[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUSJBtABV8e9MnIxftgLI31RexdO29PSBjmMfEYku28E":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"vulnerabilities":29,"developer":30,"crawl_stats":27,"alternatives":35,"analysis":141,"fingerprints":208},"wpmyavatar","WPMyAvatar","1.1","frametagmedia","https:\u002F\u002Fprofiles.wordpress.org\u002Fframetagmedia\u002F","\u003Cp>Add a custom avatar (profile picture) from the WordPress Media Library as user profile picture instead of gravatar. Perfect for customization and personalization of your website for you and your users.\u003C\u002Fp>\n\u003Cp>Shortcode to show a user avatar anywhere on your site – [my_avatar userId=\\’1\\’ size=\\’150\\’ alt=\\’User Avatar\\’]\u003C\u002Fp>\n\u003Cul>\n\u003Cli>please note users must be an author or higher to upload a custom avatar\u002Fprofile picture\u003C\u002Fli>\n\u003C\u002Ful>\n","Add a custom avatar (profile picture) from the Wordpress Media Library as user profile picture instead of gravatar.",20,1808,0,"2018-08-20T02:59:00.000Z","4.9.29","3.5.0","",[19,20,21,22,23],"avatar","custom-avatar","custom-profile-pic","customization","media-library","https:\u002F\u002Fframetagmedia.com.au\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpmyavatar.zip",85,null,"2026-03-15T15:16:48.613Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},2,30,84,"2026-04-05T20:24:24.262Z",[36,59,81,101,121],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":46,"num_ratings":47,"last_updated":48,"tested_up_to":49,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":56,"download_link":57,"security_score":58,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"simple-user-avatar","Simple User Avatar","4.8","Matteo Manna","https:\u002F\u002Fprofiles.wordpress.org\u002Fmatteomanna\u002F","\u003Cp>This plugin simplifies the life of WordPress users.\u003Cbr \u002F>\nNow users can add or remove their avatar simply using images from his Media Library. Simple to use, no additional functions required. Plugin available on \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FMatteoManna\u002FSimple-User-Avatar\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa>.\u003C\u002Fp>\n","Simple User Avatar helps users to add or remove their avatar using images from his Media Library.",20000,217845,88,19,"2026-02-06T10:09:00.000Z","6.9.4","4.0","7.3",[19,53,23,54,55],"gravatar","picture","user","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsimple-user-avatar\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsimple-user-avatar.4.8.zip",100,{"slug":60,"name":61,"version":62,"author":63,"author_profile":64,"description":65,"short_description":66,"active_installs":67,"downloaded":68,"rating":69,"num_ratings":70,"last_updated":71,"tested_up_to":72,"requires_at_least":73,"requires_php":17,"tags":74,"homepage":79,"download_link":80,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"wp-first-letter-avatar","WP First Letter Avatar","2.2.8","DanielAGW","https:\u002F\u002Fprofiles.wordpress.org\u002Fdanielagw\u002F","\u003Cp>WP First Letter Avatar \u003Cstrong>sets custom avatars for users without Gravatar\u003C\u002Fstrong>. The avatar will be a first letter of the user’s name. You can also configure the plugin to use any other letter to set custom avatar.\u003C\u002Fp>\n\u003Cp>WP First Letter Avatar includes a set of \u003Cstrong>beautiful, colorful letter avatars\u003C\u002Fstrong> in many sizes. Optimal size will be chosen by the plugin in order to display high quality avatar and not download, for example, big 512px avatars when only 48px is needed… \u003Cstrong>PSD template\u003C\u002Fstrong> for avatar is also included.\u003C\u002Fp>\n\u003Cp>You can also create your own avatar set by creating new directory next to \u003Cem>‘default’\u003C\u002Fem> folder and following the naming convention from \u003Cem>‘default’\u003C\u002Fem>.\u003C\u002Fp>\n\u003Cp>By default, custom avatar will be set only to users without Gravatars, but you can change that in settings and not use Gravatar at all.\u003C\u002Fp>\n\u003Cp>WP First Letter Avatar helps you \u003Cstrong>bring more colors\u003C\u002Fstrong> into your blog. Plus, your readers will be more \u003Cstrong>willing to comment on your posts\u003C\u002Fstrong>, since they can actually relate to these avatars much better than to Mystery Person.