[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f54PNWJobdCHRiee0zpenPdcGRarJdrpQzBKdaK_4AAc":3},{"slug":4,"name":5,"version":6,"author":5,"author_profile":7,"description":8,"short_description":9,"active_installs":10,"downloaded":11,"rating":12,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":22,"download_link":23,"security_score":24,"vuln_count":25,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28,"vulnerabilities":29,"developer":46,"crawl_stats":35,"alternatives":49,"analysis":152,"fingerprints":251},"web-stat","Web-Stat","2.6","https:\u002F\u002Fprofiles.wordpress.org\u002Fwebstat\u002F","\u003Cp>Observe visitors interacting with your web site through real-time and intuitive reports! Web-Stat is FREE and records the details of all your visits. We detect everything that can be detected and present the results in clear, user-friendly charts and graphics.\u003C\u002Fp>\n\u003Cp>Check out the kind of info you can gain on your visitors with our \u003Ca href=\"https:\u002F\u002Fwww.web-stat.com\u002Fcheckstats.htm?loginID=demo\" rel=\"nofollow ugc\">demo stats\u003C\u002Fa>. You can get the same type of data for your own site immediately: simply add the Web-Stat plugin.\u003C\u002Fp>\n\u003Cp>You can install Web-Stat in just two steps: click on ‘install’, click on ‘activate’, and you are done! Web-Stat will initialize automatically.\u003C\u002Fp>\n\u003Cp>Our stats are live, fast, easy to use and very accurate. We are currently serving 125,000 web sites.\u003C\u002Fp>\n\u003Ch4>Plugin\u002F Theme Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>This plugin works out of the box for all themes\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Localization\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>English at \u003Ca href=\"https:\u002F\u002Fwww.web-stat.com\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fwww.web-stat.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>French at \u003Ca href=\"https:\u002F\u002Fwww.web-stat.fr\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fwww.web-stat.fr\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Spanish at \u003Ca href=\"https:\u002F\u002Fes.web-stat.com\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fes.web-stat.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Portuguese at \u003Ca href=\"https:\u002F\u002Fpt.web-stat.com\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fpt.web-stat.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Italian at \u003Ca href=\"https:\u002F\u002Fit.web-stat.com\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fit.web-stat.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>German at \u003Ca href=\"https:\u002F\u002Fde.web-stat.com\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fde.web-stat.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Turkish at \u003Ca href=\"https:\u002F\u002Ftr.web-stat.com\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Ftr.web-stat.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Russian at \u003Ca href=\"https:\u002F\u002Fru.web-stat.com\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fru.web-stat.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Japanese at \u003Ca href=\"https:\u002F\u002Fjp.web-stat.com\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fjp.web-stat.com\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Feedback\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>We are hoping for your suggestions and feedback – Thank you for using or trying out our plugin!\u003C\u002Fli>\n\u003Cli>Drop us a line on \u003Ca href=\"https:\u002F\u002Fwww.web-stat.com\u002Fcontact_us.htm\" rel=\"nofollow ugc\">our contact form\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Or follow us on \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002FLiveTrafficAnalysis\" rel=\"nofollow ugc\">our Facebook page\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Free, real-time stats for your web site with full visitors details. Add Web-Stat in just one click and check out your site's activity, live!",6000,103875,88,19,"2025-04-19T15:58:00.000Z","6.8.5","4.9.5","5.2.4",[19,20,4,21],"web-analytics","web-stats","webstat","https:\u002F\u002Fwww.web-stat.