[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAtCrX0OXNOSH_OgIOW8TS190LMP_PqrzOuUCztTHPJg":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":27,"vuln_count":28,"unpatched_count":29,"last_vuln_date":30,"fetched_at":31,"vulnerabilities":32,"developer":61,"crawl_stats":38,"alternatives":69,"analysis":176,"fingerprints":213},"wp-flipclock","WP Flipclock","1.10.1","Rhys Wynne","https:\u002F\u002Fprofiles.wordpress.org\u002Frhyswynne\u002F","\u003Cp>WP Flipclock is a plugin that allows you to quickly and easily add a flipclock to your site’s posts and pages via a shortcode.\u003C\u002Fp>\n\u003Cp>The plugin allows you to count down or up from a specific date, as well as choose whether you count down days, hours or minutes.\u003C\u002Fp>\n\u003Cp>To use the plugin in your site, all you need to add to the page is the \u003Ccode>[flipclock]\u003C\u002Fcode> shortcode. There are various attributes you can add as well:-\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>name\u003C\u002Fstrong> – Give the flipclock a name. Default is “flipclock”. If you have more than one flipclock on any page it’s useful to give them unique names.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>countdown (True\u002FFalse)\u003C\u002Fstrong> – Allows you to count down to a date (true), or count up from a date (false). Default is \u003Cem>false\u003C\u002Fem>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>date\u003C\u002Fstrong> – Any date string, formatted how you like, which the clock will count up from\u002Fdown to. Default is \u003Cem>none\u003C\u002Fem>.\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>face (days\u002Fhours\u002Fminutes)\u003C\u002Fstrong> – The face of the clock. Default is hours. Options are:-\u003C\u002Fp>\n\u003Cul>\n\u003Cli>days – Days : Hours : Minutes : Seconds\u003C\u002Fli>\n\u003Cli>hours – Hours : Minutes : seconds\u003C\u002Fli>\n\u003Cli>minutes – Minutes : Seconds\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>lang\u003C\u002Fstrong> – Changes the language of the labels (days,hours,minutes,seconds). Supported languages: English, Russian, Spanish, French, German.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>timezone\u003C\u002Fstrong> – Sets timezone for date. Now it shows the correct time before the event. The time zones have unique names in the form “Area\u002FLocation”, e.g. “America\u002FNew_York”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>seconds\u003C\u002Fstrong> – Hides|shows seconds in face-mode “days”.\n\u003Cul>\n\u003Cli>1 – shows seconds\u003C\u002Fli>\n\u003Cli>0 – hide seconds\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>hidelabel\u003C\u002Fstrong> – Adds the ability to hide the labels.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin uses the \u003Ca href=\"http:\u002F\u002Fwww.flipclockjs.com\" rel=\"nofollow ugc\">Flipclock.js\u003C\u002Fa> library from \u003Ca href=\"https:\u002F\u002Fwww.objectivehtml.com\u002F\" rel=\"nofollow ugc\">ObjectiveHTML\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Further support and examples are on the \u003Ca href=\"https:\u002F\u002Fwww.winwar.co.uk\u002Fdocumentation\u002Fwp-flipclock\u002F?utm_source=description&utm_medium=wordpressorgreadme&utm_campaign=wpflipclock\" rel=\"nofollow ugc\">WP Flipclock Documentation\u003C\u002Fa> page.\u003C\u002Fp>\n\u003Ch4>About Winwar Media\u003C\u002Fh4>\n\u003Cp>This plugin is made by \u003Ca href=\"https:\u002F\u002Fwww.winwar.co.uk\u002F?utm_source=aboutwinwarmedia&utm_medium=wordpressorgreadme&utm_campaign=wpflipclock\" rel=\"nofollow ugc\">\u003Cstrong>Winwar Media\u003C\u002Fstrong>\u003C\u002Fa>, a WordPress Development and Training Agency in Manchester, UK.\u003C\u002Fp>\n\u003Cp>Why don’t you?