\u003C\u002Fp>\n\u003Cp>All images were compressed using the fantastic \u003Ca href=\"https:\u002F\u002Ftinypng.com\u002F\" rel=\"nofollow ugc\">TinyPNG\u003C\u002Fa>, so avatars are \u003Cstrong>incredibly light and ultra-high quality\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>WP First Letter Avatar is also available \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FDev49net\u002Fwp-first-letter-avatar\" rel=\"nofollow ugc\">on GitHub\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Compatibility with other plugins\u003C\u002Fh4>\n\u003Cp>WP First Letter Avatar is fully compatible with \u003Ca href=\"https:\u002F\u002Fbbpress.org\u002F\" rel=\"nofollow ugc\">bbPress\u003C\u002Fa> and \u003Ca href=\"http:\u002F\u002Fwww.gvectors.com\u002Fwpdiscuz\u002F\" rel=\"nofollow ugc\">wpDiscuz\u003C\u002Fa>. For \u003Ca href=\"https:\u002F\u002Fbuddypress.org\u002F\" rel=\"nofollow ugc\">BuddyPress\u003C\u002Fa> compatibility please use my other plugin – \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbuddypress-first-letter-avatar\u002F\" rel=\"ugc\">BuddyPress First Letter Avatar\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Requirements\u003C\u002Fh4>\n\u003Cp>WP First Letter Avatar requires at least PHP 5.4. It \u003Cstrong>does not work properly\u003C\u002Fstrong> on PHP 5.3.x and earlier.\u003C\u002Fp>\n","Set custom avatars for users with no Gravatar. The avatar will be the first (or any other) letter of user's name on a colorful background.",2000,67403,94,33,"2017-03-11T22:26:00.000Z","4.7.32","4.6",[75,76,77,20,78],"avatars","change-avatar","comments","discussion","http:\u002F\u002Fdev49.net","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-first-letter-avatar.zip",{"slug":82,"name":83,"version":84,"author":85,"author_profile":86,"description":87,"short_description":88,"active_installs":89,"downloaded":90,"rating":13,"num_ratings":13,"last_updated":91,"tested_up_to":92,"requires_at_least":93,"requires_php":94,"tags":95,"homepage":17,"download_link":100,"security_score":58,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"customize-my-account-page","Customize My Account Page For WooCommerce","1.0.0","ThemeGrill","https:\u002F\u002Fprofiles.wordpress.org\u002Fthemegrill\u002F","\u003Cp>\u003Cstrong>Customize the WooCommerce My Account page. Add tabs, reorder menus, and personalize content for your customers\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Edit the default My Account Page by adding unlimited tabs, reordering menus items with drag and drop method, customizing default WooCommerce endpoints, and personalizing customer dashboard content.\u003C\u002Fp>\n\u003Ch3>Key Features of Customize My Account Page\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Modify Default WooCommerce Endpoints:\u003C\u002Fstrong> Easily modify or disable default WooCommerce endpoints: Dashboard, Orders, Downloads, Addresses, Payment Methods, Account Details, and Logout.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Create Custom Endpoint:\u003C\u002Fstrong> Add a custom endpoint for your own using Customize My Account Page. You can specify its own label, slug, icon and personalize the page content.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Create Unlimited Links:\u003C\u002Fstrong> Add unlimited menu items linking to another page within your WooCommerce store or external website. You can have the link open in the same tab or new tab in your browser.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Hide\u002FShow WooCommerce Tabs:\u003C\u002Fstrong> Control which default WooCommerce endpoints are visible on your customer’s My Account Page. Toggle between hide and show in a single click.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Visual Styling Options for Endpoints:\u003C\u002Fstrong> Change label and icon of individual endpoints to your liking. Choose from the available icon or upload your own.You can use style the endpoint further using custom classes.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Display Custom Profile\u002FAvatar for WooCommerce Users:\u003C\u002Fstrong> Allow customers to upload custom profile images for their account page. It supports png and jpg file types and default placeholders.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>User Role-Specific Endpoints:\u003C\u002Fstrong> By default, endpoints are visible to all users. However, you can create limit endpoints to specific user roles only.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Customize Each Endpoint with custom label and icon:\u003C\u002Fstrong> Change the label and icon of each endpoint to your liking. You can choose from the available icons or upload your own.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Change Layout of Account Page with Drag and Drop Menu Method:\u003C\u002Fstrong> Re-order endpoints and links within the My Account Page easily through drag and drop interface. You can re-arrange both default and custom tabs using this method.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Custom Account Page Content:\u003C\u002Fstrong> Customize content on the WooCommerce My Account page using our WYSIWYG editor. Add rich content with formatted texts, medias, custom HTML codes. You can also integrate content from your theme and plugins through shortcodes.