[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzCnGQRqvkw8DcOTVTqVun3Z_PjISnZKdggjPIHmbB50":3,"$fTwzWBkz9cTeVBzqijVnq8jlCCcZIIRYPfrLVVf8RcEY":371,"$fDJwBo8c8yhOsxt5wkiyHtjqpNEdY0nmGi33diKsnQXE":375},{"slug":4,"name":4,"version":5,"author":6,"author_profile":7,"description":8,"short_description":9,"active_installs":10,"downloaded":11,"rating":12,"num_ratings":12,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":16,"download_link":21,"security_score":22,"vuln_count":12,"unpatched_count":12,"last_vuln_date":23,"fetched_at":24,"discovery_status":25,"vulnerabilities":26,"developer":27,"crawl_stats":23,"alternatives":31,"analysis":142,"fingerprints":356},"siteselector","1.01","scideas","https:\u002F\u002Fprofiles.wordpress.org\u002Fscideas\u002F","\u003Cul>\n\u003Cli>Find domain name suggestions based on keywords\u003C\u002Fli>\n\u003Cli>Find out which suggestions are available, registered and in use\u003C\u002Fli>\n\u003Cli>See an image of each possible competitor site found\u003C\u002Fli>\n\u003Cli>Click through to register any suggested domains\u003C\u002Fli>\n\u003Cli>Configure the number of alternatives for each keyword (paid only)\u003C\u002Fli>\n\u003Cli>Edit the suffix list to search for any domain ending (paid only)\u003C\u002Fli>\n\u003Cli>Search in your WP admin\u003C\u002Fli>\n\u003Cli>Make available to your users via a simple shortcode\u003C\u002Fli>\n\u003Cli>siteselector plugin comes with 15 free credits to allow admins to assess it\u003C\u002Fli>\n\u003Cli>When credits reach zero siteselector will continue to work at reduced capacity\u003C\u002Fli>\n\u003Cli>Use the Buy Credits button to purchase credits for your installation using PayPal\u003C\u002Fli>\n\u003Cli>Without credits domain endings cannot be chosen and only one alternative per keyword is used\u003C\u002Fli>\n\u003Cli>After purchase your plugin installation will be automatically credited with your purchase\u003C\u002Fli>\n\u003Cli>Choose from a range of credit amounts: the more you buy the cheaper they are !\u003C\u002Fli>\n\u003Cli>Paid users receive an email reminder when credits are getting low\u003C\u002Fli>\n\u003C\u002Ful>\n","siteselector plugin helps you choose a domain name, check it's availability and see your competition",30,1700,0,"2017-08-09T11:27:00.000Z","4.3.34","3.2","",[18,19,20],"administration","domain-name","web-hosting","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsiteselector.zip",85,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":6,"display_name":6,"profile_url":7,"plugin_count":28,"total_installs":10,"avg_security_score":22,"avg_patch_time_days":10,"trust_score":29,"computed_at":30},1,84,"2026-08-28T20:32:03.172Z",[32,54,77,102,123],{"slug":33,"name":34,"version":35,"author":36,"author_profile":37,"description":38,"short_description":39,"active_installs":40,"downloaded":41,"rating":42,"num_ratings":43,"last_updated":44,"tested_up_to":45,"requires_at_least":46,"requires_php":16,"tags":47,"homepage":49,"download_link":50,"security_score":51,"vuln_count":52,"unpatched_count":12,"last_vuln_date":53,"fetched_at":24},"adminimize","Adminimize","1.11.14","WP Media","https:\u002F\u002Fprofiles.wordpress.org\u002Fwp_media\u002F","\u003Cp>If you manage a multi-author WordPress blog or WordPress sites for clients, then you may have wondered if it was possible to clean up the WordPress admin area for your users? There are lots of things in the WordPress admin area that your users don’t need to see or use. This plugin help you to hide unnecessary items from WordPress admin area.\u003C\u002Fp>\n\u003Cp>Adminimize makes it easy to remove items from view based on a user’s role.\u003C\u002Fp>\n\u003Ch4>What does this plugin do?\u003C\u002Fh4>\n\u003Cp>The plugin changes the administration backend and gives you the power to assign rights on certain parts. Admins can activate\u002Fdeactivate every part of the menu and even parts of the sub-menu. Meta fields can be administered separately for posts and pages. Certain parts of the write menu can be deactivated separately for admins or non-admins. The header of the backend is minimized and optimized to give you more space and the structure of the menu gets changed to make it more logical – this can all be done per user so each role and their resulting users can have his own settings.