[凹凸曼]AI自动回复AI自动评论 Security & Risk Analysis

wordpress.org/plugins/apoyl-aicomments

基于DeepSeek大模型DeepSeek-V3、推理模型DeepSeek-R1、百度大模型,发完文章后,自动实现AI自动跟评论,多马甲随机回复,无需要人工干预自动回复,让平台运营更加活跃。

10 active installs v1.3.1 PHP 7.4+ WP 6.0+ Updated Dec 25, 2025
ai%e6%96%87%e7%ab%a0%e7%99%be%e5%ba%a6gptdeepseek%e9%a9%ac%e7%94%b2%e8%b7%9f%e8%af%84%e6%b4%bb%e8%b7%83%e4%ba%ba%e6%b0%94
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is [凹凸曼]AI自动回复AI自动评论 Safe to Use in 2026?

Generally Safe

Score 100/100

[凹凸曼]AI自动回复AI自动评论 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "apoyl-aicomments" plugin v1.3.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks, combined with zero critical or high severity taint flows and no known CVEs, suggests a well-developed and secure plugin. The code also demonstrates good practices in output escaping, with 96% of outputs being properly escaped, and SQL query usage leans heavily towards prepared statements (80%).

However, a few areas warrant attention. The presence of a single external HTTP request without further context about its destination or how its response is handled could potentially introduce a risk if the external service is compromised or returns malicious data. Additionally, the complete absence of capability checks, while potentially indicating a limited scope of functionality that doesn't require privilege checks, also means that any interactions are not being validated against user roles, which could be a concern depending on the plugin's intended use. The single nonce check, while present, is only one, and the overall lack of diverse entry points means the effectiveness of this single check is hard to gauge in isolation.

In conclusion, "apoyl-aicomments" v1.3.1 appears to be a secure plugin with minimal apparent vulnerabilities. Its strengths lie in its limited attack surface and good coding practices regarding SQL and output sanitization. The primary weaknesses are the single external HTTP request and the absence of capability checks, which could be mitigated with more information about the plugin's functionality and the target of the HTTP request. The lack of historical vulnerabilities further supports its current security standing.

Key Concerns

  • External HTTP request without auth/context
  • No capability checks found
Vulnerabilities
None known

[凹凸曼]AI自动回复AI自动评论 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

[凹凸曼]AI自动回复AI自动评论 Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
4 prepared
Unescaped Output
1
25 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

80% prepared5 total queries

Output Escaping

96% escaped26 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<setting> (admin\partials\setting.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

[凹凸曼]AI自动回复AI自动评论 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionplugins_loadedincludes\aicomments.php:49
actionadmin_menuincludes\aicomments.php:54
actionpublish_postincludes\aicomments.php:56
Maintenance & Trust

[凹凸曼]AI自动回复AI自动评论 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 25, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

[凹凸曼]AI自动回复AI自动评论 Developer Profile

apoyl

27 plugins · 710 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect [凹凸曼]AI自动回复AI自动评论

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apoyl-aicomments/admin/css/admin.css/wp-content/plugins/apoyl-aicomments/admin/js/admin.js
Version Parameters
apoyl-aicomments/admin/css/admin.css?ver=apoyl-aicomments/admin/js/admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about [凹凸曼]AI自动回复AI自动评论