[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwrVzEQkWuyqKAJi-JfArBki73T6AFMofmk2Ccz4DZl8":3,"$fi8xZ_InJTRWkO9BBd9av9Uf7dxvJYK1HtL_Gxm-gEZ8":204,"$ff9jk2ApEOBDB3jkTP82VuI1TvCxBZ_qj-PtuXtVoh4I":209},{"slug":4,"name":4,"version":5,"author":6,"author_profile":7,"description":8,"short_description":9,"active_installs":10,"downloaded":11,"rating":12,"num_ratings":12,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":22,"download_link":23,"security_score":24,"vuln_count":12,"unpatched_count":12,"last_vuln_date":25,"fetched_at":26,"discovery_status":27,"vulnerabilities":28,"developer":29,"crawl_stats":25,"alternatives":36,"analysis":136,"fingerprints":179},"yuban-jp","1.2","ta_terunuma","https:\u002F\u002Fprofiles.wordpress.org\u002Fta_terunuma\u002F","\u003Cp>You can easily auto-fill addresses by simply incorporating the yuban-jp plugin into html written in YubinBango specifications.\u003Cbr \u002F>\nThere are two modules available.\u003Cbr \u002F>\n1.zipaddrx.js series\u003Cbr \u002F>\n2.yubinbango.js\u003Cbr \u002F>\nDesigners can choose and use it according to their preference.\u003Cbr \u002F>\nFor detailed information about yuban-jp, please refer to https:\u002F\u002Fzipaddr2.com\u002Fyuban-jp\u002F.\u003Cbr \u002F>\nOnly the Japanese version is supported.\u003C\u002Fp>\n\u003Ch4>In Japanese:\u003C\u002Fh4>\n\u003Cp>郵便番号から住所自動入力を簡単に利用する為のWordpressプラグインです。\u003Cbr \u002F>\nYubinBango仕様で記述されたhtmlにプラグインyuban-jpを組み込むだけで動きます。\u003Cbr \u002F>\n実働モジュールは次の2系統あります。\u003Cbr \u002F>\n1.zipaddrx.js系\u003Cbr \u002F>\n2.yubinbango.js\u003Cbr \u002F>\n設計者の好みで選択して利用できます。\u003Cbr \u002F>\nyuban-jpの詳細説明は、https:\u002F\u002Fzipaddr2.com\u002Fyuban-jp\u002Fを参照して下さい。\u003Cbr \u002F>\n[日本語版のみ対応]\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin assists in integration with external tools and automatically inserts script statements into HTML.\u003Cbr \u002F>\nThe script statements to be inserted are as follows, and can be selected based on the selection in the administration screen.\u003Cbr \u002F>\n[Free version]\u003Cbr \u002F>\n\u003Cscript type=”text\u002Fjavascript” charset=”UTF-8″ src=”https:\u002F\u002Fyubinbango.github.io\u002Fyubinbango\u002Fyubinbango.js”>\u003Cbr \u002F>\n\u003Cscript type=”text\u002Fjavascript” charset=”UTF-8″ src=”https:\u002F\u002Fzipaddr.github.io\u002Fzipaddrx.js”>\u003Cbr \u002F>\n[Paid version]\u003Cbr \u002F>\n\u003Cscript type=”text\u002Fjavascript” charset=”UTF-8″ src=”https:\u002F\u002Fzipaddr.github.io\u002Fzipaddr3.js”>\u003Cbr \u002F>\n\u003Cscript type=”text\u002Fjavascript” charset=”UTF-8″ src=”https:\u002F\u002Fzipaddr.github.io\u002Fzipaddr30.js”>\u003C\u002Fp>\n","This is a tool that automatically enters addresses from postal codes.",20,292,0,"2025-06-30T12:12:00.000Z","6.8.5","3.7","",[18,19,20,21],"address","yuban","yubinbango","zip","https:\u002F\u002Fzipaddr2.com\u002Fyuban-jp\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fyuban-jp.1.2.zip",100,null,"2026-03-15T15:16:48.613Z","no_bundle",[],{"slug":6,"display_name":6,"profile_url":7,"plugin_count":30,"total_installs":31,"avg_security_score":32,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},4,50020,93,30,89,"2026-05-20T08:04:51.121Z",[37,54,77,91,116],{"slug":38,"name":38,"version":39,"author":6,"author_profile":7,"description":40,"short_description":41,"active_installs":42,"downloaded":43,"rating":24,"num_ratings":44,"last_updated":45,"tested_up_to":46,"requires_at_least":15,"requires_php":16,"tags":47,"homepage":51,"download_link":52,"security_score":24,"vuln_count":12,"unpatched_count":12,"last_vuln_date":25,"fetched_at":53},"zipaddr-jp","1.42","\u003Cp>Firstly zipaddr has two sites of zipaddr.com and zipaddr2.com in a service provider.