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fweb-stat.2.6.zip",99,1,0,"2021-02-23 00:00:00","2026-03-15T15:16:48.613Z",[30],{"id":31,"url_slug":32,"title":33,"description":34,"plugin_slug":4,"theme_slug":35,"affected_versions":36,"patched_in_version":37,"severity":38,"cvss_score":39,"cvss_vector":40,"vuln_type":41,"published_date":27,"updated_date":42,"references":43,"days_to_patch":45},"CVE-2021-24167","web-stat-api-key-disclosure","Web-Stat \u003C= 1.4.0 - API Key Disclosure","When visiting a site running Web-Stat \u003C 1.4.1, the \"wts_web_stat_load_init\" function used the visitor’s browser to send an XMLHttpRequest request to https:\u002F\u002Fwts2.one\u002Fajax.htm?action=lookup_WP_account. Issue was partially fixed in 1.4.0, (logged in users still able to see the key) and fully fixed in 1.4.1.",null,"\u003C=1.4.0","1.4.1","high",7.5,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N","Exposure of Sensitive Information to an Unauthorized Actor","2024-01-22 19:56:02",[44],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F83e396c3-e843-4337-bf90-894d9d7de2a8?source=api-prod",1064,{"slug":21,"display_name":5,"profile_url":7,"plugin_count":25,"total_installs":10,"avg_security_score":24,"avg_patch_time_days":45,"trust_score":47,"computed_at":48},78,"2026-04-04T07:12:35.896Z",[50,72,94,116,132],{"slug":51,"name":52,"version":37,"author":53,"author_profile":54,"description":55,"short_description":56,"active_installs":57,"downloaded":58,"rating":59,"num_ratings":60,"last_updated":61,"tested_up_to":62,"requires_at_least":63,"requires_php":64,"tags":65,"homepage":70,"download_link":71,"security_score":57,"vuln_count":26,"unpatched_count":26,"last_vuln_date":35,"fetched_at":28},"matomo-analytics","Matomo Tracker","Arnan de Gans","https:\u002F\u002Fprofiles.wordpress.org\u002Fadegans\u002F","\u003Cp>Track all the stats you need. That’s the goal of \u003Cstrong>Matomo Tracker\u003C\u002Fstrong>. And it doesn’t get any more simple than that.\u003Cbr \u002F>\nWhile other plugins are bloated with all kinds of barely-used features or add bulky dashboards. \u003Cstrong>Matomo Tracker\u003C\u002Fstrong> does not.\u003C\u002Fp>\n\u003Cp>Easily add the Matomo tracking code to your websites footer in under a minute with only a few clicks. Optionally extend the tracker with some useful features that both help you understand your visitors better and help you optimize the effectiveness of your website, and even SEO.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Matomo Tracker\u003C\u002Fstrong> is designed to be barebones but still provide a complete experience for the majority of people.\u003Cbr \u002F>\nCollect all the stats you need via the built-in Matomo tracking code.\u003Cbr \u002F>\nEasily track dead links or in-links that end up on 404 error pages so you can effectively take action and fix those issues. As a result, Google will like you more!\u003C\u002Fp>\n\u003Cp>Do you use RSS and Atom feeds? Ever wondered how effective they are? Yeah, me too!\u003Cbr \u002F>\nWith \u003Cstrong>Matomo Tracker\u003C\u002Fstrong> you can track incoming clicks from your RSS and Atom feeds.\u003C\u002Fp>\n\u003Cp>Matomo is a great tool if you don’t want to use Jetpack Stats, WP-Statistics and especially Google Analytics.\u003Cbr \u002F>\nOr simply if you want a second opinion. On my own websites I’ve used both Jetpack Stats and Matomo – Ofcourse I used \u003Cstrong>Matomo Tracker\u003C\u002Fstrong> to add the Matomo tracking code to my footer.\u003Cbr \u002F>\nMatomo can replace Google Analytics. If you use their self-hosted solution all data you record is yours without big data watching over your shoulder.\u003C\u002Fp>\n\u003Cp>No nonsense, just stats tracking!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Matomo Tracker\u003C\u002Fstrong> works with both self-hosted (on premise) and Matomo Cloud installations.\u003Cbr \u002F>\nCheck out Matomo here and register for an account on their website: \u003Ca href=\"https:\u002F\u002Fmatomo.org\" rel=\"nofollow ugc\">https:\u002F\u002Fmatomo.org\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Matomo Tracker\u003C\u002Fstrong> is not affiliated with Matomo.\u003C\u002Fp>\n","The easiest way to track visitors in Matomo. No nonsense, just stats!",100,5889,90,2,"2025-12-31T21:33:00.000Z","6.9.4","5.8","8.0",[66,67,68,69,20],"analytics","matomo","stats","tracker","https:\u002F\u002Fajdg.solutions\u002Fproduct\u002Fpaypal-surcharge-for-woocommerce\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmatomo-analytics.1.4.1.zip",{"slug":73,"name":74,"version":75,"author":76,"author_profile":77,"description":78,"short_description":79,"active_installs":80,"downloaded":81,"rating":82,"num_ratings":83,"last_updated":84,"tested_up_to":62,"requires_at_least":85,"requires_php":86,"tags":87,"homepage":90,"download_link":91,"security_score":24,"vuln_count":92,"unpatched_count":26,"last_vuln_date":93,"fetched_at":28},"plausible-analytics","Plausible Analytics","2.5.6","Plausible Insights OÜ","https:\u002F\u002Fprofiles.wordpress.org\u002Fplausible\u002F","\u003Cp>Plausible Analytics is an easy-to-use, open source, lightweight and privacy-friendly web analytics alternative to Google Analytics.