[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fEKG-ZPnZun0EMbuML5R3uTxH7Dcd-tuXb_dCIM7welI":3,"$fwq9tXlwEuQZC4kF5LkaFu2sAJuWKh3gIXuCcXRydY5Q":295,"$fEi6oYT6ERbQVvnRadnEoA3OjwWXtV-XflOu9OyBwIfE":299},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":22,"download_link":23,"security_score":24,"vuln_count":13,"unpatched_count":13,"last_vuln_date":25,"fetched_at":26,"discovery_status":27,"vulnerabilities":28,"developer":29,"crawl_stats":25,"alternatives":37,"analysis":143,"fingerprints":268},"user-recording","User Recording For WordPress","1.0.5","EDGARROJAS","https:\u002F\u002Fprofiles.wordpress.org\u002Fedgarrojas\u002F","\u003Ch4>User Recording For WordPress\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>Want to see a demo? \u003Ca href=\"http:\u002F\u002Fuserrecording.rednao.com\u002Fdemo\u002F\" rel=\"nofollow ugc\">Go here\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>The only plugins that record and save you user interactions using only your own site, the information never leave your site and you are in total control of it.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>The recorded data is sent, stored and never leaves your site\u003C\u002Fstrong>. Only you are going to be able to see your user recordings and you can delete it anytime.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Unlimited Recordings\u003C\u002Fstrong>. There is no monthly quota or limit of recordings per month. If you are worried about space fear not, the information is compressed before saving and you can configure the plugin to delete the recordings periodically.\u003C\u002Fli>\n\u003C\u002Ful>\n","User recording specially created for WordPress sites.",10,1379,0,"2017-08-07T13:51:00.000Z","4.8.28","3.3","",[19,20,21,4],"capture","recording","session-recording","http:\u002F\u002Fsessionrecording.rednao.com\u002Fgetit","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fuser-recording.zip",85,null,"2026-04-16T10:56:18.058Z","no_bundle",[],{"slug":30,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":32,"avg_security_score":33,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"edgarrojas",19,12420,94,278,75,"2026-05-20T05:16:54.001Z",[38,62,85,104,122],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":48,"num_ratings":49,"last_updated":50,"tested_up_to":51,"requires_at_least":52,"requires_php":17,"tags":53,"homepage":59,"download_link":60,"security_score":61,"vuln_count":13,"unpatched_count":13,"last_vuln_date":25,"fetched_at":26},"lucky-orange","Lucky Orange","2.1.1","luckyorange","https:\u002F\u002Fprofiles.wordpress.org\u002Fcrickeys\u002F","\u003Cp>Less time crunching numbers, more time growing your business.\u003C\u002Fp>\n\u003Ch3>Understand your visitors. Improve your website. Increase your sales.\u003C\u002Fh3>\n\u003Cp>If your WordPress site is getting traffic but not conversions, Lucky Orange shows you why. With one-click install and a free plan to get started, you can uncover where visitors struggle, what’s stopping them from buying, and how to turn browsers into customers.\u003Cbr \u002F>\nFrom session recordings to heatmaps, live chat to Page Insights, Lucky Orange helps you optimize every part of your customer journey with clear, visual data.\u003C\u002Fp>\n\u003Ch3>Dynamic Heatmaps\u003C\u002Fh3>\n\u003Cp>Discover where people click, scroll, and hover—including dynamic content like popups, dropdowns, and forms. Works seamlessly with SPAs and AJAX-loaded pages.\u003C\u002Fp>\n\u003Ch3>Session Recordings\u003C\u002Fh3>\n\u003Cp>Replay real visitor sessions to see how people navigate your site, where they abandon, and what’s preventing conversions.\u003C\u002Fp>\n\u003Ch3>Conversion Funnels\u003C\u002Fh3>\n\u003Cp>Visualize each step of your funnel to find out which pages drive success—and where people are dropping off.\u003C\u002Fp>\n\u003Ch3>Visitor Profiles\u003C\u002Fh3>\n\u003Cp>See each visitor’s journey in a single view, including traffic source, cart value, and all sessions tied to that individual.\u003C\u002Fp>\n\u003Ch3>Live Chat\u003C\u002Fh3>\n\u003Cp>Engage visitors in real time based on behavior triggers. Answer questions and recover abandoned conversions before they’re lost.\u003C\u002Fp>\n\u003Ch3>Live View\u003C\u002Fh3>\n\u003Cp>See what your visitors are doing right now on your site—every movement, scroll, and click in real time.\u003C\u002Fp>\n\u003Ch3>Page Insights\u003C\u002Fh3>\n\u003Cp>Instantly surface key performance stats: top-clicked elements, frustration signals, engagement trends, and activity snapshots—all tied to specific pages.\u003C\u002Fp>\n\u003Ch3>Surveys\u003C\u002Fh3>\n\u003Cp>Ask the right questions at the right time—like what visitors are looking for, what’s missing, or why they didn’t convert.\u003C\u002Fp>\n\u003Ch3>Announcements\u003C\u002Fh3>\n\u003Cp>Target visitors with personalized messages, discount offers, or key updates based on device, behavior, or source.