\u003Cbr \u002F>\nIn zipaddr.com, free site, the other are pay sites.\u003Cbr \u002F>\nThis plugin makes WordPress and zipaddr work together.\u003Cbr \u002F>\nSpecifically, generate the following javascript statement on one line.\u003Cbr \u002F>\n\u003Cscript src=”https:\u002F\u002Fzipaddr.com\u002Fjs\u002Fzipaddrx.js”   charset=”UTF-8″>\u003C\u002Fscript> or\u003Cbr \u002F>\n\u003Cscript src=”https:\u002F\u002Fzipaddr2.com\u002Fjs\u002Fzipaddr3.js”  charset=”UTF-8″>\u003C\u002Fscript> or\u003Cbr \u002F>\n\u003Cscript src=”https:\u002F\u002Fzipaddr2.com\u002Fjs\u002Fzipaddr30.js” charset=”UTF-8″>\u003C\u002Fscript>\u003C\u002Fp>\n\u003Ch4>In Japanese:\u003C\u002Fh4>\n\u003Cp>主な動作手順は次のようになります。\u003Cbr \u002F>\n1.起動設定後に郵便番号の入力を待ちます。\u003Cbr \u002F>\n2.Wordpress側は郵便番号検索リクエストをzipaddr側に送ります。\u003Cbr \u002F>\n3.zipaddrでは郵便番号からDBを検索して都道府県、市区町村、地域、データをjsonp形式で返します。\u003Cbr \u002F>\n4.Wordpress側にはガイダンスで検索の途中データが表示されます。\u003Cbr \u002F>\n5.最終的にWordpress側画面の都道府県、市区町村、地域、の各欄にデータが埋め込まれます。\u003Cbr \u002F>\nzipaddr-jpの詳細説明は、https:\u002F\u002Fzipaddr2.com\u002Fwordpress\u002Fを参照して下さい。\u003C\u002Fp>\n\u003Ch4>In English:\u003C\u002Fh4>\n\u003Cp>The main operating procedure is as follows.\u003Cbr \u002F>\n1.Wait for the zip code to be entered after the startup setting.\u003Cbr \u002F>\n2.Wordpress sends a zip code search request to zipaddr.\u003Cbr \u002F>\n3.zipaddr search DB from a zip code and return jsonp form for prefecture, a city, an address.\u003Cbr \u002F>\n4.On the WordPress side, the data in the middle of the search is displayed by the guidance.\u003Cbr \u002F>\n5.Wordpress bury each data in an address column on the WordPress side.\u003C\u002Fp>\n","zipaddr-jp is a collaborative tool that automatically inputs addresses from postal codes.",50000,399597,6,"2026-01-12T01:22:00.000Z","6.9.4",[18,48,49,21,50],"ajax","cross-domain","zipaddr","https:\u002F\u002Fzipaddr2.com\u002Fwordpress\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fzipaddr-jp.1.42.zip","2026-04-16T10:56:18.058Z",{"slug":55,"name":56,"version":57,"author":58,"author_profile":59,"description":60,"short_description":61,"active_installs":62,"downloaded":63,"rating":12,"num_ratings":12,"last_updated":64,"tested_up_to":65,"requires_at_least":66,"requires_php":67,"tags":68,"homepage":74,"download_link":75,"security_score":76,"vuln_count":12,"unpatched_count":12,"last_vuln_date":25,"fetched_at":53},"us-address-lookup-by-zip-code","US Address Lookup by Zip Code","1.0.2","PressTigers","https:\u002F\u002Fprofiles.wordpress.org\u002Fpresstigers\u002F","\u003Cp>US Address Lookup by Zip Code is an official plugin maintained by the PressTigers team. This plugin lets you look up US Addresses against the Zip Code and populates fields such as:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>City name\u003C\u002Fli>\n\u003Cli>State name\u003C\u002Fli>\n\u003Cli>Country name (which will always be the USA).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin is compatible with Contact Form 7, Ninja Forms, Gravity Forms, and Formidable Forms.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Populates US addresses against a Zip Code\u003C\u002Fli>\n\u003Cli>List down the related addresses\u003C\u002Fli>\n\u003Cli>Compatible with Contact Form 7, Ninja Forms, Gravity Forms, and Formidable Forms.