[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgXQTDtTIjtqEu9ZJYG5SoxgfTpkO_ckw1NZM2mGHcw8":3,"$ff9OZlMJwjx6tEYd2dKUECMxuYZ3UdpUYkh_iJv85JS4":322,"$fiImpbSEi1CxH7NyQn7FPekoF2HoobrCi0MB3yoodleM":326},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":7,"tags":17,"homepage":21,"download_link":22,"security_score":23,"vuln_count":13,"unpatched_count":13,"last_vuln_date":24,"fetched_at":25,"discovery_status":26,"vulnerabilities":27,"developer":28,"crawl_stats":24,"alternatives":35,"analysis":135,"fingerprints":301},"sl-tools","SL Tools","1.0","","https:\u002F\u002Fprofiles.wordpress.org\u002Fpaulreitz\u002F","\u003Cp>SL Tools provides a set of tools for Second Life bloggers.  The current version includes the following features:\u003Cbr \u002F>\n* SLURL shortcode to quickly include Second Life locations in you posts and pages.\u003Cbr \u002F>\n* SLURL widget to place your favorite locations in a dynamic sidebar.\u003Cbr \u002F>\n* LSL syntax highlighter – code can be entered inline or imported from a file.\u003C\u002Fp>\n\u003Cp>An inworld SLURL shortcode HUD is available from xstreetsl or MVX;\u003Cbr \u002F>\nxstreetsl: https:\u002F\u002Fwww.xstreetsl.com\u002Fmodules.php?name=Marketplace&file=item&ItemID=2514275\u003Cbr \u002F>\nMVX: http:\u002F\u002Fmetaverseexchange.com\u002Flisting.php?id=11053\u003C\u002Fp>\n\u003Cp>For more information: http:\u002F\u002Fwww.reitzdesigns.com\u002F2010\u002F07\u002Fsecond-life-tools-wordpress-plugin\u002F\u003C\u002Fp>\n","A set of tools to make life easier for Second Life bloggers.  Includes a SLURL shortcode and syntax highlighting for LSL.",10,1995,0,"2010-08-20T14:59:00.000Z","3.0.5","2.8.0",[18,19,20],"lsl","second-life","slurl","http:\u002F\u002Fwww.reitzdesigns.com\u002F2010\u002F07\u002Fsecond-life-tools-wordpress-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsl-tools.zip",85,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":29,"display_name":29,"profile_url":8,"plugin_count":30,"total_installs":31,"avg_security_score":23,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},"paulreitz",3,40,30,84,"2026-08-29T07:39:09.652Z",[36,57,76,97,118],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":46,"num_ratings":47,"last_updated":48,"tested_up_to":49,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":54,"download_link":55,"security_score":46,"vuln_count":13,"unpatched_count":13,"last_vuln_date":24,"fetched_at":56},"open-links-in-sl","Open Links in SL","0.10.1","Code Rocket Studios, LLC","https:\u002F\u002Fprofiles.wordpress.org\u002Fcoderocketstudios\u002F","\u003Cp>Have your links to Second Life&copy; locations, groups, and profiles open in SL from your website.\u003C\u002Fp>\n\u003Cp>This plugin is intended as an aid for websites which are created and managed by Second Life&copy; residents. There are many websites like this, and often these community owners run into confusion on how to link their website content (text, images, etc) to the relevant content inside the Second Life&copy; virtual world.\u003C\u002Fp>\n\u003Ch3>How to use\u003C\u002Fh3>\n\u003Cp>Simply activate plugin to use. Your published website links to \u003Ccode>maps.secondlife.com\u003C\u002Fcode> plus \u003Ccode>world.secondlife.com\u003C\u002Fcode> will automatically open inside of your Second Life&copy; viewer on click.\u003C\u002Fp>\n\u003Ch4>Example\u003C\u002Fh4>\n\u003Cp>When you open a profile window in Second Life, you can find the user’s key and also “copy URI”. You will then get something like this:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>secondlife:\u002F\u002F\u002Fapp\u002Fagent\u002F63c3809f-6fe2-4151-aa8d-ab3ce169f01a\u002Fabout\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Take the key such as \u003Ccode>63c3809f-6fe2-4151-aa8d-ab3ce169f01a\u003C\u002Fcode> and put it in this format instead to make a link to it from the web:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>http:\u002F\u002Fworld.secondlife.com\u002Fresident\u002F63c3809f-6fe2-4151-aa8d-ab3ce169f01a\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Example URL to a location within Second Life:\u003Cbr \u002F>\n    http:\u002F\u002Fmaps.secondlife.com\u002Fsecondlife\u002FSerena%20Pisces\u002F213\u002F132\u002F23\u003C\u002Fp>\n\u003Cp>Example URL to a group within Second Life:\u003Cbr \u002F>\n    https:\u002F\u002Fworld.secondlife.com\u002Fgroup\u002Fd7a76a13-68d0-553f-76b3-851a9a07919f\u003C\u002Fp>\n\u003Cp>\u003Cstrong>You still need to make sure these links are set up correctly on your website.