[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fC22PxiHTUoxKFbi_j8I1kJ3Uqf7cRyJVYmSc1SsKWnk":3,"$fYHY1vrHtIRbmGj_ua8E9qoplx2aOv1knShbS35ELk2U":200,"$fdaTOK4nJrwTxIOD1sqC6GHUmIfGdWA3hEcxVE3f3Na0":205},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":143,"fingerprints":187},"redirect-to-homepage-after-logout","Redirect to Homepage After Logout","1.0.1","Sarangan Thillaiampalam","https:\u002F\u002Fprofiles.wordpress.org\u002Fsarangan112\u002F","\u003Cp>This lightweight plugin automatically redirects users to the homepage after they log out of your WordPress site.\u003Cbr \u002F>\nIt’s simple, fast, and requires no configuration.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Redirects users to the homepage after logout\u003C\u002Fli>\n\u003Cli>Works with any WordPress theme\u003C\u002Fli>\n\u003Cli>No setup required — just activate and go\u003C\u002Fli>\n\u003Cli>No impact on login or other redirects\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cp>Developed by Sarangan Thillayampalam\u003C\u002Fp>\n","This lightweight plugin automatically redirects users to the homepage after they log out of your WordPress site.",10,825,0,"2026-05-20T20:32:00.000Z","7.0.2","5.0","7.0",[19,20,21,22,23],"homepage","logout","redirect","session","user","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fredirect-to-homepage-after-logout.1.0.1.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"sarangan112",2,30,94,"2026-08-26T16:28:02.196Z",[38,62,87,108,127],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":35,"num_ratings":48,"last_updated":49,"tested_up_to":15,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":57,"download_link":58,"security_score":59,"vuln_count":60,"unpatched_count":13,"last_vuln_date":61,"fetched_at":28},"inactive-logout","Inactive Logout","3.6.2","Deepen Bajracharya","https:\u002F\u002Fprofiles.wordpress.org\u002Fj_3rk\u002F","\u003Cp>Protect your WordPress users’ sessions from prying eyes and snoopers!\u003C\u002Fp>\n\u003Cp>The Inactive Logout plugin automatically terminates idle user sessions, safeguarding your site if users leave their sessions unattended.\u003C\u002Fp>\n\u003Cp>A simple plugin which is easy to configure and use. After installing and activating it, just set the idle timeout from the plugin settings. From then on, any unattended idle WordPress sessions will be automatically terminated. You can also display a custom message to users, warning them that their session is about to end.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Try it out ==> \u003Ca href=\"https:\u002F\u002Ftastewp.org\u002Fplugins\u002Finactive-logout\u002F\" title=\"Demo Link\" rel=\"nofollow ugc\">Demo\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>FEATURES:\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Change idle timeout time.\u003C\u002Fli>\n\u003Cli>Count down of 10 seconds before actual logout. You can remove this feature if you dont want it.\u003C\u002Fli>\n\u003Cli>Add only \u003Cstrong>Wake Up!\u003C\u002Fstrong> message where user will not logout but instead a wakeup message will be shown upon inactive.\u003C\u002Fli>\n\u003Cli>Custom Popup Message.\u003C\u002Fli>\n\u003Cli>Show idle message for non authenticated users or redirect them.\u003C\u002Fli>\n\u003Cli>Concurrent user logouts.\u003C\u002Fli>\n\u003Cli>Toast notification on Logout.\u003C\u002Fli>\n\u003Cli>Redirect to a Different Page instead of Popup box. Create a page such as timeout page and add your content there by creating a blank template or style it as you wish according to your theme.\u003C\u002Fli>\n\u003Cli>Multiple User Role Configurations for individual timeout and session logout redirects.\u003C\u002Fli>\n\u003Cli>Logout to custom page or existing page.\u003C\u002Fli>\n\u003Cli>Clean UI\u003C\u002Fli>\n\u003Cli>WooCommerce Supported.\u003C\u002Fli>\n\u003Cli>Multisite Support: Override all sites with one setting.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>EXTEND OTHER FEATURES:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Few of the key features to \u003Cstrong>\u003Ca href=\"https:\u002F\u002Finactive-logout.com\u002Fpricing\u002F\" title=\"Inactive Logout Pro\" rel=\"nofollow ugc\">Inactive Logout Pro\u003C\u002Fa>\u003C\u002Fstrong>:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Auto browser close logout after defined duration.\u003C\u002Fli>\n\u003Cli>Fully functional multi-tab support.