\u003C\u002Fli>\n\u003Cli>1 click easy configuration button\u003C\u002Fli>\n\u003Cli>Integration control from the admin screen \u003C\u002Fli>\n\u003Cli>Complete integration guidance with each Form plugin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Please click here for \u003Ca href=\"https:\u002F\u002Fsources.presstigers.dev\u002Fusz\u002F\" rel=\"nofollow ugc\">US Address Lookup by Zip Code Demo\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>The source of addresses data is \u003Ca href=\"https:\u002F\u002Fsimplemaps.com\u002Fdata\u002Fus-zips\" rel=\"nofollow ugc\">SimpleMaps\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n","This plugin allows you to auto-fill the address and related fields by putting zip code.",10,2079,"2023-11-10T13:50:00.000Z","6.4.8","4.7","7.4",[69,70,71,72,73],"auto-populate-address","contact-form-7","forms","ninja-forms","us-zip-codes","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fus-address-lookup-by-zip-code\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fus-address-lookup-by-zip-code.1.0.2.zip",85,{"slug":78,"name":78,"version":79,"author":6,"author_profile":7,"description":80,"short_description":81,"active_installs":12,"downloaded":82,"rating":12,"num_ratings":12,"last_updated":83,"tested_up_to":84,"requires_at_least":85,"requires_php":16,"tags":86,"homepage":89,"download_link":90,"security_score":76,"vuln_count":12,"unpatched_count":12,"last_vuln_date":25,"fetched_at":53},"autoin-jp","1.4","\u003Cp>In this plug-in, WordPress and autoin.jp are linked in the application.\u003Cbr \u002F>\nWhen it starts,\u003Cbr \u002F>\n\u003Cscript src=”https:\u002F\u002Fautoin.jp\u002Fjs\u002Fautoin.js” charset=”UTF-8″>\u003C\u002Fscript>\u003Cbr \u002F>\nand\u003Cbr \u002F>\n\u003Cscript src=”https:\u002F\u002Fzipaddr.com\u002Fjs\u002Fzipaddrx.js” charset=”UTF-8″>\u003C\u002Fscript>\u003Cbr \u002F>\nIs called.\u003C\u002Fp>\n\u003Cp>[important]\u003Cbr \u002F>\nAny damage that occurs while using autoin-jp will be at your own risk.\u003C\u002Fp>\n\u003Ch4>In Japanese:\u003C\u002Fh4>\n\u003Cp>次のように動作します。\u003Cbr \u002F>\n1.フォーム起動時に「Autoin入力」ボタンを生成する。\u003Cbr \u002F>\n2.ボタンのクリックで個人情報ファイルの指示画面が出力される。\u003Cbr \u002F>\n（もう一度「Autoin入力」ボタンをクリックすると指示画面が消えます）\u003Cbr \u002F>\n3.ファイルを指示すると入力及びファイル情報がautoin.jp側に送られる。\u003Cbr \u002F>\n4.入力欄とデータが合成されてフォーム側に返送される。\u003Cbr \u002F>\n5.受信内容をフォームに描画して終了する。\u003C\u002Fp>\n\u003Ch4>In English:\u003C\u002Fh4>\n\u003Cp>It works as follows:\u003Cbr \u002F>\n1.Generate “Autoin input” button when form starts.\u003Cbr \u002F>\n2.Clicking the button outputs the personal information file instruction screen.\u003Cbr \u002F>\n3.When a file is specified, input and file information are sent to autoin.jp.\u003Cbr \u002F>\n4.The input field and data are combined and sent back to the form.\u003Cbr \u002F>\n5.Draw the received content on the form and exit.\u003C\u002Fp>\n","The ultimate automatic input tool, autoin-jp, works only in the Japanese version. The operating environment is as follows. Wordpress 5.",1374,"2021-09-01T01:55:00.000Z","5.8.13","5.3",[18,87,49,88,21],"autoin","efo","https:\u002F\u002Fautoin.jp\u002Fwordpress\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fautoin-jp.1.4.zip",{"slug":92,"name":93,"version":94,"author":95,"author_profile":96,"description":97,"short_description":98,"active_installs":99,"downloaded":100,"rating":101,"num_ratings":102,"last_updated":103,"tested_up_to":46,"requires_at_least":66,"requires_php":104,"tags":105,"homepage":111,"download_link":112,"security_score":113,"vuln_count":114,"unpatched_count":12,"last_vuln_date":115,"fetched_at":53},"astra-widgets","Astra Widgets","1.2.17","Brainstorm Force","https:\u002F\u002Fprofiles.wordpress.org\u002Fbrainstormforce\u002F","\u003Ch4>The fastest way to add more widgets into your WordPress website.