\u003C\u002Fp>\n\u003Ch4>Support Custom Post Type\u003C\u002Fh4>\n\u003Cp>The plugin support all functions also for custom post types, automatically in the settings page.\u003C\u002Fp>\n\u003Ch4>Support Custom Options on all different post types\u003C\u002Fh4>\n\u003Cp>It is possible to add own options to hide areas in the back-end of WordPress. It is easy and you must only forgive a ID or class, a selector, of the markup, that you will hide.\u003C\u002Fp>\n\u003Ch4>Compatibility with plugins for MetaBoxes in Write-area\u003C\u002Fh4>\n\u003Cp>You can add your own options, you must only check for css selectors.\u003C\u002Fp>\n\u003Ch4>Help with “Your own options”\u003C\u002Fh4>\n\u003Cp>See the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002F328449\" title=\"Plugin: Adminimize Help with Your own options (3 posts)\" rel=\"ugc\">entry on the WP community forum\u003C\u002Fa> for help with this great possibility.\u003C\u002Fp>\n\u003Ch4>License\u003C\u002Fh4>\n\u003Cp>Good news, this plugin is free for everyone! Since it’s released under the GPL, you can use it free of charge on your personal or commercial blog. But if you enjoy this plugin, you can thank me and leave a \u003Ca href=\"http:\u002F\u002Fbueltge.de\u002Fwunschliste\u002F\" title=\"Wishliste and Donate\" rel=\"nofollow ugc\">small donation\u003C\u002Fa> for the time I’ve spent writing and supporting this plugin. And I really don’t want to know how many hours of my life this plugin has already eaten 😉\u003C\u002Fp>\n\u003Ch4>Translations\u003C\u002Fh4>\n\u003Cp>The plugin comes with various translations, please refer to the \u003Ca href=\"https:\u002F\u002Fcodex.wordpress.org\u002FInstalling_WordPress_in_Your_Language\" title=\"Installing WordPress in Your Language\" rel=\"nofollow ugc\">WordPress Codex\u003C\u002Fa> for more information about activating the translation. If you want to help to translate the plugin to your language, please have a look at the sitemap.pot file which contains all definitions and may be used with a \u003Ca href=\"http:\u002F\u002Fwww.gnu.org\u002Fsoftware\u002Fgettext\u002F\" rel=\"nofollow ugc\">gettext\u003C\u002Fa> editor like \u003Ca href=\"http:\u002F\u002Fwww.poedit.net\u002F\" rel=\"nofollow ugc\">Poedit\u003C\u002Fa> (Windows) or use, I prefers this, the \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Fprojects\u002Fwp-plugins\u002Fadminimize\" rel=\"nofollow ugc\">translation service from wordpress.org\u003C\u002Fa>.\u003C\u002Fp>\n","Adminimize that lets you hide 'unnecessary' items from the WordPress backend",200000,3320229,94,254,"2026-06-10T16:17:00.000Z","7.0.2","4.0",[18,48],"customization","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fadminimize\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadminimize.1.11.14.zip",96,3,"2026-05-27 00:00:00",{"slug":55,"name":56,"version":57,"author":58,"author_profile":59,"description":60,"short_description":61,"active_installs":62,"downloaded":63,"rating":64,"num_ratings":65,"last_updated":66,"tested_up_to":45,"requires_at_least":67,"requires_php":68,"tags":69,"homepage":74,"download_link":75,"security_score":76,"vuln_count":12,"unpatched_count":12,"last_vuln_date":23,"fetched_at":24},"remove-dashboard-access-for-non-admins","Remove Dashboard Access","1.3.1","TrustedLogin","https:\u002F\u002Fprofiles.wordpress.org\u002Ftrustedlogin\u002F","\u003Cp>The easiest and safest way to restrict access to your WordPress site’s Dashboard and administrative menus. Remove Dashboard Access is a lightweight plugin that automatically redirects users who shouldn’t have access to the Dashboard to a custom URL of your choosing. Redirects can also be configured on a per-role\u002Fper-capability basis, allowing you to keep certain users out of the Dashboard, while retaining access for others.