[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYPlYrNOnhWiYsJBAHqFlJ2hwy3Hs_x_SKxu0gk1FKik":3,"$f-jhvBSvJBn463sybPt5FjlLZ5ilcJX8vEzzfRGKc12w":256,"$fQ3wqpJA1MYMhg568c2je_8t_RkmCV1q-WgL4pakVx0Q":261},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":17,"download_link":24,"security_score":25,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":35,"analysis":135,"fingerprints":235},"womp-wp-e-commerce-dashboard-reporter","WOMP WP E-Commerce Dashboard Reporter","0.2.4","wompteam","https:\u002F\u002Fprofiles.wordpress.org\u002Fwompteam\u002F","\u003Cp>Admin dashboard widgets showing information about your WP e-Commerce store.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Tables\u003C\u002Fli>\n\u003Cli>Graphs\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This is the initial version.\u003C\u002Fp>\n","Admin dashboard widgets showing information about your WP e-Commerce store.",10,2454,0,"2012-08-06T10:11:00.000Z","3.2.1","2.9","",[19,20,21,22,23],"dashboard","e-commerce","google-visualisation","graph","reporting","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwomp-wp-e-commerce-dashboard-reporter.0.2.4.zip",85,null,"2026-04-06T09:54:40.288Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},1,30,84,"2026-08-29T07:02:53.916Z",[36,63,84,100,118],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":46,"num_ratings":47,"last_updated":48,"tested_up_to":49,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":58,"download_link":59,"security_score":60,"vuln_count":31,"unpatched_count":13,"last_vuln_date":61,"fetched_at":62},"error-log-monitor","Error Log Monitor","1.7.12","Janis Elsts","https:\u002F\u002Fprofiles.wordpress.org\u002Fwhiteshadow\u002F","\u003Cp>This plugin adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send you email notifications about newly logged errors.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Automatically detects error log location.\u003C\u002Fli>\n\u003Cli>Explains how to configure PHP error logging if it’s not enabled yet.\u003C\u002Fli>\n\u003Cli>The number of displayed log entries is configurable.\u003C\u002Fli>\n\u003Cli>Sends you email notifications about logged errors (optional).\u003C\u002Fli>\n\u003Cli>Configurable email address and frequency.\u003C\u002Fli>\n\u003Cli>You can easily clear the log file.\u003C\u002Fli>\n\u003Cli>The dashboard widget is only visible to administrators.\u003C\u002Fli>\n\u003Cli>Optimized to work well even with very large log files.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Usage\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Once you’ve installed the plugin, go to the Dashboard and enable the “PHP Error Log” widget through the “Screen Options” panel. The widget should automatically display the last 20 lines from your PHP error log. If you see an error message like “Error logging is disabled” instead, follow the displayed instructions to configure error logging.\u003C\u002Fp>\n\u003Cp>Email notifications are disabled by default. To enable them, click the “Configure” link in the top-right corner of the widget and enter your email address in the “Periodically email logged errors to:” box. If desired, you can also change email frequency by selecting the minimum time interval between emails from the “How often to send email” drop-down.