\u003C\u002Fp>\n\u003Cp>Plausible Analytics doesn’t use cookies and is fully compliant with GDPR, CCPA and PECR. Made and hosted in the EU, powered by European-owned cloud infrastructure 🇪🇺.\u003C\u002Fp>\n\u003Cp>Take a look at \u003Ca href=\"https:\u002F\u002Fplausible.io\u002Fplausible.io\" rel=\"nofollow ugc\">the live demo\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>You need a subscription to Plausible Analytics to track your stats. There’s a free 30-day trial with no credit card required.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>We’re completely independent, self-funded, bootstrapped and debt-free. We’re not interested in raising funds or taking investment. We choose the subscription business model rather than surveillance capitalism. We’re operating a sustainable project funded solely by the fees that our subscribers pay us.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fplausible.io\u002F\" rel=\"nofollow ugc\">Visit our website\u003C\u002Fa> for full details.\u003C\u002Fp>\n\u003Ch3>Why use Plausible?\u003C\u002Fh3>\n\u003Cp>Google Analytics is frustrating to use, difficult to understand, slow to load and privacy-invasive. That’s why we built Plausible Analytics, a simple but powerful, lightweight, open source and privacy-friendly alternative.\u003C\u002Fp>\n\u003Cp>Here’s what makes Plausible a great Google Analytics alternative and why over 16,000 paying subscribers trust us with their website and business insights:\u003C\u002Fp>\n\u003Ch3>Smooth transition from Google Analytics\u003C\u002Fh3>\n\u003Cp>Plausible features a realtime dashboard, entry pages report and integration with Search Console. You can track your paid campaigns and conversions. You can invite team members. You can even \u003Ca href=\"https:\u002F\u002Fplausible.io\u002Fdocs\u002Fgoogle-analytics-import\" rel=\"nofollow ugc\">import your historical stats from Google Analytics\u003C\u002Fa>. Learn how to get the most out of \u003Ca href=\"https:\u002F\u002Fplausible.io\u002Fdocs\u002Fyour-plausible-experience\" rel=\"nofollow ugc\">your Plausible experience\u003C\u002Fa> and join thousands who have already migrated from Google Analytics.\u003C\u002Fp>\n\u003Ch3>Simple analytics at a glance\u003C\u002Fh3>\n\u003Cp>Plausible is simple analytics. It is easy to understand and it cuts through the noise. Check your site traffic and get all the essential insights on one page in one minute. There are no layers of menus, there is no need for you to build custom reports, custom dashboards or PowerPoint documents.\u003C\u002Fp>\n\u003Ch3>Lightweight script that keeps your site speed fast\u003C\u002Fh3>\n\u003Cp>Plausible is lightweight analytics. Our script is 75 times smaller than Google Analytics. Your page weight will be cut down, your site will load faster and you’ll reduce your carbon footprint for a greener and more sustainable web. A site with 100,000 monthly visitors can save 8.2 kg of CO2 emissions per year by switching.\u003C\u002Fp>\n\u003Ch3>No need for cookie banners or GDPR consent\u003C\u002Fh3>\n\u003Cp>Plausible is privacy-friendly analytics. All the site measurement is carried out absolutely anonymously. Cookies are not used and no personal data is collected. There are no persistent identifiers. No cross-site or cross-device tracking either. Your site data is not used for any other purposes. All visitor data is exclusively processed with servers owned and operated by European companies and it never leaves the EU.\u003C\u002Fp>\n\u003Ch3>Track events and marketing campaigns\u003C\u002Fh3>\n\u003Cp>Plausible is useful. Segment your audience by any metric you click on. Answer the important questions about your visitors, content and referral sources. Analyze paid campaigns using UTM parameters. Track scroll depth, site search terms, outbound link clicks, cloaked affiliate link clicks, file downloads, form completions, 404 error pages, post authors, post categories and custom taxonomies without manually configuring anything or writing any code.