AddThisChina(分享家:收藏&分享按钮) Security & Risk Analysis

wordpress.org/plugins/addthischina

适合中文网站的AddThis按钮,含有主流中文收藏分享按钮。方便读者分享, 增加网站流量![2009-09-25]新增颜色样式配置。【如果之前手工安装1.0版本,请卸载后重新安装1.1版本,并重新保存配置】

10 active installs v1.1 PHP + WP 2.5+ Updated Unknown
%e7%bd%91%e7%bb%9c%e6%94%b6%e8%97%8f%e5%a4%b9%e5%88%86%e4%ba%ab%e5%88%86%e4%ba%ab%e6%8c%89%e9%92%ae%e6%94%b6%e8%97%8f%e4%b9%a6%e7%ad%be
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AddThisChina(分享家:收藏&分享按钮) Safe to Use in 2026?

Generally Safe

Score 100/100

AddThisChina(分享家:收藏&分享按钮) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'addthischina' v1.1 plugin exhibits a mixed security posture. While the static analysis reveals no directly exploitable entry points like AJAX handlers, REST API routes, shortcodes, or cron events without authentication, this is heavily offset by significant concerns in output sanitization. With 100% of its 7 output points unescaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of taint analysis flows is not necessarily a positive sign; it may simply indicate that the analysis tool did not identify any paths to analyze, or that the plugin's structure did not lend itself to typical taint flow detection. Furthermore, the complete lack of nonce and capability checks across all potential (though currently non-existent) entry points suggests a potential oversight in security best practices that could become problematic if the plugin were expanded. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this should not overshadow the critical issue of unescaped output, which presents an immediate and significant risk despite the lack of past vulnerabilities or identified complex attack flows. The plugin's strength lies in its minimal attack surface and secure SQL practices, but its critical weakness is its failure to properly escape output.

Key Concerns

  • All output is unescaped (7 instances)
  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

AddThisChina(分享家:收藏&分享按钮) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AddThisChina(分享家:收藏&分享按钮) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

AddThisChina(分享家:收藏&分享按钮) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuaddthis_plugin.php:30
filterthe_contentaddthis_plugin.php:32
Maintenance & Trust

AddThisChina(分享家:收藏&分享按钮) Maintenance & Trust

Maintenance Signals

WordPress version tested2.8
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

AddThisChina(分享家:收藏&分享按钮) Developer Profile

hfw828

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AddThisChina(分享家:收藏&分享按钮)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/addthischina/a1.gif
Script Paths
http://china-addthis.googlecode.com/svn/trunk/addthis.js

HTML / DOM Fingerprints

CSS Classes
addthis_org_cn
Data Attributes
u='t='d='tag='
Shortcode Output
<span class='addthis_org_cn'><a href='http://addthis.org.cn/share/' title='收藏-分享'><img src='
FAQ

Frequently Asked Questions about AddThisChina(分享家:收藏&分享按钮)