\u003C\u002Fp>\n","Adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send logged errors to email.",20000,641620,86,48,"2025-10-01T15:12:00.000Z","6.8.6","4.5","7.4",[53,54,55,56,57],"admin","administration","dashboard-widget","error-reporting","php","http:\u002F\u002Fw-shadow.com\u002Fblog\u002F2012\u002F07\u002F25\u002Ferror-log-monitor-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ferror-log-monitor.1.7.12.zip",99,"2019-02-25 00:00:00","2026-07-22T17:31:50.256Z",{"slug":64,"name":65,"version":66,"author":67,"author_profile":68,"description":69,"short_description":70,"active_installs":71,"downloaded":72,"rating":13,"num_ratings":13,"last_updated":73,"tested_up_to":74,"requires_at_least":75,"requires_php":76,"tags":77,"homepage":81,"download_link":82,"security_score":83,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":62},"business-kpi-reporting-dashboard","Business KPI Reporting Dashboard","1.1.0.33","blinkmetrics","https:\u002F\u002Fprofiles.wordpress.org\u002Fblinkmetrics\u002F","\u003Cp>BlinkMetrics brings all your website data (and data from other SaaS tools you use to run your business) into one single source of truth. This plugin lets you bring all your WordPress data into BlinkMetrics (requires an active account with \u003Ca href=\"https:\u002F\u002Fblinkmetrics.com\" rel=\"nofollow ugc\">BlinkMetrics\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Out of the box, BlinkMetrics has everything you need to keep your whole company on the same page. Decide which KPIs to track during onboarding, then sit back and relax as BlinkMetrics automatically pulls that data and gives you a real-time look into your business.\u003C\u002Fp>\n\u003Ch4>How do you know if business is going well?\u003C\u002Fh4>\n\u003Cp>If you need to open a dozen browser tabs to answer that question, we promise there’s a better way.\u003C\u002Fp>\n\u003Cp>BlinkMetrics automatically collects your KPIs and highlights where to focus your attention for maximum impact. With automated KPI tracking, you can catch problems early and identify growth opportunities.\u003C\u002Fp>\n\u003Cp>It takes 30 seconds to \u003Ca href=\"https:\u002F\u002Fblinkmetrics.com\u002Fschedule\u002F\" rel=\"nofollow ugc\">schedule a demo\u003C\u002Fa>; let’s build your single source of truth.\u003C\u002Fp>\n\u003Ch4>Automated KPI Reporting for WordPress & More!\u003C\u002Fh4>\n\u003Cp>Run a data-savvy operation without hiring a full team of developers or analysts. Enjoy Done-For-You Custom Reporting Dashboards – data visualizations built around your unique business model and KPIs. If you love a good spreadsheet, you’ll also feel right at home with our automated scorecards. All the clarity you crave, none of the tedious copy\u002Fpaste to get there.\u003C\u002Fp>\n\u003Cp>Integrations with Popular WordPress Plugins:\u003Cbr \u002F>\n* Easy Digital Downloads: Track sales data such as count of EDD licenses, customers, orders, and transactions.\u003Cbr \u002F>\n* Simply Schedule Appointments: Track the count of appointments, payments, appointment types, resources, and staff.\u003Cbr \u002F>\n* Gravity Forms: Track the count of forms and entries.\u003Cbr \u002F>\n* Ninja Forms: Track the count of entries.\u003Cbr \u002F>\n* Formidable Forms: Track the count of forms and entries.\u003Cbr \u002F>\n* Fluent Forms: Track the count of forms and entries.\u003Cbr \u002F>\n* WPForms: Track the count of entries.\u003Cbr \u002F>\n* Elementor Pro: Track the count of forms and entries.\u003C\u002Fp>\n\u003Cp>Integrations with WordPress Features:\u003Cbr \u002F>\n* Users: Track user data, including registration and activity metrics.\u003Cbr \u002F>\n* Posts: Published post data, including title, content, and metadata.\u003Cbr \u002F>\n* Plugins: Track count of installed Plugins and Plugins with Updates Available\u003C\u002Fp>\n\u003Ch4>Getting Started\u003C\u002Fh4>\n\u003Cp>To begin exposing data to BlinkMetrics:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Navigate to \u003Ccode>Tools\u003C\u002Fcode> > \u003Ccode>BlinkMetrics\u003C\u002Fcode> in your WordPress admin area.\u003C\u002Fli>\n\u003Cli>Choose the specific metrics you’d like to make accessible to BlinkMetrics and generate an API key.\u003C\u002Fli>\n\u003Cli>Add your website as a data source within BlinkMetrics, providing the API key that you generated in step 2.