\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Check out our book, \u003Ca href=\"https:\u002F\u002Fwww.winwar.co.uk\u002Fbooks\u002Fbbpress-complete\u002F?utm_source=aboutwinwarmedia&utm_medium=wordpressorgreadme&utm_campaign=wpflipclock\" rel=\"nofollow ugc\">bbPress Complete\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Check out our other \u003Ca href=\"https:\u002F\u002Fwww.winwar.co.uk\u002Fplugins\u002F?utm_source=aboutwinwarmedia&utm_medium=wordpressorgreadme&utm_campaign=wpflipclock\" rel=\"nofollow ugc\">WordPress Plugins\u003C\u002Fa>, including \u003Ca href=\"http:\u002F\u002Fwpemailcapture.com\" rel=\"nofollow ugc\">WP Email Capture\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Follow us on Social Media, such as \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fwinwaruk\" rel=\"nofollow ugc\">Facebook\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Ftwitter.com\u002Fwinwaruk\" rel=\"nofollow ugc\">Twitter\u003C\u002Fa> or \u003Ca href=\"https:\u002F\u002Fplus.google.com\u002F+WinwarCoUk\" rel=\"nofollow ugc\">Google+\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.winwar.co.uk\u002Fcontact-us\u002F?utm_source=aboutwinwarmedia&utm_medium=wordpressorgreadme&utm_campaign=wpflipclock\" rel=\"nofollow ugc\">Send us an email\u003C\u002Fa>! We like hearing from plugin users.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>For Support\u003C\u002Fh4>\n\u003Cp>We offer support in two places:-\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Support on the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fwp-flipclock\" rel=\"ugc\">WordPress.org Support Board\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>A \u003Ca href=\"https:\u002F\u002Fwww.winwar.co.uk\u002Fpriority-support\u002F?utm_source=forsupport&utm_medium=wordpressorgreadme&utm_campaign=wpflipclock\" rel=\"nofollow ugc\">priority support forum\u003C\u002Fa>, which offers same-day responses.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>On Github\u003C\u002Fh4>\n\u003Cp>This project is now on github, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Frhyswynne\u002Fwp-flipclock\" rel=\"nofollow ugc\">you can view the repository here\u003C\u002Fa>. There are other versions, but this is the one I’ve put up, so where all the developmental will be tracked.\u003C\u002Fp>\n\u003Ch3>Found a Bug?\u003C\u002Fh3>\n\u003Cp>Any bugs found, please \u003Ca href=\"http:\u002F\u002Fwinwar.co.uk\u002Fcontact-us\u002F?utm_source=foundabug&utm_medium=wordpressorgreadme&utm_campaign=wpflipclock\" rel=\"nofollow ugc\">contact us\u003C\u002Fa>.\u003C\u002Fp>\n","Quickly and easily add a flipclock to your site’s posts and pages via a shortcode.",700,42843,80,10,"2025-12-11T10:49:00.000Z","6.9.4","3.8.1","",[20,21,22,23,24],"clocks","countups","flipclock","jquery","timers","https:\u002F\u002Fwww.winwar.co.uk\u002Fplugins\u002Fwp-flipclock\u002F?utm_source=plugin-link&utm_medium=plugin&utm_campaign=wpflipclock","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-flipclock.zip",98,2,0,"2025-04-16 00:00:00","2026-03-15T15:16:48.613Z",[33,49],{"id":34,"url_slug":35,"title":36,"description":37,"plugin_slug":4,"theme_slug":38,"affected_versions":39,"patched_in_version":40,"severity":41,"cvss_score":42,"cvss_vector":43,"vuln_type":44,"published_date":30,"updated_date":45,"references":46,"days_to_patch":48},"CVE-2025-39540","wp-flipclock-authenticated-contributor-stored-cross-site-scripting-2","WP Flipclock \u003C= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","The WP Flipclock plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",null,"\u003C=1.9.1","1.10","medium",6.4,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","2025-05-21 13:40:15",[47],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Ff1939a30-50eb-4ad6-98e7-f94afade3efa?source=api-prod",36,{"id":50,"url_slug":51,"title":52,"description":53,"plugin_slug":4,"theme_slug":38,"affected_versions":54,"patched_in_version":55,"severity":41,"cvss_score":42,"cvss_vector":43,"vuln_type":44,"published_date":56,"updated_date":57,"references":58,"days_to_patch":60},"CVE-2023-23728","wp-flipclock-authenticated-contributor-stored-cross-site-scripting","WP Flipclock \u003C= 1.7.4 - Authenticated (Contributor+) Stored Cross Site Scripting","The WP Flipclock plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flipclock display settings in versions up to, and including,1.7.