[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1aQIBz2UuZKCcz-5DnqCcBX2Qjsb1GBZbblneDn_28o":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29,"vulnerabilities":30,"developer":31,"crawl_stats":28,"alternatives":37,"analysis":77,"fingerprints":140},"wp-tic-tac-toe","Wp Tic-Tac-Toe","1.8","Geeky Nigeria","https:\u002F\u002Fprofiles.wordpress.org\u002Fjohnvictor82\u002F","\u003Cp>Wp Tic-Tac-Toe allows visitors to play the game on your website, thereby driving engagement. There are four defined levels; Beginner, Learner, Pro, and Geek. Players can choose to learn with the Beginner & Learner Levels or Play to Beat the AI in Pro and Geek.\u003C\u002Fp>\n\u003Cp>The Game can be added to any page or post via an easily accessible shortcode, [wp-tic-tac-toe] or conveniently set up on a sidebar in Appearance >> Widgets. Add the plugin, and you are ready to play!\u003C\u002Fp>\n\u003Cp>Major features in Wp Tic-Tac-Toe include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Increasing Levels of Difficulty.\u003C\u002Fli>\n\u003Cli>Shortcode for Page\u002FPost Inclusion.  \u003C\u002Fli>\n\u003Cli>Low memory usage.\u003C\u002Fli>\n\u003Cli>Well designed Game Layout\u003C\u002Fli>\n\u003C\u002Ful>\n","Drive engagement to your website with the Tic-Tac-Toe Game.",70,4171,100,4,"2025-06-30T15:47:00.000Z","6.8.5","","8.0",[20,21,22,23,24],"geeky-nigeria","play-tic-tac-toe-on-wordpress","simple-tic-tac-toe-game","tic-tac-toe-game-for-wordpress","wordpress-tic-tac-toe-plugin","https:\u002F\u002Fgeeky.com.ng\u002Fwp-tic-tac-toe-plugin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-tic-tac-toe.1.8.zip",0,null,"2026-03-15T15:16:48.613Z",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":14,"total_installs":13,"avg_security_score":33,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"johnvictor82",89,30,86,"2026-04-05T17:42:00.403Z",[38,59],{"slug":39,"name":40,"version":41,"author":7,"author_profile":8,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":13,"num_ratings":46,"last_updated":47,"tested_up_to":48,"requires_at_least":49,"requires_php":50,"tags":51,"homepage":55,"download_link":56,"security_score":57,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":58},"newsletter-chat","Newsletter Chat","1.2","\u003Cp>Newsletter Chat is a lite plugin that allows you to share today’s posts to your WhatsApp subscribers. Simply enter your preferred Newsletter title and Newsletter footer. The posts are automatically set up for sharing on the Newsletter Page.\u003C\u002Fp>\n\u003Cp>Visit the Newsletter page everyday, after posting, to share your published posts on WhatsApp.\u003C\u002Fp>\n\u003Cp>The newsletter page can also be shared, so that others can assist to distribute.\u003C\u002Fp>\n\u003Cp>If posts haven’t been set up, kindly update your Timezone in Settings -> General -> Timezone\u003C\u002Fp>\n\u003Cp>Major features in Newsletter for WhatsApp include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Share Posts Published Today\u003C\u002Fli>\n\u003Cli>Set Newsletter Title and Footer\u003C\u002Fli>\n\u003Cli>Link To Read Posts Below Newsletter  \u003C\u002Fli>\n\u003Cli>Shareable Newsletter page for fans\u003C\u002Fli>\n\u003Cli>Support Inclusion\u003C\u002Fli>\n\u003C\u002Ful>\n","Newsletter Chat is a lite plugin that allows you to share today's posts to your WhatsApp subscribers. Simply enter your preferred Newsletter titl &hellip;",10,1128,2,"2020-07-18T04:26:00.000Z","5.4.19","5.2","7.2",[20,39,52,53,54],"posts-newsletter-for-whatsapp","share-latest-posts-to-whatsapp","whatsapp-newsletter-plugin","https:\u002F\u002Fgeeky.com.ng\u002Fnewsletter-chat-plugin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fnewsletter-chat.1.2.zip",85,"2026-03-15T14:54:45.397Z",{"slug":60,"name":61,"version":62,"author":7,"author_profile":8,"description":63,"short_description":64,"active_installs":44,"downloaded":65,"rating":13,"num_ratings":66,"last_updated":67,"tested_up_to":68,"requires_at_least":69,"requires_php":17,"tags":70,"homepage":75,"download_link":76,"security_score":57,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"share-christmas-tunes-decorations","Share Christmas – Tunes and Decorations","1.0.2","\u003Cp>Share Christmas – Tunes and Decorations is an all-in-one inclusive plugin that uniquely features decorations, music and a lovely Christmas font to your WordPress visitors. It is neatly designed, with a user-friendly interface. Simple visit the settings to choose your desired effect.\u003C\u002Fp>\n\u003Cp>A major feature of Share Christmas plugin is that it is extremely lightweight, despite its options, which makes it suitable, even for low-budget websites with limited resources. The tunes have low file size and is perfectly integrated to work with modern browsers.