\u003C\u002Fp>\n\u003Ch3>Built-in WooCommerce and Easy Digital Downloads analytics\u003C\u002Fh3>\n\u003Cp>Plausible provides automated WooCommerce and Easy Digital Downloads analytics solutions to track conversions, revenue and attribution. Activities tracked include adding to cart, removing from cart, entering checkout and completing a purchase. A purchase funnel looking at the user journey from viewing a product to making a purchase is enabled to help you see the drop-off rates between the different steps, understand your cart abandonment rate and increase your conversions.\u003C\u002Fp>\n\u003Ch3>Invite team members and share your dashboard\u003C\u002Fh3>\n\u003Cp>Plausible is shareable. Your stats are private by default but you can choose to be transparent and make them public so anyone with your custom link can view them. You can also share your stats privately by generating a secure link. This link is impossible to guess but you can add password protection for extra security. You can invite team members and assign user roles too.\u003C\u002Fp>\n\u003Ch3>Transparent and open source software\u003C\u002Fh3>\n\u003Cp>Plausible is open source analytics. Our source code is available and accessible on GitHub so anyone can read it, inspect it and review it to verify that our actions match with our words. We welcome feedback and have a public roadmap. If you’re happy to manage your own infrastructure, you can self-host Plausible too.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Our product is updated several times per week and with our WordPress plugin you always have access to all the latest features\u003C\u002Fli>\n\u003Cli>Automatically includes tracking code in the header of your site\u003C\u002Fli>\n\u003Cli>Simple plugin settings page with easy options and an onboarding guide \u003C\u002Fli>\n\u003Cli>Get more accurate stats and count those who use adblockers by running the Plausible script as a first-party connection from your domain name\u003C\u002Fli>\n\u003Cli>View your Plausible stats directly in your WordPress dashboard (you can grant access to other user roles too)\u003C\u002Fli>\n\u003Cli>Tracking of admin users is disabled by default (you can also disable tracking of other user roles)\u003C\u002Fli>\n\u003Cli>Enable WooCommerce or Easy Digital Downloads revenue tracking\u003C\u002Fli>\n\u003Cli>Enable file downloads, external link clicks, cloaked affiliate link clicks, site search terms, form completions and 404 error pages tracking \u003C\u002Fli>\n\u003Cli>Enable automated tracking of post authors, post categories and custom taxonomies for better content analysis\u003C\u002Fli>\n\u003Cli>Custom events and custom dimensions can be setup using CSS class names directly in the WordPress editor, no JS knowledge needed\u003C\u002Fli>\n\u003Cli>Integrate with Google Search Console so you can see search queries people use to find your site in Google’s search results\u003C\u002Fli>\n\u003Cli>Import your historical Google Analytics stats\u003C\u002Fli>\n\u003Cli>Keep an eye on your traffic with weekly and\u002For monthly email and Slack reports\u003C\u002Fli>\n\u003Cli>Get traffic spike notifications via email or Slack so you don’t miss being on the Hacker News\u003C\u002Fli>\n\u003Cli>Tag your paid ads, emails and social media posts with UTM tags and analyze your ecommerce and marketing campaigns from click to conversion using marketing funnels \u003C\u002Fli>\n\u003Cli>Filter the dashboard by any metric that you click on to get further insights. Mix and match filters too\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For more information: \u003Ca href=\"https:\u002F\u002Fplausible.io\u002Fwordpress-analytics-plugin\" rel=\"nofollow ugc\">How to setup Plausible Analytics WordPress plugin\u003C\u002Fa>.\u003C\u002Fp>\n","Plausible Analytics is a privacy-friendly web analytics plugin for WordPress that is an easy-to-use, lightweight and more accurate  alternative to Goo &hellip;",10000,343380,98,30,"2026-02-17T10:56:00.000Z","5.9","7.2",[66,88,89,68,19],"google-analytics","privacy","https:\u002F\u002Fplausible.io","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fplausible-analytics.2.5.6.zip",3,"2023-08-16 00:00:00",{"slug":95,"name":96,"version":97,"author":98,"author_profile":99,"description":100,"short_description":101,"active_installs":102,"downloaded":103,"rating":104,"num_ratings":60,"last_updated":105,"tested_up_to":106,"requires_at_least":107,"requires_php":108,"tags":109,"homepage":113,"download_link":114,"security_score":115,"vuln_count":26,"unpatched_count":26,"last_vuln_date":35,"fetched_at":28},"audience-analytics-by-quantcast","Audience Analytics – by Quantcast","1.0.1","Quantcast","https:\u002F\u002Fprofiles.wordpress.org\u002Fquantcast\u002F","\u003Cp>Quantcast Measure provides fine-grained data about visitors to every page of your website. This includes statistics about platform usage (mobile vs. desktop) and site traffic, as well as audience demographics such as age, gender, geography, income, education, occupation, and family status.