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Limit Dashboard access to user roles:\n\u003Cul>\n\u003Cli>Admins only\u003C\u002Fli>\n\u003Cli>Admins + editors\u003C\u002Fli>\n\u003Cli>Admins, editors, and authors\u003C\u002Fli>\n\u003Cli>or restrict by specific user capability\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Choose your own redirect URL\u003C\u002Fli>\n\u003Cli>Optionally allow users to edit their profiles\u003C\u002Fli>\n\u003Cli>Display a message on the login screen so users know why they’re being redirected\u003C\u002Fli>\n\u003Cli>Allow specific admin pages through the redirect — paste a list of URLs your customers should still be able to reach (with wildcard support for grouping related pages)\u003C\u002Fli>\n\u003Cli>Optionally extend the block to \u003Ccode>admin-ajax.php\u003C\u002Fcode> requests for stricter lockdown\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Blocking access to the Dashboard is a great way to prevent clients from breaking their sites, prevent users from seeing things they shouldn’t, and to keep your site’s backend more secure.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Allow only users with roles or capabilities:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>You can restrict Dashboard access to Admins only, Editors or above, Authors or above, or by selecting a specific user capability.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Grant access to user profiles:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Optionally allow all users the ability to edit their profiles in the Dashboard. Users lacking the chosen capability won’t be able to access any other sections of the Dashboard.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Show a custom login message:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Supply a message to display on the login screen. Leaving this blank disables the message.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Allow specific admin pages through the redirect:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Sometimes you want to lock down the Dashboard but still let your customers reach one or two specific admin pages — a payment confirmation, a \u003Ca href=\"https:\u002F\u002Fwww.trustedlogin.com\u002F\" rel=\"nofollow ugc\">TrustedLogin\u003C\u002Fa> secret-share screen, a custom report. Paste those URLs into the Allowed URLs box (one per line, relative or absolute), and matching requests will skip the redirect.\u003C\u002Fp>\n\u003Cp>Use \u003Ccode>*\u003C\u002Fcode> as a wildcard inside a query value to match a whole group of pages at once. For example, \u003Ccode>?page=tl-*\u003C\u002Fcode> allows \u003Ccode>tl-secrets\u003C\u002Fcode>, \u003Ccode>tl-config\u003C\u002Fcode>, and any other page whose slug starts with \u003Ccode>tl-\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Optionally block AJAX requests too:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>By default this plugin doesn’t touch requests to \u003Ccode>admin-ajax.php\u003C\u002Fcode> — most WordPress sites rely on those for legitimate frontend AJAX. If you’d rather the dashboard restriction apply there as well, turn on the “Also block AJAX” checkbox in the Advanced section of the settings page.\u003C\u002Fp>\n","Disable Dashboard access for users of a specific role or capability. Disallowed users are redirected to a chosen URL. Get set up in seconds.",30000,500189,92,78,"2026-05-22T19:01:00.000Z","3.1.0","5.3",[70,18,71,72,73],"access","dashboard","login","restrict","https:\u002F\u002Fwww.trustedlogin.com\u002Fremove-dashboard-access\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fremove-dashboard-access-for-non-admins.1.3.1.zip",100,{"slug":78,"name":79,"version":80,"author":81,"author_profile":82,"description":83,"short_description":84,"active_installs":85,"downloaded":86,"rating":87,"num_ratings":88,"last_updated":89,"tested_up_to":90,"requires_at_least":91,"requires_php":92,"tags":93,"homepage":98,"download_link":99,"security_score":100,"vuln_count":28,"unpatched_count":12,"last_vuln_date":101,"fetched_at":24},"error-log-monitor","Error Log Monitor","1.7.12","Janis Elsts","https:\u002F\u002Fprofiles.wordpress.org\u002Fwhiteshadow\u002F","\u003Cp>This plugin adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send you email notifications about newly logged errors.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Automatically detects error log location.\u003C\u002Fli>\n\u003Cli>Explains how to configure PHP error logging if it’s not enabled yet.