[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2yLHNyYxOi_WdvcrWSZ80r1M5yC_A7Fb1ZDIsd_-NuY":3,"$f04Ht4tzj5FttQBT4efcl8SHJ5is6Y-CcUQz6wFuK_PM":187,"$fySoXV0RdIA6DcpQVdT33AhH7EWIV-zawAGNUDUudZFw":191},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":22,"download_link":23,"security_score":24,"vuln_count":25,"unpatched_count":25,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":34,"analysis":35,"fingerprints":168},"showguests","Showguests","1.02","tiandi","https:\u002F\u002Fprofiles.wordpress.org\u002Ftiandi\u002F","\u003Cp>Description: Showguests is a plugin for showing the newest quests on your blog. Please visit http:\u002F\u002Fwww.tiandiyoyo.com for more information.\u003C\u002Fp>\n","Showguests is a plugin for showing the newest quests on your blog.",10,2715,100,1,"2013-09-12T04:00:00.000Z","4.0.38","3.2","",[20,21],"newest-guests","recently-guests","http:\u002F\u002Fwww.tiandiyoyo.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fshowguests.1.02.zip",85,0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":14,"total_installs":11,"avg_security_score":24,"avg_patch_time_days":31,"trust_score":32,"computed_at":33},30,84,"2026-08-29T09:43:23.434Z",[],{"attackSurface":36,"codeSignals":65,"taintFlows":96,"riskAssessment":153,"analyzedAt":167},{"hooks":37,"ajaxHandlers":53,"restRoutes":54,"shortcodes":55,"cronEvents":63,"entryPointCount":64,"unprotectedCount":25},[38,45,49],{"type":39,"name":40,"callback":41,"priority":42,"file":43,"line":44},"action","wp_footer","Showguests_check_guests_info",99,"showguests.php",150,{"type":39,"name":46,"callback":47,"file":43,"line":48},"admin_menu","showguests_admin_actions",152,{"type":39,"name":50,"callback":51,"file":43,"line":52},"widgets_init","showguestsinit",153,[],[],[56,59],{"tag":57,"callback":41,"file":43,"line":58},"sgcheck",139,{"tag":60,"callback":61,"file":43,"line":62},"sgshow","Showguests_show_guests_info",140,[],2,{"dangerousFunctions":66,"sqlUsage":67,"outputEscaping":72,"fileOperations":25,"externalRequests":25,"nonceChecks":64,"capabilityChecks":25,"bundledLibraries":95},[],{"prepared":25,"raw":14,"locations":68},[69],{"file":43,"line":70,"context":71},53,"$wpdb->get_results() with variable interpolation",{"escaped":25,"rawEcho":11,"locations":73},[74,77,79,81,83,85,87,89,91,93],{"file":43,"line":75,"context":76},22,"raw output",{"file":43,"line":78,"context":76},26,{"file":43,"line":80,"context":76},32,{"file":43,"line":82,"context":76},36,{"file":43,"line":84,"context":76},95,{"file":43,"line":86,"context":76},113,{"file":43,"line":88,"context":76},114,{"file":43,"line":90,"context":76},119,{"file":43,"line":92,"context":76},134,{"file":43,"line":94,"context":76},135,[],[97,123,143],{"entryPoint":98,"graph":99,"unsanitizedCount":25,"severity":122},"Showguestspanel (showguests.php:11)",{"nodes":100,"edges":118},[101,106,112,114],{"id":102,"type":103,"label":104,"file":43,"line":105},"n0","source","$_POST (x2)",19,{"id":107,"type":108,"label":109,"file":43,"line":110,"wp_function":111},"n1","sink","update_option() [Settings Manipulation]",21,"update_option",{"id":113,"type":103,"label":104,"file":43,"line":105},"n2",{"id":115,"type":108,"label":116,"file":43,"line":75,"wp_function":117},"n3","echo() [XSS]","echo",[119,121],{"from":102,"to":107,"sanitized":120},true,{"from":113,"to":115,"sanitized":120},"low",{"entryPoint":124,"graph":125,"unsanitizedCount":25,"severity":122},"\u003Cshowguests> (showguests.php:0)",{"nodes":126,"edges":139},[127,128,129,130,131,135],{"id":102,"type":103,"label":104,"file":43,"line":105},{"id":107,"type":108,"label":109,"file":43,"line":110,"wp_function":111},{"id":113,"type":103,"label":104,"file":43,"line":105},{"id":115,"type":108,"label":116,"file":43,"line":75,"wp_function":117},{"id":132,"type":103,"label":133,"file":43,"line":134},"n4","$_COOKIE",48,{"id":136,"type":108,"label":137,"file":43,"line":70,"wp_function":138},"n5","get_results() [SQLi]","get_results",[140,141,142],{"from":102,"to":107,"sanitized":120},{"from":113,"to":115,"sanitized":120},{"from":132,"to":136,"sanitized":120},{"entryPoint":144,"graph":145,"unsanitizedCount":14,"severity":152},"Showguests_check_guests_info (showguests.php:46)",{"nodes":146,"edges":149},[147,148],{"id":102,"type":103,"label":133,"file":43,"line":134},{"id":107,"type":108,"label":137,"file":43,"line":70,"wp_function":138},[150],{"from":102,"to":107,"sanitized":151},false,"high",{"summary":154,"deductions":155},"The \"showguests\" plugin version 1.02 exhibits a mixed security posture. While it has a relatively small attack surface with no AJAX handlers or REST API routes, and all entry points appear to have nonce checks, significant concerns arise from its code analysis.  The complete lack of prepared statements for SQL queries and the zero percent of properly escaped output are critical weaknesses.  This means sensitive data handled by the plugin is vulnerable to injection attacks and can be exposed to users in an unescaped manner, potentially leading to cross-site scripting (XSS) vulnerabilities. The taint analysis confirms a high severity flow with unsanitized paths, further underscoring these risks.\n\nThe plugin's vulnerability history is currently clean, with no recorded CVEs. This suggests either good past development practices or simply a lack of historical scrutiny. However, the presence of critical security flaws in the current code analysis, particularly around SQL and output handling, indicates that relying solely on the absence of past vulnerabilities is insufficient.  The plugin's strengths lie in its limited attack surface and the presence of nonce checks. Nevertheless, the identified code-level vulnerabilities present a substantial risk that requires immediate attention, outweighing the positive aspects of its history and attack surface.",[156,158,161,164],{"reason":157,"points":11},"Raw SQL queries without prepared statements",{"reason":159,"points":160},"Unescaped output to the browser",8,{"reason":162,"points":163},"High severity taint flow with unsanitized path",12,{"reason":165,"points":166},"No capability checks on entry points",5,"2026-03-16T23:17:32.072Z",{"wat":169,"direct":175},{"assetPaths":170,"generatorPatterns":172,"scriptPaths":173,"versionParams":174},[171],"\u002Fwp-content\u002Fplugins\u002Fshowguests\u002Fmy.css",[],[],[],{"cssClasses":176,"htmlComments":178,"htmlAttributes":179,"restEndpoints":182,"jsGlobals":183,"shortcodeOutput":184},[4,177],"showguestscss",[],[180,181],"showguestcounts","showguestmyname",[],[],[185,186],"\u003Cdiv class = 'showguests' >","\u003Cdiv class = 'showguestscss'>",{"error":120,"url":188,"statusCode":189,"statusMessage":190,"message":190},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fshowguests\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":192,"versions":193},3,[194,199,206],{"version":6,"download_url":23,"svn_tag_url":195,"released_at":26,"has_diff":151,"diff_files_changed":196,"diff_lines":26,"trac_diff_url":197,"vulnerabilities":198,"is_current":120},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fshowguests\u002Ftags\u002F1.02\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fshowguests%2Ftags%2F1.01&new_path=%2Fshowguests%2Ftags%2F1.02",[],{"version":200,"download_url":201,"svn_tag_url":202,"released_at":26,"has_diff":151,"diff_files_changed":203,"diff_lines":26,"trac_diff_url":204,"vulnerabilities":205,"is_current":151},"1.01","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fshowguests.1.01.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fshowguests\u002Ftags\u002F1.01\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fshowguests%2Ftags%2F1.0&new_path=%2Fshowguests%2Ftags%2F1.01",[],{"version":207,"download_url":208,"svn_tag_url":209,"released_at":26,"has_diff":151,"diff_files_changed":210,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":211,"is_current":151},"1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fshowguests.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fshowguests\u002Ftags\u002F1.0\u002F",[],[]]