\u003C\u002Fli>\n\u003Cli>User Based Logout\u003C\u002Fli>\n\u003Cli>Track Visitors based on \u003Cstrong>(Login time, logout time, browser, online status, session duration, role, os, IP)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Force Logout All Users\u003C\u002Fli>\n\u003Cli>Logout Specific User(s)\u003C\u002Fli>\n\u003Cli>Bulk Logout Users\u003C\u002Fli>\n\u003Cli>Concurrent Login Limits.\u003C\u002Fli>\n\u003Cli>Last Login Activity\u003C\u002Fli>\n\u003Cli>Override Multiple Login priority\u003C\u002Fli>\n\u003Cli>User Lock whenever certain limit login has been reached.\u003C\u002Fli>\n\u003Cli>Track user login sessions.\u003C\u002Fli>\n\u003Cli>Logout redirects.\u003C\u002Fli>\n\u003Cli>Login redirects.\u003C\u002Fli>\n\u003Cli>Email notification and email template overrides for Locked concurrent session.\u003C\u002Fli>\n\u003Cli>Disable inactive logout for specified pages according to your need. Check this \u003Cstrong>\u003Ca href=\"https:\u002F\u002Fgist.github.com\u002Ftechies23\u002F6d2852eedd6ae56c486056e021e4ee48\" title=\"documentation\" rel=\"nofollow ugc\">Documentation\u003C\u002Fa>\u003C\u002Fstrong> for additional post type support.\u003C\u002Fli>\n\u003Cli>Disable native wordpress login popup after logout\u003C\u002Fli>\n\u003Cli>Modal Customizer\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>**See the \u003Ca href=\"https:\u002F\u002Finactive-logout.com\u002F\" title=\"Inactive Logout\" rel=\"nofollow ugc\">Inactive Logout\u003C\u002Fa> homepage for further information.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Please consider giving a \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Finactive-logout\u002Freviews\u002F#new-post\" title=\"5 star thumbs up\" rel=\"ugc\">5 star thumbs up\u003C\u002Fa> if you found this useful.\u003C\u002Fstrong>\u003C\u002Fp>\n","Automatically logout idle user sessions, with logout redirections and concurrent limit logins all in one place.",10000,678526,106,"2026-06-04T07:06:00.000Z","6.6","7.4",[53,54,20,55,56],"concurrent-login-limit","idle-logout","security","user-redirection","https:\u002F\u002Finactive-logout.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finactive-logout.3.6.2.zip",97,3,"2025-10-31 13:27:51",{"slug":63,"name":64,"version":65,"author":66,"author_profile":67,"description":68,"short_description":69,"active_installs":70,"downloaded":71,"rating":72,"num_ratings":73,"last_updated":74,"tested_up_to":15,"requires_at_least":75,"requires_php":51,"tags":76,"homepage":82,"download_link":83,"security_score":84,"vuln_count":85,"unpatched_count":13,"last_vuln_date":86,"fetched_at":28},"loggedin","Loggedin – Limit Concurrent Sessions","3.0.2","Joel James","https:\u002F\u002Fprofiles.wordpress.org\u002Fjoelcj91\u002F","\u003Cp>\u003Cstrong>Loggedin\u003C\u002Fstrong> caps the number of simultaneous WordPress sessions a user account is allowed to hold. When the cap is reached, you choose what happens next — log out the oldest device, log out every other device, or block the new login outright. It’s the lightweight, no-bloat way to stop account sharing on membership sites, LMS courses, paid communities, and any WordPress install where one paid account shouldn’t be open on five devices at once.\u003C\u002Fp>\n\u003Cp>The plugin hooks straight into WordPress’s standard authentication pipeline and uses the native \u003Ccode>WP_Session_Tokens\u003C\u002Fcode> API, so it works on every host, with every theme, and alongside every login plugin you might already run. No cron jobs, no background polling, no third-party services.\u003C\u002Fp>\n\u003Ch3>How it works\u003C\u002Fh3>\n\u003Cp>A “session” in WordPress is the authenticated token created the moment a user logs in — one per browser, per device. Two browsers on the same laptop count as two sessions; a phone and a desktop count as two. Closing a tab does \u003Cstrong>not\u003C\u002Fstrong> end a session — the token lives server-side until the user explicitly signs out or another login displaces it.\u003C\u002Fp>\n\u003Cp>Loggedin watches every login attempt:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Counts the user’s current active sessions.\u003C\u002Fli>\n\u003Cli>Compares that count to the limit you’ve configured.\u003C\u002Fli>\n\u003Cli>Applies the rule you’ve picked — silently make room for the new login, or reject the new login with an error on wp-login.