\u003C\u002Fli>\n\u003Cli>The number of displayed log entries is configurable.\u003C\u002Fli>\n\u003Cli>Sends you email notifications about logged errors (optional).\u003C\u002Fli>\n\u003Cli>Configurable email address and frequency.\u003C\u002Fli>\n\u003Cli>You can easily clear the log file.\u003C\u002Fli>\n\u003Cli>The dashboard widget is only visible to administrators.\u003C\u002Fli>\n\u003Cli>Optimized to work well even with very large log files.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Usage\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Once you’ve installed the plugin, go to the Dashboard and enable the “PHP Error Log” widget through the “Screen Options” panel. The widget should automatically display the last 20 lines from your PHP error log. If you see an error message like “Error logging is disabled” instead, follow the displayed instructions to configure error logging.\u003C\u002Fp>\n\u003Cp>Email notifications are disabled by default. To enable them, click the “Configure” link in the top-right corner of the widget and enter your email address in the “Periodically email logged errors to:” box. If desired, you can also change email frequency by selecting the minimum time interval between emails from the “How often to send email” drop-down.\u003C\u002Fp>\n","Adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send logged errors to email.",20000,641620,86,48,"2025-10-01T15:12:00.000Z","6.8.6","4.5","7.4",[94,18,95,96,97],"admin","dashboard-widget","error-reporting","php","http:\u002F\u002Fw-shadow.com\u002Fblog\u002F2012\u002F07\u002F25\u002Ferror-log-monitor-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ferror-log-monitor.1.7.12.zip",99,"2019-02-25 00:00:00",{"slug":103,"name":104,"version":105,"author":106,"author_profile":107,"description":108,"short_description":109,"active_installs":110,"downloaded":111,"rating":87,"num_ratings":112,"last_updated":113,"tested_up_to":114,"requires_at_least":115,"requires_php":92,"tags":116,"homepage":120,"download_link":121,"security_score":76,"vuln_count":28,"unpatched_count":12,"last_vuln_date":122,"fetched_at":24},"automatic-domain-changer","Automatic Domain Changer","3.0.1","nuagelab","https:\u002F\u002Fprofiles.wordpress.org\u002Fnuagelab\u002F","\u003Cp>This plugin automatically detects a domain name change, and updates all the WordPress tables in the database to reflect this change.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Easily migrate a WordPress site from one domain to another\u003C\u002Fli>\n\u003Cli>Migrate www.domain.com and domain.com at once\u003C\u002Fli>\n\u003Cli>Migrate http and https links at once\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Feedback\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>We are open for your suggestions and feedback – Thank you for using or trying out one of our plugins!\u003C\u002Fli>\n\u003Cli>Drop us a line \u003Ca href=\"http:\u002F\u002Ftwitter.com\u002F#!\u002Fnuagelab\" rel=\"nofollow ugc\">@nuagelab\u003C\u002Fa> on Twitter\u003C\u002Fli>\n\u003Cli>Follow us on \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fpages\u002FNuageLab\u002F150091288388352\" rel=\"nofollow ugc\">our Facebook page\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Drop us a line at \u003Ca href=\"mailto:wordpress-plugins@nuagelab.com\" rel=\"nofollow ugc\">wordpress-plugins@nuagelab.com\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Translations\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>Slovak\u003C\u002Fli>\n\u003C\u002Ful>\n","Automatically detects a domain name change, and updates all the WordPress tables in the database to reflect this change.",10000,175112,29,"2026-05-08T04:01:00.000Z","6.9.5","5.0",[94,18,117,118,119],"domain-change","links","migration","http:\u002F\u002Fwww.nuagelab.com\u002Fwordpress-plugins\u002Fauto-domain-change","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fautomatic-domain-changer.3.0.1.zip","2022-05-31 00:00:00",{"slug":124,"name":125,"version":126,"author":127,"author_profile":128,"description":129,"short_description":130,"active_installs":131,"downloaded":132,"rating":51,"num_ratings":133,"last_updated":134,"tested_up_to":90,"requires_at_least":135,"requires_php":16,"tags":136,"homepage":140,"download_link":141,"security_score":64,"vuln_count":12,"unpatched_count":12,"last_vuln_date":23,"fetched_at":24},"wpcore","WPCore Plugin Manager","1.9.2","stueynet","https:\u002F\u002Fprofiles.wordpress.org\u002Fstueynet\u002F","\u003Cp>WPCore is a tool that allows you to manage collections of WordPress plugins and then quickly install them on any WordPress site. You can generate your collections at https:\u002F\u002Fwpcore.com and then import them to your WordPress site by copying and pasting your unique collection key in WordPress.