\u003C\u002Fh4>\n\u003Cp>How easy can things get when you can add widgets for particular information and fetch them anywhere on your website? This goes with the most wanted information like the business address, social profile links and list icons.\u003C\u002Fp>\n\u003Cp>The Astra Widget plugin lets you create widgets to add an address, a social profile widget and list icons that you can add into your header, sidebar, footer etc. on your website.\u003C\u002Fp>\n\u003Ch4>How does this work?\u003C\u002Fh4>\n\u003Cp>The Astra Widgets plugin can be installed like any other WordPress plugin. Once installed, you will find the following widgets listed under Appearance -> Widgets\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Astra : Address\u003C\u002Fli>\n\u003Cli>Astra : List Icons\u003C\u002Fli>\n\u003Cli>Astra : Social Profiles\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>You simply need to select the place you wish to add the widget in and then add the information in the specific fields. Save this and you are done!\u003C\u002Fp>\n\u003Ch4>WHY PEOPLE LOVE THE ASTRA THEME?\u003C\u002Fh4>\n\u003Cp>Astra is currently powering over 1+ million websites. The performance and ease of use it offers has made it the go-to theme for beginners as well as experts.\u003C\u002Fp>\n\u003Ch4>Here are a few reasons why they love Astra –\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Faster Performance\u003C\u002Fstrong> – Astra follows the best coding standards and is built with speed and performance in mind. It is the best WordPress theme that lets you build faster lading and better performing websites.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Easy Customization\u003C\u002Fstrong> – With an aim to keep it simple and easy, Astra gives you lots of options to customize everything with just a few clicks. Everything can be managed through the customizer itself!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Compatibility with Page Builders\u003C\u002Fstrong> – Astra works seamlessly with all major page builders and therefore is opted as the best \u003Ca href=\"https:\u002F\u002Fwpastra.com\u002Ftheme-for-elementor\u002F?utm_source=wp-repo&utm_medium=astra_desc&utm_campaign=ast_widgets\" rel=\"nofollow ugc\">theme for Elementor\u003C\u002Fa>, Beaver Builder, Gutenberg, etc.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Pixel Perfect Design\u003C\u002Fstrong> – Astra offers pixel-perfect FREE ready-to-use website demos within a huge library of starter sites. These can simply be imported, tweaked and used to reduce your overall design time.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Deeper Integrations\u003C\u002Fstrong> – Astra lets you create and beautify eCommerce websites and those that offer online courses in minutes. This is possible due to its in-depth integrations with all WooCommerce plugins, LifterLMS, LearnDash, etc.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Ready-to-use complete website demos\u003C\u002Fstrong> – Astra offers ready-made starter templates built with Elementor, Beaver Builder, Brizy and Gutenberg. You can import them using the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fastra-sites\u002F\" rel=\"ugc\">Starter Templates\u003C\u002Fa> plugin, tweak and go live in minutes!\u003C\u002Fp>\n","Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.",200000,4562813,78,17,"2026-03-25T05:19:00.000Z","5.2",[106,107,108,109,110],"add-widget","address-widget","list-icon-widget","social-media","social-profile-widget","https:\u002F\u002Fwpastra.