\u003C\u002Fp>\n\u003Cp>With an autoplay feature, the tune plays automatically when the visitor goes through your site content. Visitors even have the option to pause the song, to foucs on the site’s content.\u003C\u002Fp>\n\u003Cp>Install and share the love of Christmas with your visitors. Your can also drop us a review.\u003C\u002Fp>\n","Share Christmas for Wordpress gives visitors the memorable christmas experience of classic tunes and decorations for an immersive and pleasant yuletid &hellip;",2274,1,"2023-11-18T13:36:00.000Z","6.4.8","4.3",[71,72,73,20,74],"carol","christmas","christmas-font","music","https:\u002F\u002Fgeeky.com.ng","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fshare-christmas-tunes-decorations.1.0.2.zip",{"attackSurface":78,"codeSignals":109,"taintFlows":128,"riskAssessment":129,"analyzedAt":139},{"hooks":79,"ajaxHandlers":102,"restRoutes":103,"shortcodes":104,"cronEvents":108,"entryPointCount":66,"unprotectedCount":27},[80,86,90,92,94,98],{"type":81,"name":82,"callback":83,"file":84,"line":85},"action","admin_head","WPTTT_enq_admin_styles","wptictactoe.php",16,{"type":81,"name":87,"callback":88,"file":84,"line":89},"wp_enqueue_scripts","WPTTT_enq_custom_script",17,{"type":81,"name":82,"callback":83,"file":84,"line":91},26,{"type":81,"name":82,"callback":88,"file":84,"line":93},27,{"type":81,"name":95,"callback":96,"file":84,"line":97},"admin_menu","WPTTT_GAME_Dashboard",39,{"type":81,"name":99,"callback":100,"file":84,"line":101},"widgets_init","my_init_function",155,[],[],[105],{"tag":4,"callback":106,"file":84,"line":107},"WPTTT_game_page",40,[],{"dangerousFunctions":110,"sqlUsage":111,"outputEscaping":113,"fileOperations":27,"externalRequests":27,"nonceChecks":27,"capabilityChecks":27,"bundledLibraries":127},[],{"prepared":27,"raw":27,"locations":112},[],{"escaped":66,"rawEcho":114,"locations":115},7,[116,118,119,121,123,125,126],{"file":84,"line":35,"context":117},"raw output",{"file":84,"line":33,"context":117},{"file":84,"line":120,"context":117},129,{"file":84,"line":122,"context":117},149,{"file":84,"line":124,"context":117},150,{"file":84,"line":124,"context":117},{"file":84,"line":124,"context":117},[],[],{"summary":130,"deductions":131},"The wp-tic-tac-toe plugin v1.8 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no raw SQL queries, and no file operations or external HTTP requests. The absence of known vulnerabilities in its history is also a strong indicator of diligent security practices. However, significant concerns arise from the lack of proper output escaping, with only 13% of observed outputs being safely handled. This presents a notable risk for cross-site scripting (XSS) vulnerabilities, as user-controlled data, if present, could be injected into the output without proper sanitization.\n\nFurthermore, the complete absence of nonce checks and capability checks across all identified entry points, including the single shortcode, is a critical security oversight. While the attack surface is currently small and appears to be unprotected in terms of authentication, the lack of these fundamental security measures means that even a single entry point could be exploited if it handles user-supplied data. The taint analysis showing zero flows analyzed is unusual and potentially indicates insufficient analysis depth rather than a complete absence of taint. The plugin's strengths lie in its clean SQL usage and lack of known historical vulnerabilities, but the significant gaps in output escaping and authentication checks are serious weaknesses that require immediate attention.",[132,135,137],{"reason":133,"points":134},"Low output escaping percentage",8,{"reason":136,"points":44},"Missing nonce checks",{"reason":138,"points":44},"Missing capability checks","2026-03-16T21:31:59.212Z",{"wat":141,"direct":150},{"assetPaths":142,"generatorPatterns":147,"scriptPaths":148,"versionParams":149},[143,144,145,146],"\u002Fwp-content\u002Fplugins\u002Fwp-tic-tac-toe\u002Fcss\u002Fstyle.css","\u002Fwp-content\u002Fplugins\u002Fwp-tic-tac-toe\u002Fjs\u002Fwpttt.js","\u002Fwp-content\u002Fplugins\u002Fwp-tic-tac-toe\u002Fimages\u002Fblank.gif","\u002Fwp-content\u002Fplugins\u002Fwp-tic-tac-toe\u002Fimages\u002Fscoresgame.jpg",[],[144],[],{"cssClasses":151,"htmlComments":158,"htmlAttributes":159,"restEndpoints":169,"jsGlobals":170,"shortcodeOutput":174},[152,153,154,155,156,157],"WPTTT_game-center-align","WPTTT_settings-intro","WPTTT-h2","WPTTT-codebxne","WPTTT_popup","WPTTT_result",[],[160,161,162,163,164,165,166,167,168],"name=\"rc11\"","name=\"rc12\"","name=\"rc13\"","name=\"rc21\"","name=\"rc22\"","name=\"rc23\"","name=\"rc31\"","name=\"rc32\"","name=\"rc33\"",[],[171,172,173],"setlevel","setbutton","WPTTT_closex",[175],"\u003Cdiv class=\"WPTTT_game-center-align\">\u003Ch1> WP Tic-Tac-Toe\u003C\u002Fh1>\u003Ch2>By Geeky Nigeria\u003C\u002Fh2>\u003Cbr>"]