\u003C\u002Fp>\n\u003Cp>The product also goes deeper to offer detailed information about visitors’ favorite websites, shopping behavior, general interests & hobbies, media and entertainment preferences, and even political affiliations.\u003C\u002Fp>\n","Provides statistics about visitors to every page of your site: traffic, age, gender, shopping patterns, general interests and much more.",1000,26461,60,"2018-11-26T22:52:00.000Z","4.9.29","4.0","",[66,110,111,112,19],"audience-analytics","demographics","quantcast","https:\u002F\u002Fwww.quantcast.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faudience-analytics-by-quantcast.zip",85,{"slug":117,"name":118,"version":119,"author":117,"author_profile":120,"description":121,"short_description":122,"active_installs":102,"downloaded":123,"rating":57,"num_ratings":92,"last_updated":124,"tested_up_to":15,"requires_at_least":125,"requires_php":126,"tags":127,"homepage":129,"download_link":130,"security_score":24,"vuln_count":25,"unpatched_count":26,"last_vuln_date":131,"fetched_at":28},"usermaven","Usermaven","1.2.7","https:\u002F\u002Fprofiles.wordpress.org\u002Fusermaven\u002F","\u003Cp>Usermaven helps marketing and product teams turn more visitors into customers, get more people to use the product, and keep them coming back. No more guessing or relying on intuition – let data drive your success.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Effortless, no-code event tracking: Unlike other tools, Usermaven eliminates dependence on developers for tracking key actions performed by users on your website or app, including comprehensive WooCommerce store analytics.\u003C\u002Fli>\n\u003Cli>Analyze your marketing channels to increase ROI. See which traffic sources or campaigns are bringing in the most conversions and sales.\u003C\u002Fli>\n\u003Cli>Track and compare the performance of your marketing campaigns with UTMs.\u003C\u002Fli>\n\u003Cli>Track individual user behavior to understand their interests. See what they’re paying attention to, and make informed decisions.\u003C\u002Fli>\n\u003Cli>Get accurate stats with Adblocker bypassing and cookie-less tracking.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WooCommerce Integration\u003C\u002Fh4>\n\u003Cp>Usermaven automatically tracks all essential WooCommerce events to give you deep insights into your store’s performance:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Product Views: Track when customers view product pages\u003C\u002Fli>\n\u003Cli>Cart Actions: Monitor add-to-cart, remove-from-cart, and cart updates\u003C\u002Fli>\n\u003Cli>Checkout Process: Follow users through each step of your checkout funnel\u003C\u002Fli>\n\u003Cli>Purchase Events: Capture successful purchases with complete order details\u003C\u002Fli>\n\u003Cli>Product Categories: Understand which product categories drive the most interest\u003C\u002Fli>\n\u003Cli>Revenue Analytics: Get detailed revenue reports and purchase patterns\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why Usermaven?\u003C\u002Fh4>\n\u003Cp>Most firms try to use complex and expensive analytics platforms like Mixpanel or Amplitude but never get around to properly configuring them to get meaningful insights. You need a product analytics solution that’s easy to setup and has ready-made templates to generate actionable insights for making data-backed growth decisions.\u003C\u002Fp>\n\u003Cp>That’s why we built Usermaven, the new data scientist in your team. We are making product analytics affordable, easy to setup and simple to maintain.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Super Simple – Designed to be simple and intuitive in every way, without complexity or clutter to distract you. WooCommerce events are tracked automatically with zero configuration needed.