QQ旺旺Skype微信电话二维码客服WordPress插件 5usujian super serv Security & Risk Analysis

wordpress.org/plugins/5usujian-super-serv

在网站侧边添加优美的电话、QQ、旺旺客服悬浮窗

200 active installs v1.6 PHP + WP 4.0+ Updated Mar 21, 2024
%e7%94%b5%e5%ad%90%e9%82%ae%e7%ae%b1emailqq%e5%ae%a2%e6%9c%8dskype%e6%97%ba%e6%97%ba%e5%ae%a2%e6%9c%8d
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is QQ旺旺Skype微信电话二维码客服WordPress插件 5usujian super serv Safe to Use in 2026?

Generally Safe

Score 85/100

QQ旺旺Skype微信电话二维码客服WordPress插件 5usujian super serv has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin '5usujian-super-serv' v1.6 exhibits a mixed security posture. On the positive side, there are no known CVEs associated with this plugin, and all SQL queries are properly prepared, indicating good database security practices. The absence of external HTTP requests and the use of a nonce check are also positive signs. However, the code analysis reveals significant areas of concern. A large percentage of output is not properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities. The presence of the `create_function` dangerous function is a red flag, as it can lead to arbitrary code execution if used with untrusted input. Furthermore, the plugin lacks any capability checks on its entry points, meaning any authenticated user could potentially interact with its functionality, increasing the attack surface. The absence of taint analysis results is neutral but doesn't provide assurance of security in that area. Overall, while the plugin demonstrates some good practices, the unescaped output and the use of `create_function` without proper sanitization present notable risks that require immediate attention.

Key Concerns

  • Significant portion of output not properly escaped
  • Use of dangerous function create_function
  • No capability checks on entry points
Vulnerabilities
None known

QQ旺旺Skype微信电话二维码客服WordPress插件 5usujian super serv Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

QQ旺旺Skype微信电话二维码客服WordPress插件 5usujian super serv Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
31
21 escaped
Nonce Checks
1
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionregister_deactivation_hook( __FILE__ , create_function('','delete_option("wysj_serv_options");') );5usujian-super-serv.php:44

Output Escaping

40% escaped52 total outputs
Attack Surface

QQ旺旺Skype微信电话二维码客服WordPress插件 5usujian super serv Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wy-super-serv] 5usujian-super-serv.php:65
WordPress Hooks 8
actionget_footer5usujian-super-serv.php:39
filterplugin_action_links5usujian-super-serv.php:54
filterplugins_loaded5usujian-super-serv.php:61
actioninit5usujian-super-serv.php:69
actionadmin_headwysj-admin\wysj_super_serv_admin.php:32
actionadmin_footerwysj-admin\wysj_super_serv_admin.php:38
actionadmin_enqueue_scriptswysj-admin\wysj_super_serv_admin.php:45
actionadmin_menuwysj-admin\wysj_super_serv_admin.php:457
Maintenance & Trust

QQ旺旺Skype微信电话二维码客服WordPress插件 5usujian super serv Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 21, 2024
PHP min version
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

QQ旺旺Skype微信电话二维码客服WordPress插件 5usujian super serv Developer Profile

5usj

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect QQ旺旺Skype微信电话二维码客服WordPress插件 5usujian super serv

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/5usujian-super-serv/asset/css/jquery.minicolors.css/wp-content/plugins/5usujian-super-serv/asset/css/wysj-iconfont.css/wp-content/plugins/5usujian-super-serv/asset/css/5usujian-serv-admin.css/wp-content/plugins/5usujian-super-serv/asset/js/jquery.minicolors.min.js/wp-content/plugins/5usujian-super-serv/asset/js/5usujian-serv-admin.js
Version Parameters
5usujian-super-serv/asset/js/jquery.minicolors.min.js?ver=5usujian-super-serv/asset/js/5usujian-serv-admin.js?ver=5usujian-super-serv/asset/css/jquery.minicolors.css?ver=5usujian-super-serv/asset/css/wysj-iconfont.css?ver=5usujian-super-serv/asset/css/5usujian-serv-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
wy-servwy-serv-formwy-tab-headerwysj-active-statuswysj-status-deactivewy-tabwy-tab-itemwy-con-item+1 more
HTML Comments
<!-- 图标选择框 --><!-- 升级 完整版 解锁所有功能 -->
Data Attributes
name="wysj_super_serv_form"onsubmit="return false;"name="wy_enable"name="wy_mobile"name="wy_mobileHide"
JS Globals
wysjAdminPluginBase
Shortcode Output
<div class="wy-serv">
FAQ

Frequently Asked Questions about QQ旺旺Skype微信电话二维码客服WordPress插件 5usujian super serv