\u003C\u002Fp>\n\u003Ch3>Discovery\u003C\u002Fh3>\n\u003Cp>Uncover Optimization Opportunities based on specific parts of the customer journey. Know where to focus, and what changes can move the needle.\u003C\u002Fp>\n","Less time crunching numbers, more time growing your business.",2000,70614,86,24,"2025-04-14T15:38:00.000Z","6.8.0","2.0.3",[54,55,56,57,58],"analytics","conversion-rate-optimization","heatmaps","session-recordings","surveys","https:\u002F\u002Fwww.luckyorange.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flucky-orange.2.2.11.zip",92,{"slug":63,"name":64,"version":65,"author":66,"author_profile":67,"description":68,"short_description":69,"active_installs":70,"downloaded":71,"rating":72,"num_ratings":73,"last_updated":74,"tested_up_to":75,"requires_at_least":76,"requires_php":77,"tags":78,"homepage":83,"download_link":84,"security_score":72,"vuln_count":13,"unpatched_count":13,"last_vuln_date":25,"fetched_at":26},"opti-behavior","Opti-Behavior – Self-Hosted Heatmaps, Session Recording & Analytics (GDPR-Native ,Free Hotjar & Clarity Alternative)","1.2.7","OptiUser","https:\u002F\u002Fprofiles.wordpress.org\u002Foptiuser\u002F","\u003Cp>\u003Cstrong>Opti-Behavior\u003C\u002Fstrong> is the most complete self-hosted \u003Cstrong>WordPress analytics plugin\u003C\u002Fstrong> — delivering \u003Cstrong>heatmaps, session recordings, click tracking, visitor tracking, and conversion funnels\u003C\u002Fstrong> with \u003Cstrong>complete data privacy\u003C\u002Fstrong> and \u003Cstrong>zero performance impact\u003C\u002Fstrong>, all from your own server. The perfect \u003Cstrong>Hotjar alternative\u003C\u002Fstrong> and \u003Cstrong>Google Analytics alternative\u003C\u002Fstrong> for privacy-conscious WordPress sites.\u003C\u002Fp>\n\u003Cp>Powered by a revolutionary \u003Cstrong>Hybrid Storage engine\u003C\u002Fstrong>, Opti-Behavior writes analytics events to optimized files on disk instead of hammering your database. Combined with batch processing, pre-aggregated daily statistics, and a ~15KB async tracking script, your website stays blazing fast — even with millions of pageviews. \u003Cstrong>All your data stays on YOUR WordPress server.\u003C\u002Fstrong> No cloud. No third-party access. No data sharing. No GDPR grey zones.\u003C\u002Fp>\n\u003Ch4>Core Features (Free)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Click & scroll heatmaps with color-coded intensity (Mobile & Desktop)\u003C\u002Fli>\n\u003Cli>Real-time analytics dashboard — visitors, sessions, pageviews, bounce rate, scroll depth\u003C\u002Fli>\n\u003Cli>Interactive world map with visitor locations, Top Pages, and Traffic Sources\u003C\u002Fli>\n\u003Cli>Conversion funnels with multi-step dropout analysis and device filtering\u003C\u002Fli>\n\u003Cli>Session & visitor tracking (duration, pages visited, referrers, outbound links)\u003C\u002Fli>\n\u003Cli>Bot detection & filtering (Google, Bing, Yahoo, etc.)\u003C\u002Fli>\n\u003Cli>Scheduled email reports (Daily, Weekly, Monthly)\u003C\u002Fli>\n\u003Cli>IP anonymization, no cookies required, no third-party data sharing\u003C\u002Fli>\n\u003Cli>Multilingual admin: English, French, German, Spanish, Portuguese, Italian\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pro Features (Upgrade)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Session Recordings\u003C\u002Fstrong> — full playback with privacy controls\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Error Tracking\u003C\u002Fstrong> — JS errors, network errors, Core Web Vitals\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Friction Detection\u003C\u002Fstrong> — rage clicks and dead clicks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Form Analytics\u003C\u002Fstrong> — field-level interaction and abandonment tracking\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Journey Analytics\u003C\u002Fstrong> — Sankey diagram visitor path visualization\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Heatmap Filtering\u003C\u002Fstrong> — country, browser, device, and date\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Priority Support\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Try Pro FREE for 6 months\u003C\u002Fstrong> — no credit card required!\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Foptiuser.com\u002Fopti-behavior\u002F\" rel=\"nofollow ugc\">Learn more about Opti-Behavior Pro\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin may connect to external services in limited circumstances:\u003C\u002Fp>\n\u003Ch4>IP Geolocation (ip-api.com)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Purpose:\u003C\u002Fstrong> Provides geographic location data (country, city, timezone) for visitor analytics and map visualization.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When Used:\u003C\u002Fstrong> Only when a visitor’s location cannot be determined from CloudFlare headers. If CloudFlare is active, no external calls are made.