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>There’s a one-click \u003Cstrong>Force Logout\u003C\u002Fstrong> panel in the admin to clear every session for a specific user when someone’s locked out by the cap and can’t reach their other devices. Identify the user by ID, email, or username — all three work.\u003C\u002Fp>\n\u003Ch3>Who it’s for\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Membership sites\u003C\u002Fstrong> — MemberPress, Paid Memberships Pro, Restrict Content Pro, WooCommerce Memberships, etc. Stop one paid account from being shared across a household, a classroom, or a Discord server.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Online courses & LMS\u003C\u002Fstrong> — LearnDash, LifterLMS, TutorLMS, Sensei. Make sure the seat someone paid for is actually used by that someone.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Subscription stores\u003C\u002Fstrong> — WooCommerce Subscriptions, Easy Digital Downloads recurring. Keep subscriber counts honest.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Corporate intranets & client portals\u003C\u002Fstrong> — Enforce a one-device-at-a-time policy for staff or client accounts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>BuddyPress \u002F BuddyBoss communities\u003C\u002Fstrong> — Reduce ban-evasion and duplicate-account abuse.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compliance-driven sites\u003C\u002Fstrong> — Healthcare, finance, education installs where audit policy requires a per-account session cap.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Global concurrent-login limit\u003C\u002Fstrong> — Pick any number from 1 upwards as the per-user cap.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Three built-in modes\u003C\u002Fstrong> — Logout Oldest (kick the user’s oldest device, keep the rest), Logout All (the new login becomes the only active session), or Block New (reject the login and show an error on wp-login).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Force Logout\u003C\u002Fstrong> — Type a user ID, email, or username and clear every active session for that user in one click.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works with any session storage\u003C\u002Fstrong> — Uses the standard \u003Ccode>WP_Session_Tokens\u003C\u002Fcode> API. Stock WordPress, Redis, Memcached — all supported (the Logout Oldest mode needs the default user-meta storage; the other modes work everywhere).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable error message\u003C\u002Fstrong> — Override the message shown when a login is blocked, via a single filter.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built for developers\u003C\u002Fstrong> — Every decision passes through documented PHP hooks and filters. Override the cap per user \u002F role \u002F capability, exempt service accounts, audit force-logouts, or splice the plugin into your own auth pipeline. Full hook reference in the \u003Ca href=\"https:\u002F\u002Fdocs.duckdev.com\u002Floggedin\u002Fdeveloper-docs\" rel=\"nofollow ugc\">developer docs\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight\u003C\u002Fstrong> — No cron, no background polling, no remote calls. The whole plugin runs at the moment a login happens.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Translation-ready\u003C\u002Fstrong> — Loaded with the WordPress i18n APIs; contribute translations on WordPress.org.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>📦 Add-ons\u003C\u002Fh3>\n\u003Cp>Extend Loggedin with these official \u003Ca href=\"https:\u002F\u002Fduckdev.com\u002Faddons\u002Floggedin\u002F\" rel=\"nofollow ugc\">add-ons\u003C\u002Fa>:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fduckdev.com\u002Faddon\u002Floggedin-active-sessions\u002F\" rel=\"nofollow ugc\">Active Sessions\u003C\u002Fa>\u003C\u002Fstrong> — See exactly who’s signed in right now, drill into each device per user, and sign out a single session — or every session — in one click.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fduckdev.com\u002Faddon\u002Flimit-per-user\u002F\" rel=\"nofollow ugc\">Limit Per User\u003C\u002Fa>\u003C\u002Fstrong> — Override the global session cap for an individual user account directly from their WordPress profile. Perfect for tiered access or trusted-staff exemptions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fduckdev.com\u002Faddon\u002Flimit-per-role\u002F\" rel=\"nofollow ugc\">Limit Per Role\u003C\u002Fa>\u003C\u002Fstrong> — Set a different concurrent-session cap per WordPress role. Give administrators more headroom while keeping subscribers tight, or vice versa.