\u003C\u002Fli>\n\u003Cli>Privacy Compliance – We’ve designed Usermaven to comply with GDPR and CCPA regulations from day one.\u003C\u002Fli>\n\u003Cli>System Security – We apply the latest security standards and take measures to ensure your data is safe with us.\u003C\u002Fli>\n\u003C\u002Ful>\n","Usermaven's web analytics product is a Google Analytics alternative that provides a real-time view of your website traffic metrics.",13296,"2026-01-14T09:30:00.000Z","3.0.1","5.6",[66,128,89,68,19],"google-analytics-alternative","https:\u002F\u002Fgithub.com\u002Fusermaven\u002Fwordpress","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fusermaven.1.2.7.zip","2025-03-28 00:00:00",{"slug":133,"name":134,"version":135,"author":136,"author_profile":137,"description":138,"short_description":139,"active_installs":102,"downloaded":140,"rating":26,"num_ratings":26,"last_updated":141,"tested_up_to":62,"requires_at_least":142,"requires_php":17,"tags":143,"homepage":148,"download_link":149,"security_score":150,"vuln_count":25,"unpatched_count":26,"last_vuln_date":151,"fetched_at":28},"zoho-marketinghub","Zoho Marketing Automation","1.3.6","Zoho Campaigns","https:\u002F\u002Fprofiles.wordpress.org\u002Fzoho-campaigns\u002F","\u003Cp>Zoho Marketing Automation is an all-in-one marketing automation software that helps you successfully manage your marketing activities across multiple channels. It allows you to generate, nurture, and qualify more leads into customers while also retaining them as loyal customers.\u003C\u002Fp>\n\u003Cp>Using the Zoho Marketing Automation plugin, you can analyze your website visitors’ behavior and activities, convert them into leads by embedding signup forms on your web pages, and utilize the new eCommerce integration to monitor shopping activities and boost conversions.\u003C\u002Fp>\n\u003Cp>With the Zoho Marketing Automation plugin, you can add:\u003C\u002Fp>\n\u003Ch4>Web Assistant\u003C\u002Fh4>\n\u003Cp>Analyze your website visitors’ actions, the pages they navigate, and the topics that interest them. Our behavior tracking tool helps you set up events for different actions on your web pages and set goals for your visitors to perform. Based on whether your visitors achieve or miss these goals, you can build personalized journeys that engage them, and help them convert into customers.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Choose whether you want to track all the pages on your site, only specific pages, or pages of specific categories.\u003C\u002Fli>\n\u003Cli>Using a ‘date’ option, you can choose to track the pages created after a selected date.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Signup Forms\u003C\u002Fh4>\n\u003Cp>Embed signup forms to your WordPress site and entice your web visitors to sign up for your content. Once they sign up, they’re automatically added as leads in the respective mailing lists inside your Marketing Automation account.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>You can fetch these signup forms from your Marketing Automation account and embed them on your site using short codes.\u003C\u002Fli>\n\u003Cli>Instantly show or hide a signup form on your site through a control within WordPress.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>eCommerce\u003C\u002Fh4>\n\u003Cp>Seamlessly transfer your WooCommerce store data to Marketing Automation 2.0 with simple integration methods. Start sending targeted emails, automate your ecommerce activities and personalize your marketing efforts with the help of MA 2.0 after you connect your WooCommerce store.\u003C\u002Fp>\n\u003Cp>Once the integration is complete, you can start utilizing the powerful features of MA 2.0 to boost your ecommerce activities and increase your sales. So why wait? Connect your store with MA 2.0 today and take your ecommerce game to the next level.