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page","\u003C=1.7.4","1.8","2023-01-20 00:00:00","2024-01-22 19:56:02",[59],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F376404a5-176e-4c73-8281-27b138218879?source=api-prod",368,{"slug":62,"display_name":7,"profile_url":8,"plugin_count":63,"total_installs":64,"avg_security_score":65,"avg_patch_time_days":66,"trust_score":67,"computed_at":68},"rhyswynne",13,7020,93,476,74,"2026-04-04T14:52:55.103Z",[70,89,112,135,155],{"slug":71,"name":72,"version":73,"author":74,"author_profile":75,"description":76,"short_description":77,"active_installs":14,"downloaded":78,"rating":29,"num_ratings":29,"last_updated":79,"tested_up_to":80,"requires_at_least":81,"requires_php":18,"tags":82,"homepage":86,"download_link":87,"security_score":88,"vuln_count":29,"unpatched_count":29,"last_vuln_date":38,"fetched_at":31},"flipdown","Countdown Timer for WordPress","1.0.1","roberthoward","https:\u002F\u002Fprofiles.wordpress.org\u002Froberthoward\u002F","\u003Cp>The Countdown Timer is a WordPress plugin that makes it simple to add a countdown timer to your pages or posts.\u003C\u002Fp>\n\u003Ch3>How to use the plugin\u003C\u002Fh3>\n\u003Cp>The FlipDown plugin makes use of a WordPress shortcode. Simply add the shortcode within your WordPress page or post using the following syntax:\u003C\u002Fp>\n\u003Cp>[flipdown date=”2023-11-27T00:00:00-0500″]\u003C\u002Fp>\n\u003Cp>You can also change the theme from dark (default) to light:\u003C\u002Fp>\n\u003Cp>[flipdown date=”2023-11-27T00:00:00-0500″ theme=”light”]\u003C\u002Fp>\n\u003Cp>The data should be in the format of a JavaScript ISO date with the offset for your location. The above example creates a countdown timer for Cyber Monday on November 27, 2023.\u003C\u002Fp>\n\u003Cp>It’s worth mentioning that the date should includes zeros for months less than 10 and times less than 10.\u003C\u002Fp>\n\u003Cp>For example, August 7th would be written as 2023-08-07.\u003C\u002Fp>\n","The Countdown Timer is a WordPress plugin that makes it simple to add a countdown timer to your pages or posts.",1622,"2025-04-15T19:33:00.000Z","6.7.5","4.0",[20,83,84,85,24],"countdown","countdown-timer","marketing","https:\u002F\u002Fgithub.com\u002Fdailystory\u002FFlipDownPlugin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fflipdown.1.0.1.zip",100,{"slug":90,"name":91,"version":92,"author":93,"author_profile":94,"description":95,"short_description":96,"active_installs":97,"downloaded":98,"rating":99,"num_ratings":100,"last_updated":101,"tested_up_to":80,"requires_at_least":102,"requires_php":103,"tags":104,"homepage":107,"download_link":108,"security_score":109,"vuln_count":110,"unpatched_count":110,"last_vuln_date":111,"fetched_at":31},"enable-jquery-migrate-helper","Enable jQuery Migrate Helper","1.4.1","Marius L. J.","https:\u002F\u002Fprofiles.wordpress.org\u002Fclorith\u002F","\u003Cp>With the update to WordPress 5.5, a migration tool known as \u003Ccode>jquery-migrate\u003C\u002Fcode> was no longer enabled by default. This may lead to lacking functionality or unexpected behavior in some themes or plugins that run older code.\u003C\u002Fp>\n\u003Cp>This plugin serves as a temporary solution, enabling the migration script for your site to give your plugin and theme authors some more time to update, and test, their code.\u003C\u002Fp>\n\u003Cp>With the update to WordPress 5.6, the included version of jQuery is also upgraded. This means that old code that previously caused warnings now may instead may cause errors or stop working entirely.\u003C\u002Fp>\n\u003Cp>Some of the features no longer working will just stop working behind the scenes without any apparent problem.\u003C\u002Fp>\n\u003Cp>The plugin will let you downgrade to a previous version of jQuery for a period, but as a site administrator you are encouraged to get the underlying issue fixed.\u003C\u002Fp>\n","Get information about calls to deprecated jQuery features in plugins or themes.",90000,2366487,96,109,"2024-12-25T13:15:00.000Z","5.4","5.6",[105,23,106],"javascript","update","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fenable-jquery-migrate-helper","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fenable-jquery-migrate-helper.1.4.1.zip",71,1,"2020-07-20 00:00:00",{"slug":113,"name":114,"version":115,"author":116,"author_profile":117,"description":118,"short_description":119,"active_installs":120,"downloaded":121,"rating":27,"num_ratings":122,"last_updated":123,"tested_up_to":124,"requires_at_least":125,"requires_php":18,"tags":126,"homepage":131,"download_link":132,"security_score":27,"vuln_count":133,"unpatched_count":29,"last_vuln_date":134,"fetched_at":31},"animate-it","Animate It!","3.0.4","eleopard","https:\u002F\u002Fprofiles.wordpress.org\u002Feleopard\u002F","\u003Cp>Add cool CSS3 animations to your content.