[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhX3ITN_YMuDqf7GG6YoGThol2VxorFKaNo1obbkbuBg":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":21,"download_link":22,"security_score":23,"vuln_count":24,"unpatched_count":24,"last_vuln_date":25,"fetched_at":26,"vulnerabilities":27,"developer":28,"crawl_stats":25,"alternatives":34,"analysis":35,"fingerprints":71},"wp-digital-clock","Wp Digital clock","2.0","amanhstu","https:\u002F\u002Fprofiles.wordpress.org\u002Famanhstu\u002F","\u003Cp>This is an awesome digital clock that you can use in wp using shortcode. But in one page you can have only one clock for now. If you repeat the shortcode in a page more than one times then it will show only first one. just install it and use the shortcode “[wp_digital_clock]” anywhere in your page and you are done. I am working on it still to give options like change the color of the digit etc. Be connected\u003C\u002Fp>\n","This is an awesome digital clock that you can use in wp using shortcode.",40,3382,100,3,"2024-03-14T17:27:00.000Z","6.4.8","4.0","7.0",[20],"digitalclock","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-digital-clock.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":29,"total_installs":30,"avg_security_score":23,"avg_patch_time_days":31,"trust_score":32,"computed_at":33},2,60,30,84,"2026-04-04T23:03:40.826Z",[],{"attackSurface":36,"codeSignals":54,"taintFlows":61,"riskAssessment":62,"analyzedAt":70},{"hooks":37,"ajaxHandlers":44,"restRoutes":45,"shortcodes":46,"cronEvents":52,"entryPointCount":53,"unprotectedCount":24},[38],{"type":39,"name":40,"callback":41,"file":42,"line":43},"action","wp_enqueue_scripts","wpdc_scripts_load_cdn","wp-digital-clock.php",26,[],[],[47],{"tag":48,"callback":49,"file":50,"line":51},"wp_digital_clock","wp_digital_clock_function","main-body.php",24,[],1,{"dangerousFunctions":55,"sqlUsage":56,"outputEscaping":58,"fileOperations":24,"externalRequests":24,"nonceChecks":24,"capabilityChecks":24,"bundledLibraries":60},[],{"prepared":24,"raw":24,"locations":57},[],{"escaped":24,"rawEcho":24,"locations":59},[],[],[],{"summary":63,"deductions":64},"The wp-digital-clock plugin version 2.0 exhibits a strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices, with all SQL queries utilizing prepared statements and all outputs being properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. Furthermore, the plugin has no recorded vulnerabilities, including no known CVEs, indicating a history of stable and secure development.\n\nWhile the static analysis reveals a minimal attack surface with only one shortcode and no AJAX handlers or REST API routes exposed without authentication, a notable concern is the complete absence of nonce checks and capability checks. This means that the plugin's functionality, even though currently limited in entry points, is not protected against potential cross-site request forgery (CSRF) attacks or unauthorized access by users without the necessary permissions if new entry points are added or existing ones are modified in future versions.\n\nIn conclusion, wp-digital-clock v2.0 is commendably secure regarding direct code execution vulnerabilities and data handling. However, the lack of authentication and authorization checks on its sole entry point (the shortcode) presents a significant potential weakness that could be exploited if the plugin's functionality expands or if an attacker can trick a logged-in user into interacting with it in an unintended way. This oversight, despite an otherwise clean record, warrants attention for future development.",[65,68],{"reason":66,"points":67},"Missing nonce checks",7,{"reason":69,"points":67},"Missing capability checks","2026-03-16T22:16:15.214Z",{"wat":72,"direct":81},{"assetPaths":73,"generatorPatterns":76,"scriptPaths":77,"versionParams":78},[74,75],"\u002Fwp-content\u002Fplugins\u002Fwp-digital-clock\u002Fcss\u002Fstyle.css","\u002Fwp-content\u002Fplugins\u002Fwp-digital-clock\u002Fjs\u002Ftime-js.js",[],[75],[79,80],"wp-digital-clock\u002Fcss\u002Fstyle.css?ver=","wp-digital-clock\u002Fjs\u002Ftime-js.js?ver=",{"cssClasses":82,"htmlComments":83,"htmlAttributes":84,"restEndpoints":85,"jsGlobals":86,"shortcodeOutput":88},[],[],[],[],[87],"currentTime",[89],"\u003Cdiv id=\"clock\">\u003C\u002Fdiv>"]