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Personalize Content for Your Customers:\u003C\u002Fstrong> Personalize content for your customers through use of available smart tags: User ID, User Name, User Email, First Name, Last Name, User Display Name, User IP Address, Site Name, Site URL, Page URL, Current Date, Current Time, Billing Address, Billing Company, Shipping Address, and Shipping Company.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>How to Use Customize My Account Page for WooCommerce?\u003C\u002Fh3>\n\u003Ch3>After Installation\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Go to WooCommerce > Customize My Account Page\u003C\u002Fli>\n\u003Cli>Start customizing your My Account page using the drag-and-drop interface\u003C\u002Fli>\n\u003Cli>Save your changes and preview the results\u003C\u002Fli>\n\u003C\u002Ful>\n","Customize the default WooCommerce My Account Page. Add unlimited menu tabs, manage endpoints & display personalized content in the customer dashboard.",1000,877,"2025-12-09T07:32:00.000Z","6.8.5","5.5","7.4",[22,96,97,98,99],"endpoints","my-account","user-avatar","woocommerce","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcustomize-my-account-page.1.0.0.zip",{"slug":102,"name":103,"version":104,"author":105,"author_profile":106,"description":107,"short_description":108,"active_installs":109,"downloaded":110,"rating":58,"num_ratings":111,"last_updated":112,"tested_up_to":113,"requires_at_least":114,"requires_php":115,"tags":116,"homepage":119,"download_link":120,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"wp-custom-avatar","WP Custom Avatar","1.2.1","Hareesh S","https:\u002F\u002Fprofiles.wordpress.org\u002Fhareesh-pillai\u002F","\u003Cp>WP Custom Avatar – This light plugin adds the capability to change the default Avatar in your website. This is usually displayed when a person without a gravatar comments on your blog.\u003Cbr \u002F>\n1. Configure the plugin by going to \u003Ccode>Appearance\u003C\u002Fcode> > \u003Ccode>Customize\u003C\u002Fcode> menu that appears in your admin menu.\u003Cbr \u002F>\n2. Upload the Custom Avatar image in the WP Custom Avatar section.\u003Cbr \u002F>\n3. Navigate to \u003Ccode>Settings\u003C\u002Fcode> > \u003Ccode>Discussion\u003C\u002Fcode> menu. Scroll down to the Avatars section and choose the image that you uploaded as the Default Avatar.\u003C\u002Fp>\n\u003Ch3>Licence\u003C\u002Fh3>\n\u003Cp>This plugin is released under the GPL, you can use it free of charge on your personal or commercial blog.\u003C\u002Fp>\n","WP Custom Avatar adds the capability to change the default Avatar in your website.",500,12316,7,"2022-12-23T19:48:00.000Z","6.1.10","3.6","5.2",[20,53,117,118],"plugins","user-logo","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-custom-avatar\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-custom-avatar.1.2.1.zip",{"slug":122,"name":123,"version":124,"author":125,"author_profile":126,"description":127,"short_description":128,"active_installs":129,"downloaded":130,"rating":131,"num_ratings":132,"last_updated":133,"tested_up_to":134,"requires_at_least":39,"requires_php":135,"tags":136,"homepage":139,"download_link":140,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"letter-avatars","Letter Avatars","3.1.0","Sibin Grasic","https:\u002F\u002Fprofiles.wordpress.org\u002Fseebeen\u002F","\u003Cp>Letter Avatars \u003Cstrong>enables custom avatars for users without gravatar\u003C\u002Fstrong>. Avatar will be replaced with the first letter of username or e-mail.\u003C\u002Fp>\n\u003Cp>Letter Avatars does not use any images, scripts, or font-icons. All letters will be rendered by your theme font (or Optionally via a Google font).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Works anywhere – Plugin hooks into pre_get_avatar function, so the avatar size is preserved\u003C\u002Fli>\n\u003Cli>Highly customizable – You can change colors, letter font, as well as the font size\u003C\u002Fli>\n\u003Cli>Stylish – You can change the background and letter colors or you can randomize them for all the avatars\u003C\u002Fli>\n\u003Cli>Lightweight – Plugin does not use any external stylesheet, image, or js files. It only adds a small inline css in your header\u003C\u002Fli>\n\u003Cli>Highly compatible – You don’t have to edit your theme \u002F plugin files, it works automatically and plays nice with other plugins\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works with BuddyPress\u003C\u002Fstrong> – Users and groups without gravatar \u002F local avatar will use Letter Avatars\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works with YITH Reviews for