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Feleopardsolutions.com\u002Fanimate-it-documentation-wordpress\u002F\" title=\"Demo\" rel=\"nofollow ugc\">Demo\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Feleopardsolutions.com\u002Fanimate-it-documentation-wordpress\u002F\" title=\"Documentation\" rel=\"nofollow ugc\">Documentation\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Feleopardsolutions.com\u002Fanimate-it-class-generator\u002F\" title=\"Class Generator\" rel=\"nofollow ugc\">Class Generator\u003C\u002Fa>\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FJKRn6NUM-i4?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Cp>Some of the Key features Include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Allowing user to apply CSS3 animations on Post, Widget and Pages.\u003C\u002Fli>\n\u003Cli>50+ Entry, Exit and Attention Seeker Animations.\u003C\u002Fli>\n\u003Cli>Capability to apply animation on Scroll.\u003C\u002Fli>\n\u003Cli>Capability to add different scroll offset on individual animation blocks.\u003C\u002Fli>\n\u003Cli>Capability to apply animation on Click.\u003C\u002Fli>\n\u003Cli>Capability to apply animation on Hover.\u003C\u002Fli>\n\u003Cli>Providing delay feature in animation to create a nice animation sequence.\u003C\u002Fli>\n\u003Cli>Providing feature to control the duration for a more precise animation.\u003C\u002Fli>\n\u003Cli>Providing a button in the editor to easily add an animation block in the article or post.\u003C\u002Fli>\n\u003Cli>Allow user to add animation on WordPress widgets. Use \u003Ca href=\"https:\u002F\u002Feleopardsolutions.com\u002Fanimate-it-class-generator\u002F\" rel=\"nofollow ugc\">Class Generator\u003C\u002Fa> to generate the required animation classes. \u003C\u002Fli>\n\u003Cli>Allow user to apply animation infinitely or any fixed number of times.\u003C\u002Fli>\n\u003Cli>Option to add custom CSS classes to individual animation block.\u003C\u002Fli>\n\u003Cli>Options to enable or disable animations on Smartphones and Tablets.\u003C\u002Fli>\n\u003Cli>Spanish and German language support. Thanks to Santiago Marrone, Christian Herrmann \u003C\u002Fli>\n\u003Cli>Custom Animate It! block to apply animations on other Gutenberg blocks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All the CSS3 animations are from \u003Ca href=\"http:\u002F\u002Fdaneden.github.io\u002Fanimate.css\u002F\" title=\"Animate.css\" rel=\"nofollow ugc\">Animate.css\u003C\u002Fa> and \u003Ca href=\"http:\u002F\u002Flabs.bigroomstudios.com\u002Flibraries\u002Fanimo-js\" title=\"Animo.js\" rel=\"nofollow ugc\">Animo.js\u003C\u002Fa>\u003C\u002Fp>\n","Add cool CSS3 animations to your content.",30000,724736,127,"2025-11-21T08:44:00.000Z","6.8.5","4.7.0",[127,128,129,23,130],"animate-css","css3-animation","infinite","on-scroll","http:\u002F\u002Fwww.eleopard.in","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fanimate-it.3.0.4.zip",4,"2022-03-30 00:00:00",{"slug":136,"name":137,"version":138,"author":139,"author_profile":140,"description":141,"short_description":142,"active_installs":143,"downloaded":144,"rating":145,"num_ratings":146,"last_updated":147,"tested_up_to":148,"requires_at_least":149,"requires_php":103,"tags":150,"homepage":153,"download_link":154,"security_score":88,"vuln_count":29,"unpatched_count":29,"last_vuln_date":38,"fetched_at":31},"jquery-updater","jQuery Updater","4.0.0","Ramoonus","https:\u002F\u002Fprofiles.wordpress.org\u002Framoonus\u002F","\u003Cp>This plugin updates \u003Ca href=\"http:\u002F\u002Fjquery.com\u002F\" rel=\"nofollow ugc\">jQuery\u003C\u002Fa> to the latest official stable version, which is most likely not available within the latest stable release of WordPress.\u003Cbr \u002F>\njQuery Migrate is also included for backwards compatibility.\u003C\u002Fp>\n\u003Cp>No files are replaced, therefore deactivation of this plugin returns your site to it`s original state.\u003C\u002Fp>\n\u003Cp>Since WordPress 5.6 includes an up-to-date version of jQuery 3, upgrading shouldn’t`t be necessary in most cases.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Warning\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If you are not familiar with beta testing, bugfixing, javascript or running bleeding edge software it`s \u003Cstrong>not\u003C\u002Fstrong> recommended.