\u003C\u002Fp>\n","Create plugin collections and install them in one click on any WordPress site.",9000,170856,32,"2025-05-20T17:15:00.000Z","3.5",[94,18,137,138,139],"install","installation","plugins","https:\u002F\u002Fwpcore.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpcore.1.9.2.zip",{"attackSurface":143,"codeSignals":193,"taintFlows":275,"riskAssessment":339,"analyzedAt":355},{"hooks":144,"ajaxHandlers":167,"restRoutes":185,"shortcodes":186,"cronEvents":190,"entryPointCount":191,"unprotectedCount":192},[145,151,154,158,162],{"type":146,"name":147,"callback":148,"file":149,"line":150},"action","admin_init","siteselector_load_plugin","siteselector_functions.php",60,{"type":146,"name":152,"callback":148,"file":149,"line":153},"init",61,{"type":146,"name":155,"callback":156,"file":149,"line":157},"admin_menu","siteselector_admin_actions",79,{"type":146,"name":159,"callback":160,"file":149,"line":161},"admin_head","hide_wordpress_thankyou",554,{"type":146,"name":163,"callback":164,"priority":165,"file":149,"line":166},"wp_footer","siteselector_script",200,555,[168,173,175,178,180,183],{"action":169,"nopriv":170,"callback":169,"hasNonce":171,"hasCapCheck":171,"file":149,"line":172},"siteselector_ajax_initialize",true,false,139,{"action":169,"nopriv":171,"callback":169,"hasNonce":171,"hasCapCheck":171,"file":149,"line":174},140,{"action":176,"nopriv":170,"callback":176,"hasNonce":171,"hasCapCheck":171,"file":149,"line":177},"siteselector_find_names",149,{"action":176,"nopriv":171,"callback":176,"hasNonce":171,"hasCapCheck":171,"file":149,"line":179},150,{"action":181,"nopriv":170,"callback":181,"hasNonce":171,"hasCapCheck":171,"file":149,"line":182},"siteselector_check_url",176,{"action":181,"nopriv":171,"callback":181,"hasNonce":171,"hasCapCheck":171,"file":149,"line":184},177,[],[187],{"tag":4,"callback":188,"file":149,"line":189},"siteselector_shortcode",207,[],7,6,{"dangerousFunctions":194,"sqlUsage":195,"outputEscaping":215,"fileOperations":273,"externalRequests":28,"nonceChecks":12,"capabilityChecks":12,"bundledLibraries":274},[],{"prepared":196,"raw":191,"locations":197},5,[198,202,204,206,208,210,212],{"file":199,"line":200,"context":201},"siteselector_config.php",21,"$wpdb->get_results() with variable interpolation",{"file":149,"line":29,"context":203},"$wpdb->query() with variable interpolation",{"file":149,"line":205,"context":203},111,{"file":149,"line":207,"context":201},153,{"file":149,"line":209,"context":203},168,{"file":149,"line":211,"context":201},214,{"file":213,"line":214,"context":201},"siteselector_search.php",25,{"escaped":28,"rawEcho":216,"locations":217},31,[218,221,223,225,227,229,230,232,233,235,237,238,240,242,244,246,248,250,251,253,254,256,258,259,260,262,264,266,267,269,271],{"file":199,"line":219,"context":220},38,"raw output",{"file":199,"line":222,"context":220},41,{"file":199,"line":224,"context":220},125,{"file":199,"line":226,"context":220},126,{"file":199,"line":228,"context":220},127,{"file":199,"line":228,"context":220},{"file":199,"line":231,"context":220},144,{"file":199,"line":177,"context":220},{"file":199,"line":234,"context":220},154,{"file":199,"line":236,"context":220},179,{"file":199,"line":236,"context":220},{"file":149,"line":239,"context":220},142,{"file":149,"line":241,"context":220},172,{"file":149,"line":243,"context":220},186,{"file":149,"line":245,"context":220},307,{"file":149,"line":247,"context":220},344,{"file":149,"line":249,"context":220},412,{"file":213,"line":219,"context":220},{"file":213,"line":252,"context":220},103,{"file":213,"line":184,"context":220},{"file":213,"line":255,"context":220},305,{"file":213,"line":257,"context":220},306,{"file":213,"line":245,"context":220},{"file":213,"line":245,"context":220},{"file":213,"line":261,"context":220},326,{"file":213,"line":263,"context":220},394,{"file":213,"line":265,"context":220},402,{"file":213,"line":265,"context":220},{"file":213,"line":268,"context":220},424,{"file":213,"line":270,"context":220},430,{"file":213,"line":272,"context":220},461,2,[],[276,301,313,326],{"entryPoint":277,"graph":278,"unsanitizedCount":273,"severity":300},"siteselector_find_names (siteselector_functions.php:151)",{"nodes":279,"edges":297},[280,285,291,293],{"id":281,"type":282,"label":283,"file":149,"line":284},"n0","source","$_POST",159,{"id":286,"type":287,"label":288,"file":149,"line":289,"wp_function":290},"n1","sink","file_get_contents() [SSRF\u002FLFI]",164,"file_get_contents",{"id":292,"type":282,"label":283,"file":149,"line":284},"n2",{"id":294,"type":287,"label":295,"file":149,"line":241,"wp_function":296},"n3","echo() [XSS]","echo",[298,299],{"from":281,"to":286,"sanitized":171},{"from":292,"to":294,"sanitized":171},"medium",{"entryPoint":302,"graph":303,"unsanitizedCount":273,"severity":300},"siteselector_check_url (siteselector_functions.php:178)",{"nodes":304,"edges":310},[305,306,308,309],{"id":281,"type":282,"label":283,"file":149,"line":236},{"id":286,"type":287,"label":288,"file":149,"line":307,"wp_function":290},184,{"id":292,"type":282,"label":283,"file":149,"line":236},{"id":294,"type":287,"label":295,"file":149,"line":243,"wp_function":296},[311,312],{"from":281,"to":286,"sanitized":171},{"from":292,"to":294,"sanitized":171},{"entryPoint":314,"graph":315,"unsanitizedCount":325,"severity":300},"\u003Csiteselector_functions> (siteselector_functions.php:0)",{"nodes":316,"edges":322},[317,319,320,321],{"id":281,"type":282,"label":318,"file":149,"line":284},"$_POST (x2)",{"id":286,"type":287,"label":288,"file":149,"line":289,"wp_function":290},{"id":292,"type":282,"label":318,"file":149,"line":284},{"id":294,"type":287,"label":295,"file":149,"line":241,"wp_function":296},[323,324],{"from":281,"to":286,"sanitized":171},{"from":292,"to":294,"sanitized":171},4,{"entryPoint":327,"graph":328,"unsanitizedCount":12,"severity":338},"\u003Csiteselector_config> (siteselector_config.php:0)",{"nodes":329,"edges":336},[330,332],{"id":281,"type":282,"label":283,"file":199,"line":331},10,{"id":286,"type":287,"label":333,"file":199,"line":334,"wp_function":335},"query() [SQLi]",13,"query",[337],{"from":281,"to":286,"sanitized":170},"low",{"summary":340,"deductions":341},"The \"siteselector\" plugin v1.01 exhibits several significant security concerns, primarily stemming from a large unprotected attack surface and poor output sanitization. While the plugin does not appear to have a history of known vulnerabilities (CVEs), this does not inherently mean it is secure. The static analysis reveals 6 out of 7 entry points are unprotected, with 6 AJAX handlers lacking authentication checks. This creates a substantial risk for unauthorized actions to be performed on a WordPress site. Furthermore, a very low percentage (3%) of output is properly escaped, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities across the plugin's output.",[342,344,347,349,351,353],{"reason":343,"points":331},"Unprotected AJAX handlers",{"reason":345,"points":346},"Low output escaping percentage",8,{"reason":348,"points":331},"No nonce checks on entry points",{"reason":350,"points":331},"No capability checks on entry points",{"reason":352,"points":346},"Unsanitized paths in taint flows",{"reason":354,"points":325},"SQL queries not always prepared","2026-03-16T22:39:15.648Z",{"wat":357,"direct":363},{"assetPaths":358,"generatorPatterns":360,"scriptPaths":361,"versionParams":362},[359],"\u002Fwp-content\u002Fplugins\u002Fsiteselector\u002Fsiteselector_plugin.js",[],[359],[],{"cssClasses":364,"htmlComments":365,"htmlAttributes":366,"restEndpoints":367,"jsGlobals":368,"shortcodeOutput":370},[],[],[],[],[369],"siteselector_URL",[],{"error":170,"url":372,"statusCode":373,"statusMessage":374,"message":374},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fsiteselector\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":5,"total_versions":12,"versions":376},[]]