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Business KPI Reporting Dashboard is not just a tool for internal reporting but also a gateway to broader data utilization and external service enhancements.\u003C\u002Fp>\n\u003Cp>Check out the \u003Ca href=\"https:\u002F\u002Fblinkmetrics.com\u002Fguides\u002Fwordpress-site-connection\u002F\" rel=\"nofollow ugc\">full guide to begin automating your WordPress data tracking\u003C\u002Fa>\u003C\u002Fp>\n","Unlock growth with Custom Reporting Dashboards and automated KPI scorecards. BlinkMetrics simplifies business data analytics as we automatically pull  &hellip;",90,4546,"2026-07-21T17:35:00.000Z","7.1","5.4","7.2",[19,78,79,23,80],"kpi","metrics","reports","https:\u002F\u002Fblinkmetrics.io\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbusiness-kpi-reporting-dashboard.zip",100,{"slug":85,"name":86,"version":87,"author":88,"author_profile":89,"description":90,"short_description":91,"active_installs":11,"downloaded":92,"rating":13,"num_ratings":13,"last_updated":93,"tested_up_to":94,"requires_at_least":95,"requires_php":17,"tags":96,"homepage":17,"download_link":99,"security_score":25,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":62},"client-dash-status-cake-add-on","Client Dash Status Cake Add on","0.2.2","Kyle Maurer","https:\u002F\u002Fprofiles.wordpress.org\u002Fbrashrebel\u002F","\u003Ch4>What it does\u003C\u002Fh4>\n\u003Cp>This plugin brings the amazing uptime reporting power of Status Cake into the WordPress dashboard by integrating with Client Dash.\u003C\u002Fp>\n\u003Ch4>Requirements\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>An account on Status Cake\u003C\u002Fli>\n\u003Cli>[Client Dash] (https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fclient-dash) plugin version 1.4 or higher\u003C\u002Fli>\n\u003C\u002Ful>\n","What it does",2189,"2014-08-13T19:28:00.000Z","3.9.40","3.8.0",[53,97,19,98,23],"client","portal","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fclient-dash-status-cake-add-on.0.2.2.zip",{"slug":101,"name":102,"version":103,"author":104,"author_profile":105,"description":106,"short_description":107,"active_installs":11,"downloaded":108,"rating":83,"num_ratings":31,"last_updated":109,"tested_up_to":110,"requires_at_least":111,"requires_php":17,"tags":112,"homepage":116,"download_link":117,"security_score":25,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":62},"ecommerce-shopping-cart-by-inventorycom","eCommerce Shopping Cart by Inventory.com","1.0.2","inventory","https:\u002F\u002Fprofiles.wordpress.org\u002Finventory\u002F","\u003Cp>eCommerce Shopping Cart by Inventory.com is web store frontend for our powerful Inventory.com platform. We include full suite to manage your online business:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Product management\u003C\u002Fli>\n\u003Cli>Inventory management\u003C\u002Fli>\n\u003Cli>Procurement management\u003C\u002Fli>\n\u003Cli>Order management\u003C\u002Fli>\n\u003Cli>Customer and supplier management\u003C\u002Fli>\n\u003Cli>Loyalty and promotions\u003C\u002Fli>\n\u003Cli>Powerful reporting\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Rich product information\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Name, code, EAN, description, brand, manufacturer, supplier, price, stock level\u003C\u002Fli>\n\u003Cli>Length, width, height, volume, weight\u003C\u002Fli>\n\u003Cli>Custom product parameters\u003C\u002Fli>\n\u003Cli>Images and files served from CDN\u003C\u002Fli>\n\u003Cli>Product variations (matrix products) with different prices\u003C\u002Fli>\n\u003Cli>Related products and substitute products\u003C\u002Fli>\n\u003Cli>Organize products into product group tree.\u003C\u002Fli>\n\u003Cli>You can pick which product and groups are displayed in web store.