\u003C\u002Fstrong> In the future this plugin may be released with helper tools to create these links properly, but this is not yet a feature.\u003C\u002Fp>\n","Have your links to Second Life&copy; locations, groups, and profiles (maps.secondlife.com and world.secondlife.com) open in SL from your website.",20,1726,100,2,"2026-01-20T17:49:00.000Z","6.9.4","5.0","7.0",[19,20,53],"virtual-world","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fopen-links-in-sl\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fopen-links-in-sl.0.10.1.zip","2026-04-16T10:56:18.058Z",{"slug":58,"name":59,"version":60,"author":61,"author_profile":62,"description":63,"short_description":64,"active_installs":11,"downloaded":65,"rating":13,"num_ratings":13,"last_updated":66,"tested_up_to":67,"requires_at_least":68,"requires_php":7,"tags":69,"homepage":74,"download_link":75,"security_score":23,"vuln_count":13,"unpatched_count":13,"last_vuln_date":24,"fetched_at":56},"sl-map","SL Map","0.1.1","signpostmarv","https:\u002F\u002Fprofiles.wordpress.org\u002Fsignpostmarv\u002F","\u003Cp>SL-Map uses an asynchronous wrapper to the slurl.com API to allow JavaScript to rapidly process all second life links (SLURLs) and append the region image to the link.\u003C\u002Fp>\n\u003Cp>This plugin is a proof of concept for how a JSON-only API combined with cross-domain XHR has more wide-ranging applications than the current slurl.com API.\u003C\u002Fp>\n","Embed Second Life Maps in your blog posts!",1996,"2010-04-10T17:02:00.000Z","2.9.2","2.8",[70,71,72,19,73,20],"embed","map","region","sl","http:\u002F\u002Fsignpostmarv.name\u002Fsl-map\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsl-map.0.1.1.zip",{"slug":77,"name":78,"version":6,"author":79,"author_profile":80,"description":81,"short_description":82,"active_installs":83,"downloaded":84,"rating":46,"num_ratings":85,"last_updated":86,"tested_up_to":87,"requires_at_least":88,"requires_php":7,"tags":89,"homepage":95,"download_link":96,"security_score":23,"vuln_count":13,"unpatched_count":13,"last_vuln_date":24,"fetched_at":25},"seo-sitemap-generator-with-fetch-urls","SEO Sitemap Generator with fetch urls","vwediting","https:\u002F\u002Fprofiles.wordpress.org\u002Fvwediting\u002F","\u003Cp>Generate google xml sitemap and webmaster tools fetch urls automatically. Improve your website SEO ranking in few steps.\u003C\u002Fp>\n\u003Cp>1) submit your http:\u002F\u002Fyoursiteurl\u002Fsitmape.xml in webmaster tools.\u003C\u002Fp>\n\u003Cp>2) copy all website urls from http:\u002F\u002Fyoursiteurl\u002Furlslist.xml\u003C\u002Fp>\n\u003Cp>3) paste urls in wordpad and fetch them easily in webmaster tools. Your urls will starts showing in 15 minutes in google.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"http:\u002F\u002Fvashikaranspecialist.xyz\u002F\" rel=\"nofollow ugc\">www.vashikaranspecialist.xyz\u003C\u002Fa>\u003C\u002Fp>\n","Automatic generate xml sitemap for search engine and fetch urls in webmaster tools",200,8605,1,"2016-09-18T11:15:00.000Z","4.3.34","3.0.1",[90,91,92,93,94],"automatic-webmaster-fetch-urlslist","sitemap","webmaster-fetch-url-generator","xml-site-map","xml-sitemap","http:\u002F\u002Fwww.vashikaran.biz\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fseo-sitemap-generator-with-fetch-urls.zip",{"slug":98,"name":99,"version":68,"author":100,"author_profile":101,"description":102,"short_description":103,"active_installs":44,"downloaded":104,"rating":46,"num_ratings":105,"last_updated":106,"tested_up_to":107,"requires_at_least":108,"requires_php":109,"tags":110,"homepage":115,"download_link":116,"security_score":117,"vuln_count":13,"unpatched_count":13,"last_vuln_date":24,"fetched_at":25},"w4os-opensimulator-web-interface","w4os – OpenSimulator Web Interface","Olivier van Helden","https:\u002F\u002Fprofiles.wordpress.org\u002Fmagicoli69\u002F","\u003Cp>Ready to use WordPress interface for \u003Ca href=\"http:\u002F\u002Fopensimulator.org\u002F\" rel=\"nofollow ugc\">OpenSimulator\u003C\u002Fa>. Provides user registration, default avatar model choice, login info, statistics and a web assets server for grids or standalone simulators.