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fduckdev.com\u002Faddon\u002Freal-time-logout\u002F\" rel=\"nofollow ugc\">Real-time Logout\u003C\u002Fa>\u003C\u002Fstrong> — Detect logouts in near-real-time. When Loggedin terminates a session, the user’s other open tabs reload to wp-login automatically — no waiting for the next page click.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>📚 Documentation\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.duckdev.com\u002Floggedin\u002Fgetting-started\" rel=\"nofollow ugc\">Getting started\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.duckdev.com\u002Floggedin\u002Fgeneral-settings\" rel=\"nofollow ugc\">General settings\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.duckdev.com\u002Floggedin\u002Fmanage-sessions\" rel=\"nofollow ugc\">Force Logout (Manage Sessions)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.duckdev.com\u002Floggedin\u002Faddons\u002F\" rel=\"nofollow ugc\">Add-ons overview\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.duckdev.com\u002Floggedin\u002Fdeveloper-docs\" rel=\"nofollow ugc\">Developer docs — hooks, filters, REST\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🐛 Bug reports\u003C\u002Fh3>\n\u003Cp>Found a bug? File it on the \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FJoel-James\u002Floggedin\u002Fissues\" rel=\"nofollow ugc\">Loggedin GitHub repository\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Cem>GitHub is for bug reports and development-related issues only. For end-user support, please use the WordPress.org \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Floggedin\u002F\" rel=\"ugc\">support forums\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n","Limit concurrent user logins in WordPress, stop account sharing, force logout active sessions, and pick what happens when the cap is hit.",8000,144274,98,110,"2026-07-01T07:59:00.000Z","6.0",[77,78,79,80,81],"concurrent-login","force-logout","login-limit","prevent-account-sharing","user-sessions","https:\u002F\u002Fduckdev.com\u002Fproducts\u002Floggedin-limit-active-logins\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Floggedin.3.0.2.zip",99,1,"2024-09-30 19:43:37",{"slug":88,"name":89,"version":90,"author":91,"author_profile":92,"description":93,"short_description":94,"active_installs":95,"downloaded":96,"rating":97,"num_ratings":60,"last_updated":98,"tested_up_to":99,"requires_at_least":16,"requires_php":51,"tags":100,"homepage":106,"download_link":107,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"basic-front-end-login","Basic Front-End Login","2.1","Mitchell Bennis","https:\u002F\u002Fprofiles.wordpress.org\u002Feemitch\u002F","\u003Cp>Adds a basic front-end login for to any page, post or widget and redirects to the page you choose. It also can block access to the back-end and disable the Admin Bar. This plugin is for when you want your users to be logged-in, but do not want them to have access to the WordPress Dashboard.\u003C\u002Fp>\n\u003Cp>To display the login form, place this shortcode on any page, post, or widget: \u003Cem>[eeBFEL]\u003C\u002Fem>\u003C\u002Fp>\n\u003Cp>After the user has logged in, they will be redirected to your home page or the URL you define in the plugin settings. You can also optionaly display a logout button at the bottom-right of each page.\u003C\u002Fp>\n\u003Ch3>Redirect After Login\u003C\u002Fh3>\n\u003Cp>To define destinations in additional login forms, use the “redirect” attribute to over-ride the default. There is no limit to the number of forms you can use.\u003C\u002Fp>\n\u003Cp>\u003Cem>[eeBFEL redirect=”https:\u002F\u002Fwebsite.com\u002Fyour-files-page\u002F”]\u003C\u002Fem>\u003C\u002Fp>\n\u003Ch3>Deny Dashboard Access\u003C\u002Fh3>\n\u003Cp>In the plugin settings you can optionally select roles that you want to deny back-end access to. All built-in and custom roles, except Administrator, can be blocked. The Admin Bar will not appear and direct back-end access attempts will simply redirect to your home page. This restriction will be site-wide and is unrelated to the use of the shortcode.\u003C\u002Fp>\n\u003Cp>Even if you don’t need a login form, this can add an extra measure of security to your website by denying back-end access to all roles except Administrators.