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Inventory backend features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Min\u002FMax ordering\u003C\u002Fli>\n\u003Cli>Automated stock replenishment\u003C\u002Fli>\n\u003Cli>Multiple price lists support\u003C\u002Fli>\n\u003Cli>Inventory Transfers\u003C\u002Fli>\n\u003Cli>Forecasting analytics\u003C\u002Fli>\n\u003Cli>Fully featured Supplier Purchasing & Receiving\u003C\u002Fli>\n\u003Cli>Flexible attribute support\u003C\u002Fli>\n\u003Cli>Matrix products\u003C\u002Fli>\n\u003Cli>Across company stock visibility\u003C\u002Fli>\n\u003Cli>EDI support\u003C\u002Fli>\n\u003Cli>Supplier database\u003C\u002Fli>\n\u003Cli>Supplier price list management\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Sell more Features for eCommerce\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Gift card support\u003C\u002Fli>\n\u003Cli>Customer Loyalty programs\u003C\u002Fli>\n\u003Cli>Fully Featured Sales Promotion module\u003C\u002Fli>\n\u003Cli>Built-in coupon generator\u003C\u002Fli>\n\u003Cli>Sales promotion ROI analytics\u003C\u002Fli>\n\u003Cli>Gift or product kits\u003C\u002Fli>\n\u003Cli>Suggested products\u003C\u002Fli>\n\u003Cli>Price lists\u003C\u002Fli>\n\u003Cli>Customer purchase history\u003C\u002Fli>\n\u003Cli>Customer grouping\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Management and HeadOffice Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Store level drill down reporting\u003C\u002Fli>\n\u003Cli>Store Comparison reporting\u003C\u002Fli>\n\u003Cli>Time period comparison reporting\u003C\u002Fli>\n\u003Cli>Custom report generator\u003C\u002Fli>\n\u003Cli>Supplier purchasing analytics\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Constant Innovation\u003C\u002Fh4>\n\u003Cp>We are backed by SaaS model and its ability to provide customers with automatic, consistent upgrades to the system. However what good are automatic updates if the offerings are not innovative? At Inventory.com our pioneering development team focuses on adding tools that promote growth and retention. Leave the market research up to us; it is what we do best\u003C\u002Fp>\n","eCommerce Shopping Cart plugin backed by a powerful order and inventory management service.",7803,"2014-01-27T15:58:00.000Z","3.7.41","3.5",[113,19,20,114,115],"commerce","ecommerce","reportin","http:\u002F\u002Fwww.inventory.com\u002Fecommerce-shopping-cart\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fecommerce-shopping-cart-by-inventorycom.1.0.2.zip",{"slug":119,"name":120,"version":121,"author":122,"author_profile":123,"description":124,"short_description":125,"active_installs":11,"downloaded":126,"rating":83,"num_ratings":31,"last_updated":127,"tested_up_to":128,"requires_at_least":129,"requires_php":51,"tags":130,"homepage":17,"download_link":134,"security_score":83,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":62},"js-error-logger","JS Error Logger","1.5","JFG Media","https:\u002F\u002Fprofiles.wordpress.org\u002Fjfgmedia\u002F","\u003Cp>The plugin catches most JS errors, logs them, and displays them in a dashboard widget.\u003C\u002Fp>\n\u003Cp>Here are some of its features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\nExcept for the plugin settings, there is no database storage involved. Log is written in a “.log” file.\n\u003C\u002Fli>\n\u003Cli>\nDisplay latest JS errors in a dashboard widget.\n\u003C\u002Fli>\n\u003Cli>\nRefresh errors from the dashboard widget.\n\u003C\u002Fli>\n\u003Cli>\nSee the full error log on a separate page.\n\u003C\u002Fli>\n\u003Cli>\nIgnore errors if the user agent contains a specific string.\n\u003C\u002Fli>\n\u003Cli>\nIgnore errors if the error contains a specific string.\n\u003C\u002Fli>\n\u003Cli>\nIgnore errors if the script url contains a specific string.\n\u003C\u002Fli>\n\u003Cli>\nSee which page and which script triggered the errors.\n\u003C\u002Fli>\n\u003Cli>\nChoose the maximum amount of errors to log per page load.