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Sent:\u003C\u002Fstrong> Only the visitor’s IP address. No personally identifiable information is transmitted.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Caching:\u003C\u002Fstrong> Results are cached for 1 hour to minimize API requests.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Service: https:\u002F\u002Fip-api.com\u002F\u003Cbr \u002F>\n* Terms & Privacy: https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\u003Cbr \u002F>\n* Note: ip-api.com may log IP addresses. Review their privacy policy for details.\u003C\u002Fp>\n\u003Ch4>IP Geolocation Fallback (ipwho.is)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Purpose:\u003C\u002Fstrong> Secondary geolocation fallback when ip-api.com is rate-limited or unavailable. Provides geographic location data (country, city, region, timezone) for visitor analytics.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When Used:\u003C\u002Fstrong> Only when both CloudFlare headers and ip-api.com fail to resolve a visitor’s location. ip-api.com’s free tier has a 45 requests\u002Fminute rate limit, so on high-traffic sites ipwho.is ensures visitors are still geolocated accurately.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Sent:\u003C\u002Fstrong> Only the visitor’s IP address. No personally identifiable information is transmitted.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Caching:\u003C\u002Fstrong> Results are cached for 1 hour to minimize API requests.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Service: https:\u002F\u002Fipwho.is\u002F\u003Cbr \u002F>\n* Terms & Privacy: https:\u002F\u002Fipwho.is\u002F\u003Cbr \u002F>\n* Note: ipwho.is may log IP addresses. Review their privacy policy for details.\u003C\u002Fp>\n\u003Ch4>OpenStreetMap Tiles\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Purpose:\u003C\u002Fstrong> Displays the interactive visitor location map in your WordPress admin dashboard.\u003Cbr \u002F>\n\u003Cstrong>When Used:\u003C\u002Fstrong> Only when YOU (the admin) view the real-time visitor map. Not used on the frontend.\u003Cbr \u002F>\n\u003Cstrong>Data Sent:\u003C\u002Fstrong> Your browser makes direct requests to OpenStreetMap tile servers (standard HTTP headers only).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Service: https:\u002F\u002Fwww.openstreetmap.org\u002F\u003Cbr \u002F>\n* Tile Policy: https:\u002F\u002Foperations.osmfoundation.org\u002Fpolicies\u002Ftiles\u002F\u003Cbr \u002F>\n* Privacy Policy: https:\u002F\u002Fwiki.osmfoundation.org\u002Fwiki\u002FPrivacy_Policy\u003C\u002Fp>\n\u003Ch4>OptiUser API (api.optiuser.com)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Purpose:\u003C\u002Fstrong> Handles anonymous install tracking, plugin deactivation notifications, Pro trial license generation, license validation, update checks, and download access code generation for the Pro plugin.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When Used:\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Install tracker:\u003C\u002Fstrong> Sends an anonymous heartbeat once every 24 hours after activation, containing only: site URL, WordPress version, PHP version, plugin version, and plugin type (free\u002Fpro). No visitor data or personal information is sent.\u003Cbr \u002F>\n* \u003Cstrong>Deactivation:\u003C\u002Fstrong> Notifies the API when the plugin is deactivated so installation records stay up to date.\u003Cbr \u002F>\n* \u003Cstrong>Pro upgrade pages:\u003C\u002Fstrong> When an admin views a Pro feature upgrade page (Session Recordings, Error Tracking, User Journeys, Form Analytics), the plugin requests a one-time download access code from the API. This code is used to securely access the Pro download page on optiuser.com.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Sent:\u003C\u002Fstrong> Site URL, WordPress admin username, admin email address (only when requesting a Pro download access code). No visitor analytics data is ever sent to the API.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Service: https:\u002F\u002Fapi.optiuser.com\u002F\u003Cbr \u002F>\n* Website: https:\u002F\u002Foptiuser.com\u002F\u003Cbr \u002F>\n* Privacy Policy: https:\u002F\u002Foptiuser.com\u002Fprivacy-policy\u002F\u003Cbr \u002F>\n* The API stores installation metadata (site URL, plugin version) for license management. No visitor data is collected or stored by the API.\u003C\u002Fp>\n\u003Ch4>OptiUser Website (optiuser.com)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Purpose:\u003C\u002Fstrong> Hosts the Opti-Behavior Pro download page and sales\u002Ffeature pages. When an admin clicks “Download Pro — Free for 6 Months” on a Pro upgrade page, they are redirected to optiuser.com to register and download the Pro plugin.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When Used:\u003C\u002Fstrong> Only when an admin chooses to download Opti-Behavior Pro from a Pro upgrade page within the WordPress admin. This is an optional, user-initiated action.