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fastra-widgets.1.2.17.zip",96,3,"2025-12-28 00:00:00",{"slug":117,"name":118,"version":119,"author":120,"author_profile":121,"description":122,"short_description":123,"active_installs":99,"downloaded":124,"rating":113,"num_ratings":125,"last_updated":126,"tested_up_to":46,"requires_at_least":127,"requires_php":128,"tags":129,"homepage":134,"download_link":135,"security_score":24,"vuln_count":12,"unpatched_count":12,"last_vuln_date":25,"fetched_at":53},"custom-post-type-permalinks","Custom Post Type Permalinks","3.5.4","Toro_Unit (Hiroshi Urabe)","https:\u002F\u002Fprofiles.wordpress.org\u002Ftoro_unit\u002F","\u003Cp>Custom Post Type Permalinks allow you edit the permalink structure of custom post type.\u003C\u002Fp>\n\u003Cp>Change custom taxonomy archive’s permalink to “example.org\u002Fpost_type\u002Ftaxonomy_name\u002Fterm_slug”. Can disable this fix.\u003C\u002Fp>\n\u003Cp>And support \u003Ccode>wp_get_archives( 'post_type=foo' )\u003C\u002Fcode> and post type date archive (ex. \u003Ccode>example.com\u002Fpost_type_slug\u002Fdate\u002F2010\u002F01\u002F01\u003C\u002Fcode> ).\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ftorounit\u002Fcustom-post-type-permalinks\" rel=\"nofollow ugc\">This Plugin published on GitHub.\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Donation: Please send \u003Ca href=\"http:\u002F\u002Fwww.amazon.co.jp\u002Fregistry\u002Fwishlist\u002FCOKSXS25MVQV\" rel=\"nofollow ugc\">My Wishlist\u003C\u002Fa> or \u003Ca href=\"https:\u002F\u002Fwww.paypal.me\u002Ftorounit\" rel=\"nofollow ugc\">Paypal\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Translators\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Japanese(ja) – \u003Ca href=\"http:\u002F\u002Fwww.torounit.com\u002F\" rel=\"nofollow ugc\">Toro_Unit\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>French(fr_FR) – \u003Ca href=\"http:\u002F\u002Fgeoffrey.crofte.fr\u002F\" rel=\"nofollow ugc\">Geoffrey Crofte\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Russian(ru_RU) – \u003Ca href=\"http:\u002F\u002Folart.ru\" rel=\"nofollow ugc\">Olart\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002Fnatali_z\" rel=\"nofollow ugc\">Natali_Z\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Also checkout\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsimple-post-type-permalinks\u002F\" rel=\"ugc\">Simple Post Type Permalinks\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Setting on Code\u003C\u002Fh3>\n\u003Cp>Example:\u003C\u002Fp>\n\u003Cpre>register_post_type( 'foo',\n    array(\n        'public' => true,\n        'has_archive' => true,\n        'rewrite' => array(\n            \"with_front\" => true\n        ),\n        'cptp_permalink_structure' => '%post_id%'\n    )\n);\u003C\u002Fpre>\n\u003Ch4>Exclude specific post type\u003C\u002Fh4>\n\u003Cpre>add_filter(  'cptp_is_rewrite_supported_by_foo',  '__return_false' );\n\n\u002F\u002F or\n\nadd_filter(  'cptp_is_rewrite_supported', function ( $support , $post_type ) {\n    if ( 'foo' === $post_type ) {\n        return false;\n    }\n    return $support;\n}, 10, 2);\u003C\u002Fpre>\n","Edit the permalink of custom post