\n\u003C\u002Fli>\n\u003Cli>\nExclude logging errors from specific post types.\n\u003C\u002Fli>\n\u003Cli>\nChoose how ajax calls are made.\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Developer hooks and filters\u003C\u002Fh4>\n\u003Cp>The plugin cleans the log every 24 hours, to only keep the last 100 entries.\u003Cbr \u002F>\nYou may use the “jserrlog_max_log_entries” WP filter to enable more or less entries, by returning an integer: \u003Ccode>add_filter('jserrlog_max_log_entries',function(){return 200;})\u003C\u002Fcode>\u003C\u002Fp>\n\u003Cp>Alter error data:\u003Cbr \u002F>\nYou may use the “jserrlog_pre_insert_error” WP filter to modify the error data before it’s inserted into the log file: \u003Ccode>add_filter('jserrlog_pre_insert_error',function($error_data){return $error_data;})\u003C\u002Fcode>\u003C\u002Fp>\n\u003Cp>Trigger integrations:\u003Cbr \u002F>\nYou may use the “jserrlog_after_log” WP hook to trigger an action (Slack notification, etc.) after an error was logged: \u003Ccode>add_action('jserrlog_after_log',function($error_data){\u002F\u002Fdo something})\u003C\u002Fcode>\u003C\u002Fp>\n\u003Cp>Backup old errors:\u003Cbr \u002F>\nYou may use the “jserrlog_before_log_maintenance” WP hook to trigger an action (archive errors, etc.) before old errors are deleted: \u003Ccode>add_action('jserrlog_before_log_maintenance',function($errors){\u002F\u002Fdo something})\u003C\u002Fcode>\u003C\u002Fp>\n\u003Cp>Request hardening:\u003Cbr \u002F>\nYou may use the “jserrlog_enforce_same_host_origin” WP filter to require same-host Origin\u002FReferer checks for logging requests (default true): \u003Ccode>add_filter('jserrlog_enforce_same_host_origin',function(){return true;})\u003C\u002Fcode>\u003Cbr \u002F>\nYou may use the “jserrlog_rate_limit_requests” and “jserrlog_rate_limit_window” WP filters to control request throttling (defaults: 60 requests per 60 seconds): \u003Ccode>add_filter('jserrlog_rate_limit_requests',function(){return 120;}); add_filter('jserrlog_rate_limit_window',function(){return 60;});\u003C\u002Fcode>\u003Cbr \u002F>\nYou may use the “jserrlog_max_payload_bytes”, “jserrlog_max_batch_errors” and “jserrlog_max_error_field_length” WP filters to limit incoming payload sizes (defaults: 16384 bytes, 20 errors per batch, 512 chars per field): \u003Ccode>add_filter('jserrlog_max_payload_bytes',function(){return 32768;});\u003C\u002Fcode>\u003Cbr \u002F>\nYou may use the “jserrlog_duplicate_window” WP filter to suppress duplicate errors for a short period (default: 60 seconds): \u003Ccode>add_filter('jserrlog_duplicate_window',function(){return 30;});\u003C\u002Fcode>\u003C\u002Fp>\n\u003Ch4>Multisite\u003C\u002Fh4>\n\u003Cp>The plugin works with multisite. There’s one error log per site.\u003C\u002Fp>\n","Logs front-end javascript errors, and displays them in a dashboard widget",1877,"2026-05-26T03:59:00.000Z","7.0.2","5.0",[55,131,56,132,133],"debug","javascript","js","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fjs-error-logger.1.5.zip",{"attackSurface":136,"codeSignals":167,"taintFlows":223,"riskAssessment":224,"analyzedAt":234},{"hooks":137,"ajaxHandlers":148,"restRoutes":163,"shortcodes":164,"cronEvents":165,"entryPointCount":166,"unprotectedCount":166},[138,144],{"type":139,"name":140,"callback":141,"file":142,"line":143},"action","wp_dashboard_setup","womp_wpcs_dr_add_dashboard_widgets","womp-wpcs-dr.php",66,{"type":139,"name":145,"callback":146,"file":142,"line":147},"init","womp_wpcs_dr_init",77,[149,155,159],{"action":150,"nopriv":151,"callback":152,"hasNonce":151,"hasCapCheck":151,"file":153,"line":154},"womp-wpcs-dr-product-sales",false,"womp_wpcs_dr_ajax_product_sales","womp-wpcs-dr-widgets.php",72,{"action":156,"nopriv":151,"callback":157,"hasNonce":151,"hasCapCheck":151,"file":153,"line":158},"womp-wpcs-dr-recent-orders","womp_wpcs_dr_ajax_recent_orders",105,{"action":160,"nopriv":151,"callback":161,"hasNonce":151,"hasCapCheck":151,"file":153,"line":162},"womp-wpcs-dr-sales","womp_wpcs_dr_ajax_sales",151,[],[],[],3,{"dangerousFunctions":168,"sqlUsage":169,"outputEscaping":178,"fileOperations":13,"externalRequests":13,"nonceChecks":13,"capabilityChecks":31,"bundledLibraries":222},[],{"prepared":170,"raw":171,"locations":172},9,2,[173,176],{"file":142,"line":174,"context":175},33,"$wpdb->get_var() with