WooCommerce\u003C\u002Fstrong> – Avatars in reviews support Letter Avatars\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works with WP User Avatar\u003C\u002Fstrong> – Users with Custom Avatar will use those, users without avatar will default to Letter Avatar\u003C\u002Fli>\n\u003C\u002Ful>\n","Sets custom avatars for users without gravatar. Avatars will be replaced by first letter of usename (or e-mail) on a colorful background",300,18850,92,9,"2020-03-03T09:24:00.000Z","5.3.21","7.0",[75,137,20,53,138],"comment","letter","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fletter-avatars\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fletter-avatars.3.1.zip",{"attackSurface":142,"codeSignals":189,"taintFlows":196,"riskAssessment":197,"analyzedAt":207},{"hooks":143,"ajaxHandlers":181,"restRoutes":182,"shortcodes":183,"cronEvents":187,"entryPointCount":188,"unprotectedCount":13},[144,150,153,157,161,164,168,171,177],{"type":145,"name":146,"callback":147,"file":148,"line":149},"action","admin_print_styles-user-edit.php","wpma_admin_print_styles","wpmyavatar.php",12,{"type":145,"name":151,"callback":147,"file":148,"line":152},"admin_print_styles-profile.php",13,{"type":145,"name":154,"callback":155,"file":148,"line":156},"admin_enqueue_scripts","load_wp_media_files",22,{"type":145,"name":158,"callback":159,"file":148,"line":160},"show_user_profile","wpma_form",24,{"type":145,"name":162,"callback":159,"file":148,"line":163},"edit_user_profile",25,{"type":145,"name":165,"callback":166,"file":148,"line":167},"personal_options_update","wpma_profile_fields",103,{"type":145,"name":169,"callback":166,"file":148,"line":170},"edit_user_profile_update",104,{"type":172,"name":173,"callback":174,"priority":175,"file":148,"line":176},"filter","get_avatar","wpma",10,119,{"type":145,"name":178,"callback":179,"file":148,"line":180},"admin_head","wpma_move_around",165,[],[],[184],{"tag":174,"callback":185,"file":148,"line":186},"wpma_shortcode",177,[],1,{"dangerousFunctions":190,"sqlUsage":191,"outputEscaping":193,"fileOperations":13,"externalRequests":13,"nonceChecks":13,"capabilityChecks":31,"bundledLibraries":195},[],{"prepared":13,"raw":13,"locations":192},[],{"escaped":188,"rawEcho":13,"locations":194},[],[],[],{"summary":198,"deductions":199},"The wpmyavatar v1.1 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by exclusively using prepared statements for SQL queries and properly escaping all output. There are no identified dangerous functions, file operations, or external HTTP requests, which significantly reduces the plugin's attack surface. Furthermore, the absence of known CVEs and a clean vulnerability history suggests a commitment to security by the developers or a lack of historically exploitable issues.\n\nHowever, there are a few areas that warrant consideration. The presence of a shortcode without explicit authentication checks, while not immediately flagged as a critical issue due to the limited total entry points, could be a potential area of concern if the shortcode's functionality is sensitive. The absence of nonce checks, although not directly tied to specific vulnerabilities in this analysis, is a common security best practice for WordPress plugins, especially when handling user input or actions that modify data. While no critical taint flows were identified, the limited scope of the taint analysis (0 flows analyzed) means that potentially unsanitized paths might not have been detected.\n\nIn conclusion, wpmyavatar v1.1 appears to be a relatively secure plugin with sound coding practices regarding SQL and output handling. The lack of known vulnerabilities is a significant positive. The primary areas for improvement would be to ensure any shortcodes have appropriate capability checks and to consider implementing nonce checks for added security, even if no immediate threats are apparent. The limited taint analysis scope is a weakness in the assessment itself, rather than the plugin's code.",[200,203,205],{"reason":201,"points":202},"Shortcode without auth checks",5,{"reason":204,"points":202},"Missing nonce checks",{"reason":206,"points":31},"Limited taint analysis scope","2026-03-16T22:54:01.168Z",{"wat":209,"direct":215},{"assetPaths":210,"generatorPatterns":212,"scriptPaths":213,"versionParams":214},[211],"\u002Fwp-content\u002Fplugins\u002Fwpmyavatar\u002Fcss\u002Fmy-avatar.css",[],[],[],{"cssClasses":216,"htmlComments":220,"htmlAttributes":221,"restEndpoints":227,"jsGlobals":228,"shortcodeOutput":230},[217,218,219],"my-avatar-display","my-avatar-display-image","my-avatar-link",[],[222,223,224,225,226],"id=\"wpma_field_row\"","id=\"my-avatar-display\"","id=\"my-avatar-display-image\"","id=\"my-avatar-link\"","id=\"wpma_url\"",[],[229],"file_frame",[231],"\u003Cimg src=\""]