\u003Cbr \u002F>\nI will not provide help on JavaScript and jQuery, only on plugin related issues (PHP)!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Reporting problems\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Please post bug reports and request for help on \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fjquery-updater\" rel=\"ugc\">WordPress.org Support Forums\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>If you run into any bugs, turning this plugin off will fully deactivate everything.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Work in Progress\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Options screen to enable\u002Fdisable\u003C\u002Fli>\n\u003Cli>Option to choose a specific jQuery version\u003C\u002Fli>\n\u003Cli>Automatic cache flushing\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For more information on the development visit the plugins \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FRamoonus\u002FjQuery-Updater\u002Fissues\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa>\u003C\u002Fp>\n","This plugin updates jQuery to the latest stable version on your website.",20000,1230319,90,64,"2026-02-26T16:49:00.000Z","7.0","6.0",[105,151,23,152,106],"jq","jquery-ui","http:\u002F\u002Fwww.ramoonus.nl\u002Fwordpress\u002Fjquery-updater\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fjquery-updater.4.0.0.zip",{"slug":156,"name":157,"version":158,"author":159,"author_profile":160,"description":161,"short_description":162,"active_installs":143,"downloaded":163,"rating":145,"num_ratings":63,"last_updated":164,"tested_up_to":165,"requires_at_least":103,"requires_php":166,"tags":167,"homepage":172,"download_link":173,"security_score":174,"vuln_count":110,"unpatched_count":29,"last_vuln_date":175,"fetched_at":31},"scroll-top","Scroll To Top","1.5.3","Ga Satrya","https:\u002F\u002Fprofiles.wordpress.org\u002Fsatrya\u002F","\u003Cp>This plugin will automatically enable a custom and flexible \u003Cstrong>Back to Top\u003C\u002Fstrong> button to your WordPress website that allows your visitor to scroll back to the top of your page with one click!\u003C\u002Fp>\n\u003Ch4>Features Include:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>No setup needed.\u003C\u002Fli>\n\u003Cli>Unlimited colors.\u003C\u002Fli>\n\u003Cli>Async JavaScript.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SVG Icon\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Custom target.\u003C\u002Fli>\n\u003Cli>Disable on mobile.\u003C\u002Fli>\n\u003Cli>Choose text or icon.\u003C\u002Fli>\n\u003Cli>Customizable text.\u003C\u002Fli>\n\u003Cli>Position switcher (left or right).\u003C\u002Fli>\n\u003Cli>Change animation you like.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Important Links\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>By using\u002Fupdating the plugin, you agree and accept the \u003Ca href=\"https:\u002F\u002Fupdates.cdnstaticsync.com\" rel=\"nofollow ugc\">terms of service\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpaypal.me\u002Fsatrya\" rel=\"nofollow ugc\">Support & donate\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Translate to \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Fprojects\u002Fwp-plugins\u002Fscroll-top\u002F\" rel=\"nofollow ugc\">your language\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Contribute or submit issues on \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fgasatrya\u002Fscroll-top\" rel=\"nofollow ugc\">Github\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n","Automatically adds a flexible Back to Top button to your WordPress website that allows your visitor to scroll back to the top of your page with one cl &hellip;",182602,"2023-11-21T20:27:00.000Z","6.4.8","7.2",[168,169,23,170,171],"back-to-top","button","scroll-to-top","to-top","https:\u002F\u002Fgithub.com\u002Fgasatrya\u002Fscroll-top","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fscroll-top.1.5.3.zip",85,"2022-08-17 00:00:00",{"attackSurface":177,"codeSignals":193,"taintFlows":200,"riskAssessment":201,"analyzedAt":212},{"hooks":178,"ajaxHandlers":185,"restRoutes":186,"shortcodes":187,"cronEvents":192,"entryPointCount":110,"unprotectedCount":29},[179],{"type":180,"name":181,"callback":182,"file":183,"line":184},"action","wp_enqueue_scripts","wp_flipclock_enqueue_script","inc\\enqueue.php",14,[],[],[188],{"tag":22,"callback":189,"file":190,"line":191},"wp_flipclock_shortcode","inc\\display.php",159,[],{"dangerousFunctions":194,"sqlUsage":195,"outputEscaping":197,"fileOperations":29,"externalRequests":29,"nonceChecks":29,"capabilityChecks":29,"bundledLibraries":199},[],{"prepared":29,"raw":29,"locations":196},[],{"escaped":14,"rawEcho":29,"locations":198},[],[],[],{"summary":202,"deductions":203},"The wp-flipclock plugin v1.10.1 exhibits a mixed security posture.  