variable interpolation",{"file":142,"line":177,"context":175},37,{"escaped":13,"rawEcho":179,"locations":180},20,[181,185,187,189,191,193,195,198,200,202,204,205,207,209,211,212,214,216,218,220],{"file":182,"line":183,"context":184},"womp-wpcs-dr-ajax.php",97,"raw output",{"file":182,"line":186,"context":184},122,{"file":182,"line":188,"context":184},152,{"file":182,"line":190,"context":184},176,{"file":182,"line":192,"context":184},236,{"file":182,"line":194,"context":184},292,{"file":196,"line":197,"context":184},"womp-wpcs-dr-functions.php",187,{"file":153,"line":199,"context":184},34,{"file":153,"line":201,"context":184},40,{"file":153,"line":203,"context":184},46,{"file":153,"line":46,"context":184},{"file":153,"line":206,"context":184},87,{"file":153,"line":208,"context":184},88,{"file":153,"line":210,"context":184},89,{"file":153,"line":71,"context":184},{"file":153,"line":213,"context":184},95,{"file":153,"line":215,"context":184},96,{"file":153,"line":217,"context":184},101,{"file":153,"line":219,"context":184},123,{"file":153,"line":221,"context":184},129,[],[],{"summary":225,"deductions":226},"The \"womp-wp-e-commerce-dashboard-reporter\" plugin, version 0.2.4, exhibits significant security concerns primarily due to its unprotected AJAX endpoints. With three AJAX handlers identified, all of which lack authentication checks, a substantial attack surface is exposed. This means any unauthenticated user could potentially interact with these handlers, leading to unauthorized actions or data exposure if they are vulnerable. The absence of nonce checks further exacerbates this risk, as it bypasses a fundamental WordPress security mechanism designed to prevent Cross-Site Request Forgery (CSRF) attacks. The code analysis also reveals a critical weakness in output escaping, with 0% of outputs being properly escaped. This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the application, which could then be executed in the browsers of other users. While the plugin does not show any known CVEs or recorded vulnerabilities historically, and most SQL queries utilize prepared statements, these strengths are overshadowed by the fundamental security oversights in its AJAX endpoint handling and output sanitization.",[227,229,231],{"reason":228,"points":11},"Unprotected AJAX handlers",{"reason":230,"points":11},"Missing nonce checks on AJAX",{"reason":232,"points":233},"Unescaped output",8,"2026-03-16T23:17:28.087Z",{"wat":236,"direct":246},{"assetPaths":237,"generatorPatterns":240,"scriptPaths":241,"versionParams":243},[238,239],"\u002Fwp-content\u002Fplugins\u002Fwomp-wp-e-commerce-dashboard-reporter\u002Fwomp-wpcs-dr.css","\u002Fwp-content\u002Fplugins\u002Fwomp-wp-e-commerce-dashboard-reporter\u002Fwomp-wpcs-dr.js",[],[242],"https:\u002F\u002Fwww.google.com\u002Fjsapi",[244,245],"womp-wpcs-dr.css?ver=","womp-wpcs-dr.js?ver=",{"cssClasses":247,"htmlComments":251,"htmlAttributes":252,"restEndpoints":253,"jsGlobals":254,"shortcodeOutput":255},[248,249,250],"womp-wpcs-dr-widget-product-sales","womp-wpcs-dr-widget-sales","womp-wpcs-dr-widget-recent-orders",[],[],[],[],[],{"error":257,"url":258,"statusCode":259,"statusMessage":260,"message":260},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fwomp-wp-e-commerce-dashboard-reporter\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":233,"versions":262},[263,268,275,281,288,295,302,309],{"version":6,"download_url":24,"svn_tag_url":264,"released_at":26,"has_diff":151,"diff_files_changed":265,"diff_lines":26,"trac_diff_url":266,"vulnerabilities":267,"is_current":257},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwomp-wp-e-commerce-dashboard-reporter\u002Ftags\u002F0.2.