
AddThisChina(分享家:收藏&分享按钮) Security & Risk Analysis
wordpress.org/plugins/addthischina适合中文网站的AddThis按钮,含有主流中文收藏分享按钮。方便读者分享, 增加网站流量![2009-09-25]新增颜色样式配置。【如果之前手工安装1.0版本,请卸载后重新安装1.1版本,并重新保存配置】
Is AddThisChina(分享家:收藏&分享按钮) Safe to Use in 2026?
Generally Safe
Score 100/100AddThisChina(分享家:收藏&分享按钮) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'addthischina' v1.1 plugin exhibits a mixed security posture. While the static analysis reveals no directly exploitable entry points like AJAX handlers, REST API routes, shortcodes, or cron events without authentication, this is heavily offset by significant concerns in output sanitization. With 100% of its 7 output points unescaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of taint analysis flows is not necessarily a positive sign; it may simply indicate that the analysis tool did not identify any paths to analyze, or that the plugin's structure did not lend itself to typical taint flow detection. Furthermore, the complete lack of nonce and capability checks across all potential (though currently non-existent) entry points suggests a potential oversight in security best practices that could become problematic if the plugin were expanded. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this should not overshadow the critical issue of unescaped output, which presents an immediate and significant risk despite the lack of past vulnerabilities or identified complex attack flows. The plugin's strength lies in its minimal attack surface and secure SQL practices, but its critical weakness is its failure to properly escape output.
Key Concerns
- All output is unescaped (7 instances)
- No nonce checks detected
- No capability checks detected
AddThisChina(分享家:收藏&分享按钮) Security Vulnerabilities
AddThisChina(分享家:收藏&分享按钮) Code Analysis
Output Escaping
AddThisChina(分享家:收藏&分享按钮) Attack Surface
WordPress Hooks 2
Maintenance & Trust
AddThisChina(分享家:收藏&分享按钮) Maintenance & Trust
Maintenance Signals
Community Trust
AddThisChina(分享家:收藏&分享按钮) Alternatives
bShare 分享
17fav-bookmark-share
数以万计的分享,源自一个简单的按钮, bShare 分享 是一个强大的网页分享插件工具,您的读者可以将您网站上精采的内容快速分享、转贴到社群网络上。
SinoShare
sinoshare
wordpress的日志文章分享收藏插件。
WP Weixin
wp-weixin
WordPress WeChat integration
[凹凸曼]微信分享有图-WeChat Page Sharing
apoyl-weixinshare
这是一款解决在微信里首页、文章、单页等页面(如post, page, attachment, revision, menu)分享到朋友或朋友圈,图标无法显示,描述更改为部分文章内容或者文章摘要. This is a solution to share to Chat or share on Mome …
Bosima WeChat Page Sharing
bosima-wechat-page-sharing
您可以控制Wordpress页面的分享内容,包括Url、标题、图片和描述,支持分享到微信朋友、微信朋友圈、QQ和QQ空间。 请注意,0.2.x版本升级后需重新配置AppId和AppSecrect。
AddThisChina(分享家:收藏&分享按钮) Developer Profile
1 plugin · 10 total installs
How We Detect AddThisChina(分享家:收藏&分享按钮)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/addthischina/a1.gifhttp://china-addthis.googlecode.com/svn/trunk/addthis.jsHTML / DOM Fingerprints
addthis_org_cnu='t='d='tag='<span class='addthis_org_cn'><a href='http://addthis.org.cn/share/' title='收藏-分享'><img src='