advert广告 Security & Risk Analysis

wordpress.org/plugins/advert-wzt

包含开屏广告、对联广告、侧边广告、banner 广告等功能。

0 active installs v0.0.4 PHP 7.4+ WP 5.3+ Updated Unknown
%e5%af%b9%e8%81%94%e5%b9%bf%e5%91%8a%ef%bc%8c%e5%bc%80%e5%b1%8f%e5%b9%bf%e5%91%8a%ef%bc%8cbanner-%e5%b9%bf%e5%91%8a%ef%bc%8c%e4%be%a7%e8%be%b9%e5%b9%bf%e5%91%8a
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is advert广告 Safe to Use in 2026?

Generally Safe

Score 100/100

advert广告 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "advert-wzt" plugin version 0.0.4 exhibits a generally good security posture based on the provided static analysis. All identified entry points, including AJAX handlers, are protected by either nonce checks or, implicitly, capability checks (though the latter are explicitly listed as 0, the presence of 6 nonce checks suggests these are the primary authentication mechanisms). The absence of critical or high-severity taint flows is a significant positive indicator, suggesting that user-supplied data is being handled with reasonable care. Furthermore, the plugin has no recorded vulnerability history, indicating a strong track record of security.

However, there are areas for improvement. While the majority of SQL queries utilize prepared statements, 33% do not, which could be a potential risk if these queries handle user-controlled input without proper sanitization. Similarly, a notable portion of output (34%) is not properly escaped, leaving room for cross-site scripting (XSS) vulnerabilities if that output includes user-supplied data. The presence of 7 external HTTP requests without explicit mention of sanitization or validation could also pose a risk if the plugin interacts with untrusted external resources.

In conclusion, "advert-wzt" v0.0.4 demonstrates strengths in its protected entry points and lack of historical vulnerabilities. Nevertheless, the unescaped output and raw SQL queries represent potential weaknesses that should be addressed to further harden the plugin's security.

Key Concerns

  • SQL queries not using prepared statements
  • Output not properly escaped
Vulnerabilities
None known

advert广告 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

advert广告 Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
13
25 escaped
Nonce Checks
6
Capability Checks
0
File Operations
0
External Requests
7
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

66% escaped38 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
advert_vip (inc\post.php:36)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

advert广告 Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_advert_get_vipinc\post.php:5
authwp_ajax_advert_vipinc\post.php:6
authwp_ajax_advert_guanggaoinc\post.php:7
authwp_ajax_advert_get_guanggaoinc\post.php:8
authwp_ajax_advert_get_gonggaoinc\post.php:9
authwp_ajax_advert_gonggao_readinc\post.php:10
WordPress Hooks 7
actionplugins_loadedadvert.php:25
actionwp_enqueue_scriptsinc\header.php:6
actionadmin_enqueue_scriptsinc\index.php:7
actionadmin_menuinc\index.php:9
actionplugins_loadedinc\index.php:11
filteradvert_dhdfkdksjinc\index.php:16
filteradvert_dssddinc\index.php:17
Maintenance & Trust

advert广告 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads445

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

advert广告 Alternatives

No alternatives data available yet.

Developer Profile

advert广告 Developer Profile

沃之涛

8 plugins · 1K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
98 days
View full developer profile
Detection Fingerprints

How We Detect advert广告

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advert-wzt/inc/css/prism.css/wp-content/plugins/advert-wzt/inc/css/header.css/wp-content/plugins/advert-wzt/assets/css/advert.css/wp-content/plugins/advert-wzt/assets/js/advert.js/wp-content/plugins/advert-wzt/inc/js/header.js
Script Paths
/wp-content/plugins/advert-wzt/inc/js/header.js/wp-content/plugins/advert-wzt/assets/js/advert.js
Version Parameters
advert-wzt/inc/css/prism.css?ver=advert-wzt/inc/css/header.css?ver=advert-wzt/assets/css/advert.css?ver=advert-wzt/assets/js/advert.js?ver=advert-wzt/inc/js/header.js?ver=

HTML / DOM Fingerprints

CSS Classes
advert_is_mianze
Data Attributes
advert_wztkj_url
JS Globals
advertDataadvert_wztkj_url
FAQ

Frequently Asked Questions about advert广告