\u003C\u002Fp>\n\u003Cp>Full installation instructions: (https:\u002F\u002Fgudulelapointe.github.io\u002Fw4os\u002FINSTALLATION.html)\u003C\u002Fp>\n\u003Cp>See Features and Roadmap sections for current and upcoming functionalties.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Avatar creation\u003C\u002Fstrong>:\n\u003Cul>\n\u003Cli>Opensimulator section in standard wp account page\u003C\u002Fli>\n\u003Cli>Avatar tab in account dashboard on WooCommerce websites\u003C\u002Fli>\n\u003Cli>Avatar and website passwords are synchronized\u003C\u002Fli>\n\u003Cli>Configuration instructions for new avatars\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Public avatar profile\u003C\u002Fstrong>: excerpt of the avatar’s profile\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Avatar Models\u003C\u002Fstrong>: default outfits to choose from on registration\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reserved names\u003C\u002Fstrong>: avatar whose first name or last name is “Default”, “Test”, “Admin” or the pattern used for appearance models are disallowed for public (such avatars must be created by admins from Robust console)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Search Engine\u003C\u002Fstrong>: enable in-world search\n\u003Cul>\n\u003Cli>\u003Cstrong>places\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>land for sale\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>classifieds\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>events\u003C\u002Fstrong> (2do.directory integration)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Shortcodes\n\u003Cul>\n\u003Cli>\u003Cstrong>Grid info\u003C\u002Fstrong>: \u003Ccode>[grid-info]\u003C\u002Fcode> shortcode, Gutenberg block and Divi module\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Grid status\u003C\u002Fstrong>: \u003Ccode>[grid-status]\u003C\u002Fcode> shortcode, Gutenberg block and Divi module\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Grid status\u003C\u002Fstrong>: \u003Ccode>[popular-places]\u003C\u002Fcode> shortcode, Gutenberg block and Divi module\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Profile page\u003C\u002Fstrong>: \u003Ccode>[avatar-profile]\u003C\u002Fcode>  shortcode, Gutenberg block and Divi module\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Web assets server\u003C\u002Fstrong>: the needed bridge to display in-world images on a website\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Currency helpers\u003C\u002Fstrong>: integration with Podex, Gloebit and core money module\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Offline messages e-mail forwarding\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Manual and cron Grid\u002FWP users sync\u003C\u002Fli>\n\u003Cli>Auth with avatar credentials (if no matching wp account, create one)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Paid version\u003C\u002Fh4>\n\u003Cp>The free version from WordPress plugins directory and the \u003Ca href=\"https:\u002F\u002Fmagiiic.com\u002Fwordpress\u002Fplugins\u002Fw4os\u002F\" rel=\"nofollow ugc\">paid version\u003C\u002Fa> are technically the same. The only difference is the way you support this plugin developement: with the free version, you join the community experience (please rate and comment), while the paid version helps us to dedicate resources to this project.\u003C\u002Fp>\n\u003Ch3>Requirements\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>OpenSimulator 0.9.x (0.9.2.2 recommended). 