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Sent:\u003C\u002Fstrong> Site URL,  username, and  email address are passed as URL parameters to pre-fill the registration form. No visitor analytics data is sent.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Service: https:\u002F\u002Foptiuser.com\u002F\u003Cbr \u002F>\n* Privacy Policy: https:\u002F\u002Foptiuser.com\u002Fprivacy-policy\u002F\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Important Note:\u003C\u002Fstrong> All analytics data is stored locally on your WordPress server. The external services listed above are used only for optional geographic features (ip-api.com, ipwho.is, OpenStreetMap), anonymous install tracking, and Pro license management (api.optiuser.com). No visitor analytics data ever leaves your server.\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>Opti-Behavior collects user interaction data to provide analytics insights. This data includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Page URLs and titles\u003C\u002Fli>\n\u003Cli>Click coordinates and target elements\u003C\u002Fli>\n\u003Cli>Mouse movement patterns\u003C\u002Fli>\n\u003Cli>Scroll depth\u003C\u002Fli>\n\u003Cli>Session timestamps\u003C\u002Fli>\n\u003Cli>Referrer URLs\u003C\u002Fli>\n\u003Cli>Browser and device information\u003C\u002Fli>\n\u003Cli>IP addresses (can be anonymized)\u003C\u002Fli>\n\u003Cli>Approximate location based on browser timezone (client-side only, no external services)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Data Storage:\u003C\u002Fstrong> All analytics data is stored locally in your WordPress database or file system. No data is sent to external analytics servers.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>External Services:\u003C\u002Fstrong> This plugin may make API calls to ip-api.com and ipwho.is for IP geolocation when CloudFlare headers are not available. ipwho.is is used as a secondary fallback when ip-api.com is rate-limited or unavailable. Only the visitor’s IP address is sent to these services. See the “External Services” section above for complete details.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Usage Tracking:\u003C\u002Fstrong> With your explicit consent (granted via the first-run welcome screen), this plugin sends anonymous usage statistics to api.optiuser.com once every 24 hours. The data includes: site URL, plugin version, WordPress version, PHP version, and the site administrator email address. This data is used solely to understand plugin adoption and improve the product. Tracking only begins after you click “Accept & Continue” on the welcome page shown at first activation. You may review our full data practices at https:\u002F\u002Foptiuser.com\u002Fprivacy-policy\u002F\u003C\u002Fp>\n\u003Cp>\u003Cstrong>No Third-Party Data Sharing:\u003C\u002Fstrong> Unlike cloud-based analytics tools, Opti-Behavior does not share, sell, or transfer your visitors’ data to any third party. You are the sole data controller.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User Rights:\u003C\u002Fstrong> You have full control over data retention and deletion. Users can request data deletion at any time.\u003C\u002Fp>\n\u003Cp>When using this plugin, ensure your site’s privacy policy discloses:\u003Cbr \u002F>\n* What data is being collected\u003Cbr \u002F>\n* How long it is retained\u003Cbr \u002F>\n* Who has access to it\u003Cbr \u002F>\n* How users can request deletion\u003Cbr \u002F>\n* That data is stored locally and not shared with third parties\u003C\u002Fp>\n\u003Ch3>Third-Party Libraries\u003C\u002Fh3>\n\u003Cp>This plugin bundles the following open-source libraries:\u003C\u002Fp>\n\u003Ch4>Chart.js\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Version: 4.4.0\u003C\u002Fli>\n\u003Cli>License: MIT License\u003C\u002Fli>\n\u003Cli>Homepage: https:\u002F\u002Fwww.chartjs.org\u002F\u003C\u002Fli>\n\u003Cli>Used for: Rendering analytics charts and graphs\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Leaflet\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Version: 1.9.4\u003C\u002Fli>\n\u003Cli>License: BSD 2-Clause License\u003C\u002Fli>\n\u003Cli>Homepage: https:\u002F\u002Fleafletjs.com\u002F\u003C\u002Fli>\n\u003Cli>Used for: Real-time visitor map visualization\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>heatmap.js\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Version: 2.0.5\u003C\u002Fli>\n\u003Cli>License: MIT License\u003C\u002Fli>\n\u003Cli>Homepage: https:\u002F\u002Fwww.patrick-wied.at\u002Fstatic\u002Fheatmapjs\u002F\u003C\u002Fli>\n\u003Cli>Used for: Generating visual heatmaps of user interactions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Lucide\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Version: 0.554.0\u003C\u002Fli>\n\u003Cli>License: ISC License\u003C\u002Fli>\n\u003Cli>Homepage: https:\u002F\u002Flucide.dev\u002F\u003C\u002Fli>\n\u003Cli>Used for: Icon library for the admin interface\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All bundled libraries use GPL-compatible licenses (MIT, BSD 2-Clause, and ISC) and are included locally within the plugin. See THIRD-PARTY-LICENSES.txt in the plugin directory for full license texts.