitize.php",24,{"id":218,"type":219,"label":220,"file":215,"line":221,"wp_function":222},"n1","sink","call_user_func() [RCE]",35,"call_user_func",[224],{"from":212,"to":218,"sanitized":225},false,"high",{"summary":228,"deductions":229},"The ostoolbar v3.0.3 plugin exhibits a mixed security posture. On the positive side, the plugin has no recorded CVEs, and its static analysis shows no dangerous functions, no raw SQL queries, and no known vulnerabilities. This suggests a diligent approach to addressing security vulnerabilities historically.\n\nHowever, significant concerns arise from the code analysis. The complete lack of output escaping for 19 total outputs is a major red flag, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis identified one flow with an unsanitized path, classified as high severity. The absence of nonce checks and capability checks on its entry points, while the attack surface appears small, leaves it susceptible to various attacks if any of these entry points were to process untrusted input or perform actions requiring authorization.\n\nIn conclusion, while the plugin's vulnerability history is clean, the static analysis reveals critical weaknesses in output handling and taint flow sanitation. The lack of authorization checks on its entry points further exacerbates these risks. The strengths lie in its SQL practices and lack of historical vulnerabilities, but these are overshadowed by the immediate and severe risks posed by unescaped output and unsanitized data flows.",[230,233,236,239],{"reason":231,"points":232},"0% of outputs properly escaped",15,{"reason":234,"points":235},"High severity unsanitized path taint flow",12,{"reason":237,"points":238},"0 nonce checks on entry points",7,{"reason":240,"points":238},"0 capability checks on entry points","2026-03-17T01:15:46.589Z",{"wat":243,"direct":252},{"assetPaths":244,"generatorPatterns":249,"scriptPaths":250,"versionParams":251},[245,246,247,248],"\u002Fwp-content\u002Fplugins\u002Fostoolbar\u002Fassets\u002Fcss\u002Fui-lightness\u002Fjquery-ui.css","\u002Fwp-content\u002Fplugins\u002Fostoolbar\u002Fassets\u002Fjs\u002Fjquery-ui.js","\u002Fwp-content\u002Fplugins\u002Fostoolbar\u002Fassets\u002Fcss\u002Fconfiguration.css","\u002Fwp-content\u002Fplugins\u002Fostoolbar\u002Fassets\u002Fjs\u002Fconfiguration.js",[],[246,248],[],{"cssClasses":253,"htmlComments":254,"htmlAttributes":255,"restEndpoints":256,"jsGlobals":257,"shortcodeOutput":258},[],[],[],[],[],[]]