0.8.x and earlier version might work and used to, but are definitely not supported anymore\u003C\u002Fli>\n\u003Cli>Latest WordPdress release\u003C\u002Fli>\n\u003Cli>PHP 8.x or later (8.2 recommended), and the PHP extensions recommended by WordPress (particularly xmlrpc, curl and ImageMagick )\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Troubleshooting\u003C\u002Fh3>\n\u003Cp>See \u003Ca href=\"https:\u002F\u002Fgudulelapointe.github.io\u002Fw4os\u002FTROUBLESHOOTING.html\" rel=\"nofollow ugc\">TROUBLESHOOTING.md\u003C\u002Fa> for more information.\u003C\u002Fp>\n\u003Ch3>Roadmap\u003C\u002Fh3>\n\u003Cp>See \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FGuduleLapointe\u002Fw4os\u002F\" rel=\"nofollow ugc\">github.com\u002FGuduleLapointe\u002Fw4os\u003C\u002Fa> for complete status and changelog.\u003C\u002Fp>\n\u003Ch4>Medium term\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Destinations guide\u003C\u002Fli>\n\u003Cli>Web search\u003C\u002Fli>\n\u003Cli>Multiple avatars for same WordPress user\u003C\u002Fli>\n\u003Cli>Improve avatar profile\n\u003Cul>\n\u003Cli>Switch to allow web profile\u003C\u002Fli>\n\u003Cli>Better basic layout\u003C\u002Fli>\n\u003Cli>Web edit profile\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>2do HYPEvents project integration \u003Ca href=\"https:\u002F\u002F2do.pm\" rel=\"nofollow ugc\">https:\u002F\u002F2do.pm\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Gudz Teleport Board project integration (based on user picks)\u003C\u002Fli>\n\u003Cli>Admin Use sim\u002Fgrid configuration file to fetch settings if on the same host\u003C\u002Fli>\n\u003Cli>Admin create users\u003C\u002Fli>\n\u003Cli>Admin create models (from current own avatar appearance)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Long term\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Robust console connection\n\u003Cul>\n\u003Cli>Admin Start \u002F Stop regions\u003C\u002Fli>\n\u003Cli>Admin Create region\u003C\u002Fli>\n\u003Cli>User’s own regions control (create, start, stop, backup)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>WooCommerce integration\n\u003Cul>\n\u003Cli>paid accounts\u003C\u002Fli>\n\u003Cli>regions orders\u003C\u002Fli>\n\u003Cli>other pay-for services\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Deactivate (recommended) or delete (experimental) grid user when deleting wp account\u003C\u002Fli>\n\u003Cli>Split code between OpenSimulator and WordPress specific codes\u003C\u002Fli>\n\u003C\u002Ful>\n","WordPress interface for OpenSimulator (w4os)",4135,5,"2024-10-28T18:33:00.000Z","6.7.5","5.3.0","7.3",[111,112,19,113,114],"hypergrid","opensimulator","standalone","web-interface","https:\u002F\u002Fw4os.org\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fw4os-opensimulator-web-interface.2.8.zip",92,{"slug":119,"name":120,"version":121,"author":122,"author_profile":123,"description":124,"short_description":125,"active_installs":11,"downloaded":126,"rating":46,"num_ratings":85,"last_updated":127,"tested_up_to":128,"requires_at_least":50,"requires_php":109,"tags":129,"homepage":133,"download_link":134,"security_score":23,"vuln_count":13,"unpatched_count":13,"last_vuln_date":24,"fetched_at":25},"online-status-insl","Online Status inSL","1.6.3","Gwyneth Llewelyn","https:\u002F\u002Fprofiles.wordpress.org\u002Fgwynethllewelyn\u002F","\u003Cp>This simple plugin with associated widget allows you to show your online status in Second Life® or any OpenSimulator grid.\u003C\u002Fp>\n\u003Cp>It also includes a LSL script to place inside an in-world script, which is available from the Settings menu.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Warning\u003C\u002Fstrong>: Versions 1.3.X and above are utterly incompatible with previous versions; you will need to add the new script to all your in-world scripted objects or your blog will not display the status at all!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Warning\u003C\u002Fstrong>: Version 1.3.8 and above might make it impossible for you to delete old tracking objects. 1.4.0 adds a way to delete all of the tracking objects, but there have been plenty of changes that this simply might not work any longer.