[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdnI2BNjb0CRvssIhfJd4l0utPNrGqDfFoZPqJzENX-4":3,"$frgmSesM4_X3Zw_t0FUMSgkT7CQgblibLUFdHs9CWxDQ":98,"$fs9TVfgjR9xQHxfmV5QBCK0pJZUIS4TnCdJB0kmOIyP4":103},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":22,"download_link":23,"security_score":24,"vuln_count":25,"unpatched_count":25,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":36,"analysis":37,"fingerprints":82},"wp-fixed-ads","Wp Fixed Ad code","1.0","Wuptii","https:\u002F\u002Fprofiles.wordpress.org\u002Fwuptii\u002F","\u003Cp>WP Fixed Ad code : Simple Plugin to Show fixed content in both sides of your website .\u003C\u002Fp>\n\u003Cp>Installation Guide:\u003C\u002Fp>\n\u003Cp>1.Upload the  plugin to your blog and just activate it.\u003C\u002Fp>\n\u003Cp>2.Goto your Settings->WP Fixed Ad code and then Edit its data as per requirement.\u003C\u002Fp>\n","Simple Plugin to Show fixed content in both sides of your website .",10,2127,100,2,"2014-08-08T10:19:00.000Z","3.9.40","3.5","",[20,21],"right-and-left-fixed-ad-slots","wordpress-fixed-ad-code","http:\u002F\u002Fmadmaskiner.dk\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-fixed-ads.zip",85,0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":14,"total_installs":32,"avg_security_score":24,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"wuptii",20,30,84,"2026-08-29T17:51:50.592Z",[],{"attackSurface":38,"codeSignals":62,"taintFlows":74,"riskAssessment":75,"analyzedAt":81},{"hooks":39,"ajaxHandlers":58,"restRoutes":59,"shortcodes":60,"cronEvents":61,"entryPointCount":25,"unprotectedCount":25},[40,46,50,54],{"type":41,"name":42,"callback":43,"file":44,"line":45},"action","wp_enqueue_scripts","madmas_addscripts","index.php",15,{"type":41,"name":47,"callback":48,"file":44,"line":49},"admin_init","madmas_general_settings",26,{"type":41,"name":51,"callback":52,"file":44,"line":53},"admin_menu","madmas_admin_menu",45,{"type":41,"name":55,"callback":56,"file":44,"line":57},"wp_footer","madmas_wpfoot",75,[],[],[],[],{"dangerousFunctions":63,"sqlUsage":64,"outputEscaping":66,"fileOperations":25,"externalRequests":25,"nonceChecks":25,"capabilityChecks":25,"bundledLibraries":73},[],{"prepared":25,"raw":25,"locations":65},[],{"escaped":25,"rawEcho":14,"locations":67},[68,71],{"file":44,"line":69,"context":70},65,"raw output",{"file":44,"line":72,"context":70},70,[],[],{"summary":76,"deductions":77},"The 'wp-fixed-ads' v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate responsible coding practices, with no dangerous functions, file operations, or external HTTP requests observed. The use of prepared statements for all SQL queries is a major positive, mitigating the risk of SQL injection vulnerabilities. \n\nHowever, a critical concern arises from the output escaping analysis. With 100% of the identified outputs being unescaped, this plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Any dynamic content rendered by the plugin without proper sanitization could be exploited by attackers to inject malicious scripts, leading to session hijacking, defacement, or redirection to malicious sites. The lack of recorded vulnerabilities in its history is positive but does not negate the current XSS risk posed by unescaped output.\n\nIn conclusion, while the plugin demonstrates good practices in attack surface reduction and SQL query handling, the complete lack of output escaping represents a significant and immediate security risk. This weakness needs to be addressed urgently to prevent potential XSS exploits.",[78],{"reason":79,"points":80},"100% of outputs are not properly escaped",8,"2026-03-16T23:49:41.544Z",{"wat":83,"direct":89},{"assetPaths":84,"generatorPatterns":86,"scriptPaths":87,"versionParams":88},[85],"\u002Fwp-content\u002Fplugins\u002Fwp-fixed-ads\u002Fcss\u002Fstyle.css",[],[],[],{"cssClasses":90,"htmlComments":93,"htmlAttributes":94,"restEndpoints":95,"jsGlobals":96,"shortcodeOutput":97},[91,92],"madmas_left_fx","madmas_right_fx",[],[],[],[],[],{"error":99,"url":100,"statusCode":101,"statusMessage":102,"message":102},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fwp-fixed-ads\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":25,"versions":104},[]]