\u003C\u002Fp>\n","Zoho Marketing Automation is an all-in-one marketing automation software that helps you successfully manage your marketing activities across multiple  &hellip;",27182,"2026-01-19T06:31:00.000Z","5.1.1",[144,145,146,19,147],"automation","marketing-hub","sign-up-form","website-tracking","https:\u002F\u002Fhelp.zoho.com\u002Fportal\u002Fen\u002Fkb\u002Fmarketing-automation\u002Fuser-guide\u002Fsettings\u002Fintegrations\u002Farticles\u002Fmarketingautomation-plugin-for-wordpress","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fzoho-marketinghub.zip",97,"2024-06-21 00:00:00",{"attackSurface":153,"codeSignals":207,"taintFlows":215,"riskAssessment":242,"analyzedAt":250},{"hooks":154,"ajaxHandlers":198,"restRoutes":204,"shortcodes":205,"cronEvents":206,"entryPointCount":25,"unprotectedCount":26},[155,162,166,170,173,177,181,184,190,194],{"type":156,"name":157,"callback":158,"priority":159,"file":160,"line":161},"action","init","init_options",5,"Web-Stat.php",36,{"type":156,"name":163,"callback":164,"file":160,"line":165},"plugins_loaded","load_textdomain",38,{"type":156,"name":167,"callback":168,"file":160,"line":169},"wp_enqueue_scripts","enqueue_scripts",39,{"type":156,"name":171,"callback":168,"file":160,"line":172},"admin_enqueue_scripts",40,{"type":156,"name":174,"callback":175,"file":160,"line":176},"admin_menu","add_admin_menu",42,{"type":156,"name":178,"callback":179,"file":160,"line":180},"wp_dashboard_setup","add_dashboard_widget",43,{"type":156,"name":178,"callback":182,"priority":102,"file":160,"line":183},"reorder_dashboard_widgets",44,{"type":185,"name":186,"callback":187,"priority":188,"file":160,"line":189},"filter","plugin_row_meta","add_plugin_row_meta",10,45,{"type":185,"name":191,"callback":192,"priority":188,"file":160,"line":193},"plugin_action_links","add_plugin_action_links",46,{"type":156,"name":195,"callback":196,"file":160,"line":197},"admin_head-plugins.php","add_custom_css",47,[199],{"action":200,"nopriv":201,"callback":200,"hasNonce":202,"hasCapCheck":201,"file":160,"line":203},"handle_ajax_data",false,true,41,[],[],[],{"dangerousFunctions":208,"sqlUsage":209,"outputEscaping":211,"fileOperations":25,"externalRequests":25,"nonceChecks":25,"capabilityChecks":213,"bundledLibraries":214},[],{"prepared":26,"raw":26,"locations":210},[],{"escaped":92,"rawEcho":26,"locations":212},[],4,[],[216,234],{"entryPoint":217,"graph":218,"unsanitizedCount":26,"severity":233},"handle_ajax_data (Web-Stat.php:137)",{"nodes":219,"edges":231},[220,225],{"id":221,"type":222,"label":223,"file":160,"line":224},"n0","source","$_POST (x2)",147,{"id":226,"type":227,"label":228,"file":160,"line":229,"wp_function":230},"n1","sink","update_option() [Settings Manipulation]",170,"update_option",[232],{"from":221,"to":226,"sanitized":202},"low",{"entryPoint":235,"graph":236,"unsanitizedCount":26,"severity":233},"\u003CWeb-Stat> (Web-Stat.php:0)",{"nodes":237,"edges":240},[238,239],{"id":221,"type":222,"label":223,"file":160,"line":224},{"id":226,"type":227,"label":228,"file":160,"line":229,"wp_function":230},[241],{"from":221,"to":226,"sanitized":202},{"summary":243,"deductions":244},"The \"web-stat\" plugin version 2.6 demonstrates a generally strong security posture based on the provided static analysis.  It utilizes prepared statements for all SQL queries, properly escapes all output, and implements nonce and capability checks on its single AJAX entry point. The absence of critical or high severity taint flows and dangerous function usage further reinforces this positive outlook. The plugin also avoids bundled libraries and only makes a single external HTTP request, reducing potential attack vectors.\n\nHowever, the plugin's vulnerability history presents a significant concern. It has a known CVE, specifically related to Exposure of Sensitive Information to an Unauthorized Actor, and while it's currently patched, the existence of past vulnerabilities, particularly a high-severity one, suggests a potential for recurring security flaws.  The single AJAX entry point, while protected by nonce and capability checks, still represents a potential target if future vulnerabilities are introduced.\n\nIn conclusion, while \"web-stat\" v2.6 implements several key security best practices, the past occurrence of a high-severity vulnerability indicates that ongoing vigilance and thorough auditing are necessary. The plugin's strengths lie in its secure coding practices for current analysis, but its historical track record necessitates a cautious approach.",[245,248],{"reason":246,"points":247},"Past high severity vulnerability",15,{"reason":249,"points":159},"Known CVE history","2026-03-16T18:06:19.055Z",{"wat":252,"direct":260},{"assetPaths":253,"generatorPatterns":255,"scriptPaths":256,"versionParams":258},[254],"\u002Fwp-content\u002Fplugins\u002Fweb-stat\u002Fjs\u002Fwts_script.js",[],[257],"https:\u002F\u002Fapp.ardalio.com\u002Fajax.pl",[259],"web-stat\u002Fjs\u002Fwts_script.js?ver=",{"cssClasses":261,"htmlComments":262,"htmlAttributes":263,"restEndpoints":264,"jsGlobals":265,"shortcodeOutput":267},[],[],[],[],[266],"wts_data",[]]