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Note\u003C\u002Fstrong>: Versions before 1.6.0 are so old that I have deleted them from the WordPress repository.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FGwynethLlewelyn\u002Fonline-status-insl\u002Factions\u002Fworkflows\u002Fcodeql-analysis.yml\" rel=\"nofollow ugc\">\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.codacy.com\u002Fgh\u002FGwynethLlewelyn\u002Fonline-status-insl\u002Fdashboard?utm_source=github.com&utm_medium=referral&utm_content=GwynethLlewelyn\u002Fonline-status-insl&utm_campaign=Badge_Grade\" rel=\"nofollow ugc\">\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>CSS\u003C\u002Fh3>\n\u003Cp>To allow styling of the plugin, the following styles are emitted by the widget:\u003C\u002Fp>\n\u003Cp>The whole content of the widget is included inside a \u003Ccode>\u003Cdiv class='osinsl'>\u003C\u002Fcode>\u003C\u002Fp>\n\u003Cp>The text before the status is a \u003Ccode>span\u003C\u002Fcode> with class \u003Ccode>osinsl-before-status\u003C\u002Fcode>. The status itself is \u003Ccode>osinsl-status\u003C\u002Fcode> and the text afterwards is \u003Ccode>osinsl-after-status\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cem>Status unknown\u003C\u002Fem> (i.e. SL dataserver issues) is styled as \u003Ccode>osinsl-problems\u003C\u002Fcode> and the text for an unconfigured widget is styled \u003Ccode>osinsl-unconfigured\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>The profile picture (if visible) will have the class \u003Ccode>osinsl-profile-picture\u003C\u002Fcode>. Users can set the horizontal alignment (using the standard \u003Cem>alignleft\u003C\u002Fem>, \u003Cem>aligncenter\u003C\u002Fem>, \u003Cem>alignright\u003C\u002Fem> classes) but nothing else. Size is limited to 80×80 (all this might be changed).\u003C\u002Fp>\n\u003Cp>To style embedded shortcode, change the CSS class for \u003Ccode>osinsl-shortcode\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch3>Shortcodes\u003C\u002Fh3>\n\u003Cp>1.2 and onwards support shortcodes, to embed online status and SL profile pictures inside posts and pages.\u003C\u002Fp>\n\u003Cp>The overall syntax is:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>[osinsl avatar=\"\u003Cavatar name>\" picture=\"[none|center|right|left]\" status=\"[on|off]\" profilelink=\"[on|off]\"]\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>or\u003C\u002Fp>\n\u003Cpre>\u003Ccode>[osinsl objectkey=\"\u003CUUID>\" picture=\"[none|center|right|left]\" status=\"[on|off]\" profilelink=\"[on|off]\"]\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>\u003Cstrong>avatar\u003C\u002Fstrong> should have a valid Second Life\u002FOpenSimulator avatar name which has an associated online status indicator in SL\u002FOpenSimulator. This will expand to show the online status (e.g. usually \u003Cem>online\u003C\u002Fem>, \u003Cem>offline\u003C\u002Fem>, or an error message if no widget was configured or if the avatar is not being tracked). Note that if you have avatars with the same name on different grids, this will just get you one of them.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>objectkey\u003C\u002Fstrong> should be the Object Key of an in-world online status tracking object. This should be used alternatively to \u003Cstrong>avatar\u003C\u002Fstrong> and is useful if you have several objects tracking your avatar across different grids, all for the same avatar name. Note that object keys may change over time (when they get copied, duplicated, taken back to inventory and rezzed again, etc.) so this should be used only as a last alternative, when you really have several avatars in different grids, all with the same name.