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.2.3&new_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.2.4",[],{"version":269,"download_url":270,"svn_tag_url":271,"released_at":26,"has_diff":151,"diff_files_changed":272,"diff_lines":26,"trac_diff_url":273,"vulnerabilities":274,"is_current":151},"0.2.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwomp-wp-e-commerce-dashboard-reporter.0.2.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwomp-wp-e-commerce-dashboard-reporter\u002Ftags\u002F0.2.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.2.2&new_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.2.3",[],{"version":87,"download_url":276,"svn_tag_url":277,"released_at":26,"has_diff":151,"diff_files_changed":278,"diff_lines":26,"trac_diff_url":279,"vulnerabilities":280,"is_current":151},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwomp-wp-e-commerce-dashboard-reporter.0.2.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwomp-wp-e-commerce-dashboard-reporter\u002Ftags\u002F0.2.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.2.1&new_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.2.2",[],{"version":282,"download_url":283,"svn_tag_url":284,"released_at":26,"has_diff":151,"diff_files_changed":285,"diff_lines":26,"trac_diff_url":286,"vulnerabilities":287,"is_current":151},"0.2.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwomp-wp-e-commerce-dashboard-reporter.0.2.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwomp-wp-e-commerce-dashboard-reporter\u002Ftags\u002F0.2.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.2&new_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.2.1",[],{"version":289,"download_url":290,"svn_tag_url":291,"released_at":26,"has_diff":151,"diff_files_changed":292,"diff_lines":26,"trac_diff_url":293,"vulnerabilities":294,"is_current":151},"0.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwomp-wp-e-commerce-dashboard-reporter.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwomp-wp-e-commerce-dashboard-reporter\u002Ftags\u002F0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.1.2&new_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.2",[],{"version":296,"download_url":297,"svn_tag_url":298,"released_at":26,"has_diff":151,"diff_files_changed":299,"diff_lines":26,"trac_diff_url":300,"vulnerabilities":301,"is_current":151},"0.1.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwomp-wp-e-commerce-dashboard-reporter.0.1.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwomp-wp-e-commerce-dashboard-reporter\u002Ftags\u002F0.1.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.1.1&new_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.1.2",[],{"version":303,"download_url":304,"svn_tag_url":305,"released_at":26,"has_diff":151,"diff_files_changed":306,"diff_lines":26,"trac_diff_url":307,"vulnerabilities":308,"is_current":151},"0.1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwomp-wp-e-commerce-dashboard-reporter.0.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwomp-wp-e-commerce-dashboard-reporter\u002Ftags\u002F0.1.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.1&new_path=%2Fwomp-wp-e-commerce-dashboard-reporter%2Ftags%2F0.1.1",[],{"version":310,"download_url":311,"svn_tag_url":312,"released_at":26,"has_diff":151,"diff_files_changed":313,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":314,"is_current":151},"0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwomp-wp-e-commerce-dashboard-reporter.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwomp-wp-e-commerce-dashboard-reporter\u002Ftags\u002F0.1\u002F",[],[]]