\u003C\u002Fp>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cp>Developed by \u003Ca href=\"https:\u002F\u002Foptiuser.com\u002F\" rel=\"nofollow ugc\">OptiUser\u003C\u002Fa>\u003C\u002Fp>\n","Free self-hosted heatmaps, click tracking, session recordings & funnels. GDPR-ready. No session limits. Your data stays on your server.",300,1109,100,2,"2026-04-09T13:56:00.000Z","6.9.4","5.8","7.4",[79,80,81,21,82],"click-tracking","funnel","heatmap","visitor-tracking","https:\u002F\u002Foptiuser.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fopti-behavior.1.2.7.zip",{"slug":86,"name":87,"version":88,"author":89,"author_profile":90,"description":91,"short_description":92,"active_installs":72,"downloaded":93,"rating":72,"num_ratings":73,"last_updated":94,"tested_up_to":95,"requires_at_least":96,"requires_php":97,"tags":98,"homepage":17,"download_link":100,"security_score":101,"vuln_count":102,"unpatched_count":102,"last_vuln_date":103,"fetched_at":26},"ux-sniff","UXsniff AI-powered Heatmaps and Session Recordings","1.3.3","Pei Yong Goh","https:\u002F\u002Fprofiles.wordpress.org\u002Fuxsniff\u002F","\u003Cp>A simple WordPress heatmap plugin to monitoring your user’s behaviour, detect and report abnormal user activities. This plugin allows you to install UXsniff tracking code to your wordpress without editing your theme.\u003C\u002Fp>\n\u003Cp>The plugin also shows basic statistic about your website. Some basic features such as Heatmaps, Clickmaps, Session Recordings and Rage alerts are available within the plugin. Login to UXsniff for advanced features such as Time-Travel A\u002FB Testing, User Journey, Feedback Widgets, On-site Surveys, Broken link scanner, Site Audit and advanced reports.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Plugin Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Insert UXsniff tracking code\u003C\u002Fli>\n\u003Cli>Report abnormal user activities\u003C\u002Fli>\n\u003Cli>Heatmaps\u003C\u002Fli>\n\u003Cli>Clickmaps\u003C\u002Fli>\n\u003Cli>Session recordings\u003C\u002Fli>\n\u003Cli>AI insights for session recordings\u003C\u002Fli>\n\u003Cli>Rage alerts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Advanced Features (available on uxsniff.com for free)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Time-Travel A\u002FB Testing (compare against past snapshots—no split traffic, no code.)\u003C\u002Fli>\n\u003Cli>Real-time monitoring\u003C\u002Fli>\n\u003Cli>Wayback machine for heatmaps (time travel to old designs)\u003C\u002Fli>\n\u003Cli>Feedback widgets\u003C\u002Fli>\n\u003Cli>On-site surveys\u003C\u002Fli>\n\u003Cli>LinkGuard – broken links scanner\u003C\u002Fli>\n\u003Cli>Site audit – scan your site for UX and SEO issues\u003C\u002Fli>\n\u003C\u002Ful>\n","Short Description: AI-powered Heatmaps, Session Recordings & A\u002FB Testing",7510,"2026-03-10T14:00:00.000Z","6.8.5","3.0.1","5.2.4",[99,56,57],"a-b-testing","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fux-sniff.1.3.3.zip",79,1,"2025-04-10 00:00:00",{"slug":105,"name":106,"version":107,"author":108,"author_profile":109,"description":110,"short_description":111,"active_installs":112,"downloaded":113,"rating":13,"num_ratings":13,"last_updated":114,"tested_up_to":115,"requires_at_least":116,"requires_php":97,"tags":117,"homepage":120,"download_link":121,"security_score":24,"vuln_count":13,"unpatched_count":13,"last_vuln_date":25,"fetched_at":26},"session-rewind","Session Rewind","1.1.1","yairsr","https:\u002F\u002Fprofiles.wordpress.org\u002Fyairsr\u002F","\u003Cp>\u003Ca href=\"https:\u002F\u002Fsessionrewind.com\" rel=\"nofollow ugc\">Session Rewind\u003C\u002Fa> offers a simple and affordable way to understand your users’ behavior.\u003C\u002Fp>\n\u003Cp>We offer:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Session Playback\u003C\u002Fstrong>: Watch what happens when you really watch what happens. See exactly what your users saw. Save the most insightful sessions and share them with your teammates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Notifications\u003C\u002Fstrong>: Get alerted whenever a user session meets pre-specified criteria, or as part of a daily rollup.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Heatmaps\u003C\u002Fstrong>: Quickly identify where your users are spending the most time and attention.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin makes installation of Session Rewind on your WordPress site a breeze.\u003C\u002Fp>\n\u003Cp>Please note that an active account and API key with Session Rewind is required to enable this plugin on your site.