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>picture\u003C\u002Fstrong> is optional and defaults to \u003Cem>none\u003C\u002Fem> (i.e. profile picture is not shown); if the user has set the Second Life web profile to be visible, this will retrieve their profile picture, and resize it to 80×80. Options are \u003Cem>left\u003C\u002Fem>, \u003Cem>right\u003C\u002Fem>, and \u003Cem>center\u003C\u002Fem> which will provide minimal formatting (additional styling requires CSS; image size is fixed for now; see the \u003Cstrong>CSS\u003C\u002Fstrong> section for more information). However, for the time being, pictures for avatars in OpenSimulator grids will \u003Cem>not\u003C\u002Fem> be displayed.\u003C\u002Fp>\n\u003Cp>If the \u003Cstrong>picture\u003C\u002Fstrong> is set, \u003Cstrong>status\u003C\u002Fstrong> can be set to \u003Cem>off\u003C\u002Fem> (just show the picture but not the actual status).\u003C\u002Fp>\n\u003Cp>If the \u003Cstrong>picture\u003C\u002Fstrong> is set, \u003Cstrong>profilelink\u003C\u002Fstrong> can be set to \u003Cem>on\u003C\u002Fem> (default is \u003Cem>off\u003C\u002Fem>) to link the picture to SL’s web profile page.\u003C\u002Fp>\n","Allows you to show your Second Life® or OpenSimulator online status on any WordPress blog (multiple widgets and shortcodes are possible)",5839,"2023-08-31T16:11:00.000Z","6.3.8",[130,112,131,19,132],"online","profile","status","https:\u002F\u002Fgwynethllewelyn.net\u002Fonline-status-insl\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fonline-status-insl.1.6.3.zip",{"attackSurface":136,"codeSignals":158,"taintFlows":264,"riskAssessment":289,"analyzedAt":300},{"hooks":137,"ajaxHandlers":148,"restRoutes":149,"shortcodes":150,"cronEvents":157,"entryPointCount":47,"unprotectedCount":13},[138,144],{"type":139,"name":140,"callback":141,"file":142,"line":143},"action","admin_menu","sl_lsl_add_admin_action","sl_tools.php",37,{"type":139,"name":145,"callback":146,"file":142,"line":147},"widgets_init","sl_load_slurl_widget",48,[],[],[151,154],{"tag":20,"callback":152,"file":142,"line":153},"sl_slurl_shortcode",55,{"tag":18,"callback":155,"file":142,"line":156},"sl_parse_lsl_shortcode",56,[],{"dangerousFunctions":159,"sqlUsage":165,"outputEscaping":167,"fileOperations":47,"externalRequests":13,"nonceChecks":85,"capabilityChecks":13,"bundledLibraries":263},[160],{"fn":161,"file":162,"line":163,"context":164},"create_function","geshi\\geshi.php",4617,"$callback_2 = create_function('$matches', 'return \"[\" . str_replace(\"|\", \"\", $matches[1]) . \"]\";');",{"prepared":13,"raw":13,"locations":166},[],{"escaped":30,"rawEcho":168,"locations":169},54,[170,173,176,178,180,182,184,186,188,190,192,194,196,198,200,203,205,207,209,211,213,214,215,217,219,220,221,223,225,226,227,229,231,232,233,235,237,238,239,241,243,244,245,247,249,250,251,253,255,256,257,259,261,262],{"file":162,"line":171,"context":172},4647,"raw output",{"file":174,"line":175,"context":172},"php\\lsl_parser_admin.php",266,{"file":174,"line":177,"context":172},268,{"file":174,"line":179,"context":172},281,{"file":174,"line":181,"context":172},291,{"file":174,"line":183,"context":172},310,{"file":174,"line":185,"context":172},329,{"file":174,"line":187,"context":172},348,{"file":174,"line":189,"context":172},367,{"file":174,"line":191,"context":172},386,{"file":174,"line":193,"context":172},405,{"file":174,"line":195,"context":172},424,{"file":174,"line":197,"context":172},443,{"file":174,"line":199,"context":172},462,{"file":201,"line":202,"context":172},"php\\slurl_widget.php",41,{"file":201,"line":204,"context":172},43,{"file":201,"line":206,"context":172},59,{"file":201,"line":208,"context":172},67,{"file":201,"line":210,"context":172},113,{"file":201,"line":212,"context":172},114,{"file":201,"line":212,"context":172},{"file":201,"line":212,"context":172},{"file":201,"line":216,"context":172},119,{"file":201,"line":218,"context":172},120,{"file":201,"line":218,"context":172},{"file":201,"line":218,"context":172},{"file":201,"line":222,"context":172},125,{"file":201,"line":224,"context":172},126,{"file":201,"line":224,"context":172},{"file":201,"line":224,"context":172},{"file":201,"line":228,"context":172},131,{"file":201,"line":230,"context":172},132,{"file":201,"line":230,"context":172},{"file":201,"line":230,"context":172},{"file":201,"line":234,"context":172},135,{"file":201,"line":236,"context":172},136,{"file":201,"line