type.",1752588,71,"2026-03-31T17:55:00.000Z","6.7","8.0",[18,130,131,132,133],"custom-post-type","link","permalink","url","https:\u002F\u002Fgithub.com\u002Ftorounit\u002Fcustom-post-type-permalinks","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcustom-post-type-permalinks.3.5.4.zip",{"attackSurface":137,"codeSignals":154,"taintFlows":169,"riskAssessment":170,"analyzedAt":178},{"hooks":138,"ajaxHandlers":150,"restRoutes":151,"shortcodes":152,"cronEvents":153,"entryPointCount":12,"unprotectedCount":12},[139,145],{"type":140,"name":141,"callback":142,"file":143,"line":144},"action","admin_menu","yubanjp_adminmenu","yuban-jp.php",24,{"type":146,"name":147,"callback":148,"priority":149,"file":143,"line":33},"filter","the_content","yubanjp_change",999999,[],[],[],[],{"dangerousFunctions":155,"sqlUsage":163,"outputEscaping":165,"fileOperations":12,"externalRequests":12,"nonceChecks":167,"capabilityChecks":12,"bundledLibraries":168},[156,161],{"fn":157,"file":158,"line":159,"context":160},"unserialize","admin.php",52,"$param= unserialize( get_option(yubanjp_DEFINE) ); \u002F\u002F get定義情報",{"fn":157,"file":162,"line":44,"context":160},"yuban.php",{"prepared":12,"raw":12,"locations":164},[],{"escaped":114,"rawEcho":12,"locations":166},[],1,[],[],{"summary":171,"deductions":172},"The \"yuban-jp\" plugin v1.2 exhibits a generally strong security posture based on the provided static analysis. It boasts zero detected AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting its attack surface. Furthermore, all SQL queries are prepared, all outputs are properly escaped, and there are no detected file operations or external HTTP requests. The presence of a nonce check is also a positive indicator of security awareness in the code.\n\nHowever, the static analysis does reveal two instances of the `unserialize` function. While there are no current taint flows or known CVEs associated with this function in this specific analysis, the use of `unserialize` on untrusted data is a well-known security risk that can lead to Remote Code Execution (RCE) if not handled with extreme caution and proper validation. The absence of capability checks is another area of concern, as it suggests that even entry points (if they existed) might not be properly secured against unauthorized access. The vulnerability history being clean is a positive sign, indicating a lack of past exploitable issues, but it does not negate the inherent risks posed by potentially insecure functions like `unserialize`.\n\nIn conclusion, while \"yuban-jp\" v1.2 demonstrates good practices in many areas, the presence of `unserialize` introduces a potential vulnerability that requires careful consideration. The lack of capability checks further adds to this concern. The absence of known CVEs and a clean taint analysis are reassuring, but the inherent risk of `unserialize` means the plugin is not entirely risk-free. Diligent review and potential mitigation strategies around the `unserialize` usage are recommended.",[173,176],{"reason":174,"points":175},"Use of unserialize function",15,{"reason":177,"points":62},"Missing capability checks","2026-03-16T22:57:39.697Z",{"wat":180,"direct":190},{"assetPaths":181,"generatorPatterns":186,"scriptPaths":187,"versionParams":188},[182,183,184,185],"\u002Fwp-content\u002Fplugins\u002Fyuban-jp\u002Fyuban.js","\u002Fwp-content\u002Fplugins\u002Fyuban-jp\u002Fyuban.css","\u002Fwp-content\u002Fplugins\u002Fyuban-jp\u002Fadmin.js","\u002Fwp-content\u002Fplugins\u002Fyuban-jp\u002Fadmin.css",[],[182,184],[189],"yubanjp_VERS=1.2",{"cssClasses":191,"htmlComments":195,"htmlAttributes":196,"restEndpoints":199,"jsGlobals":200,"shortcodeOutput":202},[192,193,194],"yubanjp_input","yubanjp_button","yubanjp_address_result",[],[197,198],"data-yubanjp-postcode-input","data-yubanjp-address-output",[],[201],"yubanjp_ajax_url",[203],"[yubanjp_form]",{"error":205,"url":206,"statusCode":207,"statusMessage":208,"message":208},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fyuban-jp\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":5,"total_versions":12,"versions":210},[]]