[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5g5o8OTirZFoB7-7OpRmoo356cruwt60bHFcSgB6Pf4":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":14,"requires_at_least":14,"requires_php":14,"tags":15,"homepage":16,"download_link":17,"security_score":18,"vuln_count":13,"unpatched_count":13,"last_vuln_date":19,"fetched_at":20,"vulnerabilities":21,"developer":22,"crawl_stats":19,"alternatives":27,"analysis":28,"fingerprints":64},"recenlty-modified-admin-dashboard","Recently Modified","0.0.5","tbarsness","https:\u002F\u002Fprofiles.wordpress.org\u002Ftbarsness\u002F","\u003Cp>Plugin to list recently edited pages in the wordpress dashboard\u003C\u002Fp>\n","Plugin to list recently edited pages in the wordpress dashboard",10,1526,0,"",[],"http:\u002F\u002Fserversideguy.com\u002Fwordpress\u002Fplugins\u002Frecently-modified","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Frecenlty-modified-admin-dashboard.zip",100,null,"2026-03-15T14:44:11.924Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":23,"total_installs":11,"avg_security_score":18,"avg_patch_time_days":24,"trust_score":25,"computed_at":26},1,30,94,"2026-04-05T21:07:55.309Z",[],{"attackSurface":29,"codeSignals":41,"taintFlows":51,"riskAssessment":52,"analyzedAt":63},{"hooks":30,"ajaxHandlers":37,"restRoutes":38,"shortcodes":39,"cronEvents":40,"entryPointCount":13,"unprotectedCount":13},[31],{"type":32,"name":33,"callback":34,"file":35,"line":36},"action","wp_dashboard_setup","recently_modified_add_dashboard_widgets","recently-modified.php",70,[],[],[],[],{"dangerousFunctions":42,"sqlUsage":43,"outputEscaping":45,"fileOperations":13,"externalRequests":13,"nonceChecks":13,"capabilityChecks":13,"bundledLibraries":50},[],{"prepared":23,"raw":13,"locations":44},[],{"escaped":13,"rawEcho":23,"locations":46},[47],{"file":35,"line":48,"context":49},43,"raw output",[],[],{"summary":53,"deductions":54},"The \"recenlty-modified-admin-dashboard\" plugin v0.0.5 exhibits a generally good security posture with no identified vulnerabilities in its history and a clean taint analysis. The static analysis reveals a minimal attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events, and critically, none of these entry points are unprotected. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security.\n\nHowever, there are significant concerns regarding output escaping. The analysis indicates that 100% of the identified outputs are not properly escaped. This is a critical weakness, as unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the dashboard, potentially compromising user sessions or data. The lack of nonce checks and capability checks also presents a potential risk, as it implies that certain actions might not be properly authorized or protected against replay attacks.\n\nWhile the plugin's vulnerability history is spotless, suggesting good development practices so far, the identified output escaping issue is a severe oversight that needs immediate attention. In conclusion, the plugin has a strong foundation with a small attack surface and no known vulnerabilities, but the unescaped output represents a significant and actionable security risk that must be addressed.",[55,58,61],{"reason":56,"points":57},"100% of outputs are not properly escaped",8,{"reason":59,"points":60},"0 Nonce checks found",5,{"reason":62,"points":60},"0 Capability checks found","2026-03-16T23:33:17.139Z",{"wat":65,"direct":70},{"assetPaths":66,"generatorPatterns":67,"scriptPaths":68,"versionParams":69},[],[],[],[],{"cssClasses":71,"htmlComments":72,"htmlAttributes":73,"restEndpoints":74,"jsGlobals":75,"shortcodeOutput":76},[],[],[],[],[],[]]