\u003C\u002Fp>\n","Optimize your web experience with video recordings of user behavior.",80,2349,"2024-01-12T20:00:00.000Z","6.4.8","2.7",[56,118,119,21],"insights","recordings","https:\u002F\u002Fsessionrewind.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsession-rewind.1.1.1.zip",{"slug":123,"name":124,"version":125,"author":126,"author_profile":127,"description":128,"short_description":129,"active_installs":130,"downloaded":131,"rating":13,"num_ratings":13,"last_updated":132,"tested_up_to":133,"requires_at_least":134,"requires_php":135,"tags":136,"homepage":17,"download_link":141,"security_score":24,"vuln_count":13,"unpatched_count":13,"last_vuln_date":25,"fetched_at":142},"analytics-integrator","Analytics Integrator","1.0.0","WP Replay","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpreplay\u002F","\u003Cp>Integrate your favourite session recording and analytics tool with ease. This plugin allows you to integrate the most popular services: Smartlook, Fullstory, Hotjar and  Mouseflow. \u003Cstrong>Easy integration – just put the tracking ID and you are ready to go.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Some of the key features that those services include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Real-Time Data\u003C\u002Fstrong>: Real-time data that allows you to track user behavior as it happens on your website. This feature lets you see how many users are currently on your site, what pages they are viewing, and where they are coming from.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Audience Reports\u003C\u002Fstrong>: Detailed audience reports that give you insights into the demographics, interests, and behaviors of your website visitors. This data helps you understand your audience and tailor your marketing efforts to their needs.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Behavior Reports\u003C\u002Fstrong>: Behavior reports that show how users are interacting with your website. This feature helps you identify which pages are most popular, how long users are staying on your site, and which pages are leading to conversions.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Session Replay\u003C\u002Fstrong>: Detailed recordings of every user interaction on your website or mobile app, including clicks, scrolls, and pageviews.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Heatmaps\u003C\u002Fstrong>: Visual representations of user engagement on your website, highlighting which areas are receiving the most attention.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Conversion Funnels\u003C\u002Fstrong>: A powerful tool for analysing and optimising the user journey from start to finish, identifying potential areas for improvement.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Search and Segmentation\u003C\u002Fstrong>: A powerful search engine that allows businesses to filter sessions based on specific criteria, such as user location, device type, and behaviour.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Rage Clicks and Error Tracking\u003C\u002Fstrong>: Identifying and resolving issues on your website that cause frustration for users, such as broken links or error messages.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Integrations\u003C\u002Fstrong>: Integrate with a range of popular marketing and analytics tools, including Google Analytics, Slack, and Salesforce.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Customizable Dashboards\u003C\u002Fstrong>: Customizable dashboards that allow businesses to track and visualise key metrics, such as conversion rates and user engagement.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Collaboration Tools\u003C\u002Fstrong>: Provide a range of collaboration tools, including the ability to share sessions and notes with team members, making it easier for businesses to collaborate and solve problems quickly.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Privacy and Security\u003C\u002Fstrong>: Privacy and security is taken seriously, offering features such as GDPR compliance, two-factor authentication, and encryption to keep your data safe and secure.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Custom Events\u003C\u002Fstrong>: Create custom events that track specific user actions, such as button clicks or form submissions, providing more detailed insights into user behaviour.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Form Analytics\u003C\u002Fstrong>: Detailed analytics on form usage and submission, including field completion rates and drop-off points, helping businesses identify areas for improvement in their forms.