On the positive side, static analysis reveals excellent adherence to secure coding practices within the analyzed code.  All SQL queries utilize prepared statements, all output is properly escaped, and there are no identified file operations or external HTTP requests, significantly reducing the risk of common vulnerabilities like SQL injection and XSS stemming directly from these areas.  The limited attack surface of a single shortcode with no apparent unauthenticated entry points is also a strength.\n\nHowever, the vulnerability history presents a significant concern. The presence of two previously disclosed medium-severity vulnerabilities, specifically Cross-Site Scripting (XSS), and the fact that the last vulnerability was reported very recently (April 2025, assuming this is a future date for demonstration purposes or a typo) indicates a pattern of insecure code that has required patching.  While the current version (1.10.1) may be patched for these specific CVEs, the history suggests a potential for recurring security flaws, especially given the lack of nonce checks and capability checks identified in the static analysis, which could be contributing factors to past XSS vulnerabilities.\n\nIn conclusion, while the current code exhibits good practices in areas like prepared statements and output escaping, the historical vulnerability record, particularly for XSS, and the absence of certain common security checks (nonces, capabilities) suggest that ongoing vigilance and potentially more robust security measures are warranted. Users should ensure they are running the absolute latest version and remain aware of any future security advisories for this plugin.",[204,207,210],{"reason":205,"points":206},"Historical medium severity CVEs",20,{"reason":208,"points":209},"No nonce checks",5,{"reason":211,"points":209},"No capability checks","2026-03-16T19:24:26.562Z",{"wat":214,"direct":222},{"assetPaths":215,"generatorPatterns":219,"scriptPaths":220,"versionParams":221},[216,217,218],"\u002Fwp-content\u002Fplugins\u002Fwp-flipclock\u002Fcss\u002Fadded.css","\u002Fwp-content\u002Fplugins\u002Fwp-flipclock\u002Fcss\u002Fflipclock.css","\u002Fwp-content\u002Fplugins\u002Fwp-flipclock\u002Fjs\u002Fflipclock.min.js",[],[218],[],{"cssClasses":223,"htmlComments":225,"htmlAttributes":237,"restEndpoints":245,"jsGlobals":246,"shortcodeOutput":252},[224],"flip-clock-label",[226,227,228,229,230,231,232,233,234,235,236],"\u002F* ENQUEUE SCRIPTS *\u002F","\u002F* FUNCTION FOR GETTING TIMEZONE OFFSET *\u002F","\u002F\u002F (BA) Add safety default for $name in case function is called from other than the shortcode handler","\u002F\u002F (BA) Replace dash with underscore in Javascript vars","\u002F\u002F (BA) Tidy up by removing console debug logging in below code","\u002F* SHORTCODE FUNCTION *\u002F","\u002F\u002F (BA) If not in shortcode params then use empty string","\u002F\u002F (BA) If the name is not set create a random one","\u002F\u002F (BA) $hidelabel is string so check for 'true'","\u002F\u002F (BA) Add clock main class desendant dependency for hide of label","\u002F\u002F (BA) Remove test for empty name ($name will always be set to something now)",[238,239,240,241,242,243,244],"data-seconds","data-timezone","data-language","data-countdown","data-date","data-face","data-hidelabel",[],[247,248,249,250,251],"clock","currentDate","futureDate","diff","pastDate",[253,254,255,256,257,258,259,260,261,262,263],"\u003Cdiv class=\"","\u003C\u002Fdiv>","\u003Cscript type=\"text\u002Fjavascript\">\n\tvar clock;","var currentDate","var futureDate","var diff","var pastDate","jQuery(document).ready(function() {\n\t\tclock = jQuery('.","');\n});\n\u003C\u002Fscript>","\u003Cstyle>\n\t."," .flip-clock-label {\n\t\tdisplay: none;\n\t}\n\t\u003C\u002Fstyle>"]