\u003C\u002Fp>\n\u003Ch3>NEW – Show a Logout Button\u003C\u002Fh3>\n\u003Cp>Optionally show a small logout button on the bottom-right of each page if the user is logged in. Logging out returns the user to the home page.\u003C\u002Fp>\n","Adds a basic front-end login form to any page, post or widget and redirects to the page you choose.",300,5745,74,"2025-12-25T22:12:00.000Z","6.9.5",[101,102,103,104,105],"login-form","login-redirect","logout-button","no-admin-bar","user-login","https:\u002F\u002Fsimplefilelist.com\u002Fbasic-front-end-login\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbasic-front-end-login.zip",{"slug":109,"name":110,"version":111,"author":112,"author_profile":113,"description":114,"short_description":115,"active_installs":116,"downloaded":117,"rating":26,"num_ratings":60,"last_updated":118,"tested_up_to":119,"requires_at_least":120,"requires_php":24,"tags":121,"homepage":123,"download_link":124,"security_score":125,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":126},"easy-timeout-session","Easy Timeout Session","1.1","jokiruiz","https:\u002F\u002Fprofiles.wordpress.org\u002Fjokioki\u002F","\u003Cp>The Easy Timeout Session WordPress plugin allows you to change the session\u003Cbr \u002F>\nduration for the WordPress user.\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>Open Timeout Session Page\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Specify the session length (you can specify in seconds, hours or days)\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Do you use worpdress admin with an iPad? Don´t worry, this plugin is fully\u003Cbr \u002F>\nadapted for tablets and smartphones.\u003C\u002Fp>\n\u003Cp>\u003Cem>Thank you for downloading! your feedback is well appreciated!\u003C\u002Fem>\u003C\u002Fp>\n","The Easy Timeout Session WordPress plugin allows you to change the session duration for the WordPress user.",200,6968,"2015-11-02T12:36:00.000Z","4.3.34","3.0.1",[122],"timeout-session-cookie-user-wordpress-login-logout","http:\u002F\u002Fwordpress.org\u002Fplugins\u002Feasy-timeout-session\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Feasy-timeout-session.zip",85,"2026-04-16T10:56:18.058Z",{"slug":128,"name":129,"version":130,"author":131,"author_profile":132,"description":133,"short_description":134,"active_installs":135,"downloaded":136,"rating":13,"num_ratings":13,"last_updated":137,"tested_up_to":138,"requires_at_least":24,"requires_php":24,"tags":139,"homepage":24,"download_link":142,"security_score":125,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"wp-redirect-to-homepage-after-login","WP – Redirect to homepage after login","1.7.9","Hervé Yvis","https:\u002F\u002Fprofiles.wordpress.org\u002Fyvisherve\u002F","\u003Cp>This lightweight plugin allow you to redirect all users to your site’s homepage after the login step.\u003C\u002Fp>\n\u003Ch4>License\u003C\u002Fh4>\n\u003Cp>This program is provided under the MIT license.\u003C\u002Fp>\n\u003Cp>Copyright (c) 2019 Hervé Yvis\u003C\u002Fp>\n\u003Cp>Permission is hereby granted, free of charge, to any person obtaining a copy\u003Cbr \u002F>\nof this software and associated documentation files (the “Software”), to deal\u003Cbr \u002F>\nin the Software without restriction, including without limitation the rights\u003Cbr \u002F>\nto use, copy, modify, merge, publish, distribute, sublicense, and\u002For sell\u003Cbr \u002F>\ncopies of the Software, and to permit persons to whom the Software is\u003Cbr \u002F>\nfurnished to do so, subject to the following conditions:\u003C\u002Fp>\n\u003Cp>The above copyright notice and this permission notice shall be included in all\u003Cbr \u002F>\ncopies or substantial portions of the Software.\u003C\u002Fp>\n\u003Cp>THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\u003Cbr \u002F>\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\u003Cbr \u002F>\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\u003Cbr \u002F>\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\u003Cbr \u002F>\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\u003Cbr \u002F>\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\u003Cbr \u002F>\nSOFTWARE.