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>And much more…\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Plugin features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Tracking script to your wordpress website without coding knowledge\u003C\u002Fli>\n\u003Cli>Woocommerce (work in progress) – order analytics (added\u002Fremoved from cart…)\u003C\u002Fli>\n\u003Cli>User identification (work in progress)\u003C\u002Fli>\n\u003Cli>Conditional recording (work in progress)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Supported integration\u003C\u002Fh3>\n\u003Ch3>Google Analytics\u003C\u002Fh3>\n\u003Cp>Google Analytics is a powerful tool that allows website owners to track and analyze their website’s traffic and user behavior. With its user-friendly interface and robust features, Google Analytics enables businesses to make data-driven decisions and improve their online presence. From tracking website traffic sources to analyzing user engagement and conversion rates, Google Analytics provides valuable insights into how users interact with your website. Get started with Google Analytics today and unlock the full potential of your website.\u003C\u002Fp>\n\u003Ch3>FullStory\u003C\u002Fh3>\n\u003Cp>FullStory is a comprehensive digital experience platform that helps businesses better understand their website visitors and improve their overall customer experience. Its powerful analytics tools, including session replay, heatmaps, and conversion funnels, provide invaluable insights that help businesses optimize their website’s user experience and increase conversions. With FullStory, you can take your customer experience to the next level. Try it today and see the difference it can make for your business.\u003C\u002Fp>\n\u003Ch3>Hotjar\u003C\u002Fh3>\n\u003Cp>Hotjar is an all-in-one analytics and feedback tool that helps businesses better understand their website visitors and improve their user experience. With its powerful suite of tools, including heatmaps, session recordings, and surveys, Hotjar provides businesses with valuable insights into how visitors interact with their website. These insights can help businesses optimise their website’s design, content, and user experience to increase conversions and drive growth. Try Hotjar today and unlock the full potential of your website.\u003C\u002Fp>\n\u003Ch3>Smartlook\u003C\u002Fh3>\n\u003Cp>Smartlook is an innovative customer analytics tool that provides businesses with invaluable insights into the behaviour of their website visitors. With its powerful session recording, heatmapping, and funnel analysis features, Smartlook helps businesses optimise their website’s user experience and increase conversions. Try Smartlook today and unlock the full potential of your website.\u003C\u002Fp>\n\u003Ch3>Mouseflow\u003C\u002Fh3>\n\u003Cp>Mouseflow is a powerful web analytics tool that provides businesses with valuable insights into their website visitors’ behaviour. With its advanced features, including session replay, heatmaps, and funnels, Mouseflow helps businesses understand how visitors interact with their website, identify areas for improvement, and increase conversions. With Mouseflow, you can take your website’s user experience to the next level. Try it today and see the difference it can make for your business.\u003C\u002Fp>\n","Integrate your favourite session recording and analytics tool with ease. This plugin allows you to integrate the most popular services: Smartlook, Ful &hellip;",20,898,"2023-06-04T08:20:00.000Z","6.2.9","5.0","5.6",[137,138,139,21,140],"fullstory","hotjar","mouseflow","smartlook","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fanalytics-integrator.1.0.0.zip","2026-03-15T15:16:48.613Z",{"attackSurface":144,"codeSignals":200,"taintFlows":238,"riskAssessment":255,"analyzedAt":267},{"hooks":145,"ajaxHandlers":176,"restRoutes":193,"shortcodes":194,"cronEvents":195,"entryPointCount":199,"unprotectedCount":199},[146,152,156,161,165,168,172],{"type":147,"name":148,"callback":149,"priority":13,"file":150,"line":151},"action","wp_enqueue_scripts","smart_session_recorder_include","user-recording.php",45,{"type":147,"name":153,"callback":154,"file":150,"line":155},"admin_menu","rednao_smart_session_recording_create_menu",46,{"type":157,"name":158,"callback":159,"file":150,"line":160},"filter","cron_schedules","smart_session_recorder_add_interval",53,{"type":147,"name":162,"callback":163,"file":150,"line":164},"usfwp_schedule_delete","usfwp_schedule_delete_action",54,{"type":157,"name":166,"callback":167,"file":150,"line":72},"query_vars","smart_session_recording_add_trigger",{"type":147,"name":169,"callback":170,"file":150,"line":171},"template_redirect","smart_session_recording_check_if_player",107,{"type":147,"name":173,"callback":174,"file":150,"line":175},"admin_init","rednao_smart_session_recording_was_activated",123,[177,182,184,187,190],{"action":178,"nopriv":179,"callback":178,"hasNonce":180,"hasCapCheck":180,"file":150,"line":181},"rednao_ssr_submit_recording",true,false,48,{"action":178,"nopriv":180,"callback":178,"hasNonce":180,"hasCapCheck":180,"file":150,"line":183},49,{"action":185,"nopriv":180,"callback":185,"hasNonce":180,"hasCapCheck":180,"file":150,"line":186},"rednao_ssr_get_recordings",50,{"action":188,"nopriv":180,"callback":188,"hasNonce":180,"hasCapCheck":180,"file":150,"line":189},"rednao_ssr_delete_recordings",51,{"action":191,"nopriv":180,"callback":191,"hasNonce":180,"hasCapCheck":180,"file":150,"line":192},"rednao_ssr_update_schedule",52,[],[],[196],{"hook":162,"callback":162,"file":197,"line":198},"smart-session-recording-ajax.php",224,5,{"dangerousFunctions":201,"sqlUsage":202,"outputEscaping":205,"fileOperations":236,"externalRequests":13,"nonceChecks":13,"capabilityChecks":102,"bundledLibraries":237},[],{"prepared":203,"raw":13,"locations":204},16,[],{"escaped":73,"rawEcho":206,"locations":207},13,[208,212,214,216,218,220,222,224,226,228,230,232,234],{"file":209,"line":210,"context":211},"fonts\\fontloader.php",9,"raw