
advert广告 Security & Risk Analysis
wordpress.org/plugins/advert-wzt包含开屏广告、对联广告、侧边广告、banner 广告等功能。
Is advert广告 Safe to Use in 2026?
Generally Safe
Score 100/100advert广告 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "advert-wzt" plugin version 0.0.4 exhibits a generally good security posture based on the provided static analysis. All identified entry points, including AJAX handlers, are protected by either nonce checks or, implicitly, capability checks (though the latter are explicitly listed as 0, the presence of 6 nonce checks suggests these are the primary authentication mechanisms). The absence of critical or high-severity taint flows is a significant positive indicator, suggesting that user-supplied data is being handled with reasonable care. Furthermore, the plugin has no recorded vulnerability history, indicating a strong track record of security.
However, there are areas for improvement. While the majority of SQL queries utilize prepared statements, 33% do not, which could be a potential risk if these queries handle user-controlled input without proper sanitization. Similarly, a notable portion of output (34%) is not properly escaped, leaving room for cross-site scripting (XSS) vulnerabilities if that output includes user-supplied data. The presence of 7 external HTTP requests without explicit mention of sanitization or validation could also pose a risk if the plugin interacts with untrusted external resources.
In conclusion, "advert-wzt" v0.0.4 demonstrates strengths in its protected entry points and lack of historical vulnerabilities. Nevertheless, the unescaped output and raw SQL queries represent potential weaknesses that should be addressed to further harden the plugin's security.
Key Concerns
- SQL queries not using prepared statements
- Output not properly escaped
advert广告 Security Vulnerabilities
advert广告 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
advert广告 Attack Surface
AJAX Handlers 6
WordPress Hooks 7
Maintenance & Trust
advert广告 Maintenance & Trust
Maintenance Signals
Community Trust
advert广告 Alternatives
No alternatives data available yet.
advert广告 Developer Profile
8 plugins · 1K total installs
How We Detect advert广告
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advert-wzt/inc/css/prism.css/wp-content/plugins/advert-wzt/inc/css/header.css/wp-content/plugins/advert-wzt/assets/css/advert.css/wp-content/plugins/advert-wzt/assets/js/advert.js/wp-content/plugins/advert-wzt/inc/js/header.js/wp-content/plugins/advert-wzt/inc/js/header.js/wp-content/plugins/advert-wzt/assets/js/advert.jsadvert-wzt/inc/css/prism.css?ver=advert-wzt/inc/css/header.css?ver=advert-wzt/assets/css/advert.css?ver=advert-wzt/assets/js/advert.js?ver=advert-wzt/inc/js/header.js?ver=HTML / DOM Fingerprints
advert_is_mianzeadvert_wztkj_urladvertDataadvert_wztkj_url