\u003C\u002Fp>\n","This lightweight plugin allow you to redirect all users to your site's homepage after the login step.",70,3041,"2020-04-13T03:19:00.000Z","5.4.19",[19,140,21,141],"login","users","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-redirect-to-homepage-after-login.1.7.9.zip",{"attackSurface":144,"codeSignals":164,"taintFlows":174,"riskAssessment":175,"analyzedAt":186},{"hooks":145,"ajaxHandlers":160,"restRoutes":161,"shortcodes":162,"cronEvents":163,"entryPointCount":13,"unprotectedCount":13},[146,152,156],{"type":147,"name":148,"callback":149,"file":150,"line":151},"action","admin_init","rhal_settings_init","redirect-homepage-logout.php",60,{"type":147,"name":153,"callback":154,"file":150,"line":155},"admin_menu","rhal_add_admin_menu",118,{"type":147,"name":157,"callback":158,"file":150,"line":159},"wp_logout","wpc_auto_redirect_after_logout",179,[],[],[],[],{"dangerousFunctions":165,"sqlUsage":166,"outputEscaping":168,"fileOperations":13,"externalRequests":13,"nonceChecks":13,"capabilityChecks":13,"bundledLibraries":173},[],{"prepared":13,"raw":13,"locations":167},[],{"escaped":33,"rawEcho":85,"locations":169},[170],{"file":150,"line":171,"context":172},63,"raw output",[],[],{"summary":176,"deductions":177},"The plugin 'redirect-to-homepage-after-logout' v1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface, with no identified entry points that lack authentication. The code also shows good practices by exclusively using prepared statements for its SQL queries and not performing any file operations or external HTTP requests.  However, the static analysis does reveal some potential weaknesses.  A notable concern is the lack of nonce checks and capability checks, which are crucial for securing sensitive operations, especially if the plugin were to be extended or modified in the future.  Furthermore, while the number of output operations is small, a significant portion (33%) is not properly escaped, posing a potential risk of cross-site scripting (XSS) vulnerabilities if user-supplied data were to be outputted without sanitization.  The vulnerability history being completely clear of CVEs is a positive sign, suggesting a well-maintained or less complex codebase, but it's important to remember that the absence of past vulnerabilities does not guarantee future security.  In conclusion, while the plugin has a limited attack surface and adheres to good practices in SQL handling, the missing nonce and capability checks, along with the unescaped output, represent the primary areas of concern that warrant attention to improve its overall security.",[178,181,183],{"reason":179,"points":180},"Missing Nonce Checks",5,{"reason":182,"points":180},"Missing Capability Checks",{"reason":184,"points":185},"Unescaped Output Detected",4,"2026-03-17T00:02:50.121Z",{"wat":188,"direct":193},{"assetPaths":189,"generatorPatterns":190,"scriptPaths":191,"versionParams":192},[],[],[],[],{"cssClasses":194,"htmlComments":195,"htmlAttributes":196,"restEndpoints":197,"jsGlobals":198,"shortcodeOutput":199},[],[],[],[],[],[],{"error":201,"url":202,"statusCode":203,"statusMessage":204,"message":204},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fredirect-to-homepage-after-logout\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":60,"versions":206},[207,213,220],{"version":6,"download_url":25,"svn_tag_url":208,"released_at":27,"has_diff":209,"diff_files_changed":210,"diff_lines":27,"trac_diff_url":211,"vulnerabilities":212,"is_current":201},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fredirect-to-homepage-after-logout\u002Ftags\u002F1.0.1\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fredirect-to-homepage-after-logout%2Ftags%2F1.0.0&new_path=%2Fredirect-to-homepage-after-logout%2Ftags%2F1.0.1",[],{"version":214,"download_url":215,"svn_tag_url":216,"released_at":27,"has_diff":209,"diff_files_changed":217,"diff_lines":27,"trac_diff_url":218,"vulnerabilities":219,"is_current":209},"1.0.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fredirect-to-homepage-after-logout.1.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fredirect-to-homepage-after-logout\u002Ftags\u002F1.0.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fredirect-to-homepage-after-logout%2Ftags%2F0.1&new_path=%2Fredirect-to-homepage-after-logout%2Ftags%2F1.0.0",[],{"version":221,"download_url":222,"svn_tag_url":223,"released_at":27,"has_diff":209,"diff_files_changed":224,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":225,"is_current":209},"0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fredirect-to-homepage-after-logout.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fredirect-to-homepage-after-logout\u002Ftags\u002F0.1\u002F",[],[]]