":236,"context":172},{"file":201,"line":236,"context":172},{"file":201,"line":240,"context":172},139,{"file":201,"line":242,"context":172},140,{"file":201,"line":242,"context":172},{"file":201,"line":242,"context":172},{"file":201,"line":246,"context":172},145,{"file":201,"line":248,"context":172},146,{"file":201,"line":248,"context":172},{"file":201,"line":248,"context":172},{"file":201,"line":252,"context":172},151,{"file":201,"line":254,"context":172},152,{"file":201,"line":254,"context":172},{"file":201,"line":254,"context":172},{"file":201,"line":258,"context":172},157,{"file":201,"line":260,"context":172},158,{"file":201,"line":260,"context":172},{"file":201,"line":260,"context":172},[],[265],{"entryPoint":266,"graph":267,"unsanitizedCount":13,"severity":288},"\u003Clsl_parser_admin> (php\\lsl_parser_admin.php:0)",{"nodes":268,"edges":284},[269,273,278,282],{"id":270,"type":271,"label":272,"file":174,"line":177},"n0","source","$_SERVER['REQUEST_URI']",{"id":274,"type":275,"label":276,"file":174,"line":177,"wp_function":277},"n1","sink","echo() [XSS]","echo",{"id":279,"type":271,"label":280,"file":174,"line":281},"n2","$_POST (x11)",162,{"id":283,"type":275,"label":276,"file":174,"line":179,"wp_function":277},"n3",[285,287],{"from":270,"to":274,"sanitized":286},true,{"from":279,"to":283,"sanitized":286},"low",{"summary":290,"deductions":291},"The \"sl-tools\" plugin v1.0 exhibits a generally positive security posture, with several good practices observed. The complete absence of known CVEs and unpatched vulnerabilities, along with the use of prepared statements for all SQL queries and zero taint flows indicating unsanitized paths, are significant strengths. The plugin also avoids external HTTP requests and does not bundle any libraries, which simplifies the security landscape.\n\nHowever, there are notable areas of concern. The plugin utilizes the dangerous `create_function()` PHP construct, which can be a vector for code injection if not handled with extreme care. Furthermore, only 5% of output is properly escaped, leaving a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of capability checks on any of its entry points, despite the presence of a nonce check on one, means that unauthorized users could potentially trigger functionality if they can discover or craft requests.\n\nWhile the vulnerability history is clean, this may be attributed to the plugin's simplicity or limited exposure rather than inherent robustness. The identified weaknesses, particularly the unescaped output and the use of `create_function()`, present tangible risks that require attention. The plugin's strengths lie in its adherence to modern SQL practices and lack of direct known exploits, but the identified code-level issues and potential for unauthenticated actions must be addressed for a more secure implementation.",[292,294,297],{"reason":293,"points":11},"Dangerous function create_function() used",{"reason":295,"points":296},"Low percentage of properly escaped output",8,{"reason":298,"points":299},"No capability checks on entry points",15,"2026-03-16T23:24:33.070Z",{"wat":302,"direct":313},{"assetPaths":303,"generatorPatterns":310,"scriptPaths":311,"versionParams":312},[304,305,306,307,308,309],"\u002Fwp-content\u002Fplugins\u002Fsl-tools\u002Fgeshi\u002Fgeshi.php","\u002Fwp-content\u002Fplugins\u002Fsl-tools\u002Fphp\u002Fslurl_shortcode.php","\u002Fwp-content\u002Fplugins\u002Fsl-tools\u002Fphp\u002Fslurl_widget.php","\u002Fwp-content\u002Fplugins\u002Fsl-tools\u002Fphp\u002Flsl_parser.php","\u002Fwp-content\u002Fplugins\u002Fsl-tools\u002Fphp\u002Flsl_parser_constants.php","\u002Fwp-content\u002Fplugins\u002Fsl-tools\u002Fphp\u002Flsl_parser_admin.php",[],[],[],{"cssClasses":314,"htmlComments":315,"htmlAttributes":316,"restEndpoints":317,"jsGlobals":318,"shortcodeOutput":319},[],[],[],[],[],[320,321],"[slurl]","[lsl]",{"error":286,"url":323,"statusCode":324,"statusMessage":325,"message":325},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fsl-tools\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":13,"versions":327},[]]