output",{"file":209,"line":213,"context":211},12,{"file":209,"line":215,"context":211},15,{"file":209,"line":217,"context":211},18,{"file":209,"line":219,"context":211},21,{"file":209,"line":221,"context":211},25,{"file":209,"line":223,"context":211},28,{"file":209,"line":225,"context":211},31,{"file":209,"line":227,"context":211},34,{"file":209,"line":229,"context":211},37,{"file":231,"line":192,"context":211},"screens\\child_player.php",{"file":197,"line":233,"context":211},98,{"file":197,"line":235,"context":211},140,11,[],[239],{"entryPoint":240,"graph":241,"unsanitizedCount":13,"severity":254},"\u003Cchild_player> (screens\\child_player.php:0)",{"nodes":242,"edges":252},[243,247],{"id":244,"type":245,"label":246,"file":231,"line":236},"n0","source","$_GET (x2)",{"id":248,"type":249,"label":250,"file":231,"line":31,"wp_function":251},"n1","sink","get_results() [SQLi]","get_results",[253],{"from":244,"to":248,"sanitized":179},"low",{"summary":256,"deductions":257},"The \"user-recording\" plugin v1.0.5 exhibits a mixed security posture. While it demonstrates good practice by exclusively using prepared statements for all SQL queries and shows no known vulnerabilities in its history, several significant security concerns are present in its static analysis.\n\nThe plugin has a considerable attack surface, with 5 AJAX handlers identified. Alarmingly, all 5 of these AJAX handlers lack authentication checks, meaning any unauthenticated user could potentially trigger these functions. This absence of capability checks on these critical entry points is a major security weakness. Additionally, while the taint analysis did not reveal any unsanitized paths, the limited scope of analysis (only 1 flow analyzed) and the significant number of file operations (11) without explicit mention of sanitization for those operations warrant caution.\n\nThe plugin's lack of recorded vulnerabilities is positive, suggesting that historically it may not have had exploitable flaws or that they were promptly addressed. However, this does not mitigate the current identified risks from the static analysis. The presence of unprotected AJAX endpoints represents a direct and immediate threat that needs to be addressed. In conclusion, the plugin has a strength in its SQL query handling and vulnerability history, but this is heavily outweighed by the critical risk posed by unprotected AJAX handlers and a lack of comprehensive security checks on its entry points.",[258,260,262,265],{"reason":259,"points":11},"AJAX handlers without auth checks",{"reason":261,"points":11},"No nonce checks on AJAX handlers",{"reason":263,"points":264},"Low output escaping coverage",3,{"reason":266,"points":73},"Capability checks present but not on all entry points","2026-03-17T00:30:17.301Z",{"wat":269,"direct":284},{"assetPaths":270,"generatorPatterns":278,"scriptPaths":279,"versionParams":283},[271,272,273,274,275,276,277],"\u002Fwp-content\u002Fplugins\u002Fuser-recording\u002Fjs\u002FBundle\u002Frecorder_bundle.js","\u002Fwp-content\u002Fplugins\u002Fuser-recording\u002Fimg\u002Ficon.png","\u002Fwp-content\u002Fplugins\u002Fuser-recording\u002Fscreens\u002Fplayer.php","\u002Fwp-content\u002Fplugins\u002Fuser-recording\u002Fjs\u002Flib\u002Fvelocity.min.js","\u002Fwp-content\u002Fplugins\u002Fuser-recording\u002Fjs\u002FBundle\u002Freactplayer_bundle.js","\u002Fwp-content\u002Fplugins\u002Fuser-recording\u002Fjs\u002Flib\u002Fbootstrap\u002Fcss\u002Fbootstrap.css","\u002Fwp-content\u002Fplugins\u002Fuser-recording\u002Fjs\u002Flib\u002Fbootstrap\u002Fcss\u002Fbootstrap.min.css",[],[280,281,282],"js\u002FBundle\u002Frecorder_bundle.js","js\u002Flib\u002Fvelocity.min.js","js\u002FBundle\u002Freactplayer_bundle.js",[],{"cssClasses":285,"htmlComments":287,"htmlAttributes":288,"restEndpoints":290,"jsGlobals":292,"shortcodeOutput":294},[286],"ssrLoadingScreen",[],[289],"id=\"smart-session-recording-id\"",[291],"\u002Fwp-json\u002Frednao\u002Fv1\u002Frecording\u002F",[293],"smartformsrecordingparams",[],{"error":179,"url":296,"statusCode":297,"statusMessage":298,"message":298},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fuser-recording\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":13,"versions":300},[]]