[凹凸曼]一键采集抖音视频 Security & Risk Analysis

wordpress.org/plugins/apoyl-grabdouyin

通过抖音分享视频链接,一键采集抖音视频到自己网站上,非常方便实用的工具。

20 active installs v1.1.0 PHP 7.4+ WP 6.0+ Updated Nov 20, 2024
douyin%e9%87%87%e9%9b%86%e6%8a%93%e5%8f%96%e6%8a%96%e9%9f%b3
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is [凹凸曼]一键采集抖音视频 Safe to Use in 2026?

Generally Safe

Score 92/100

[凹凸曼]一键采集抖音视频 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "apoyl-grabdouyin" plugin v1.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, avoiding file operations, and having a high percentage of properly escaped output. The absence of known CVEs and a clean vulnerability history further suggest a relatively stable codebase. However, significant concerns arise from the static analysis. The plugin has a single entry point via an AJAX handler that lacks any authentication checks. This unprotected endpoint represents a critical attack vector that could be exploited by unauthenticated users. Furthermore, the taint analysis reveals two flows with unsanitized paths, indicating a potential for malicious data to be processed without proper validation, although these are not classified as critical or high severity.

Key Concerns

  • Unprotected AJAX handler
  • Unsanitized paths in taint flows
Vulnerabilities
None known

[凹凸曼]一键采集抖音视频 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

[凹凸曼]一键采集抖音视频 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
15 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

88% escaped17 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
apoyl_grabdouyin_ajax (admin\admin.php:75)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

[凹凸曼]一键采集抖音视频 Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_apoyl_grabdouyin_ajaxincludes\grabdouyin.php:56
WordPress Hooks 3
actionplugins_loadedincludes\grabdouyin.php:49
actionadmin_menuincludes\grabdouyin.php:54
actionadmin_initincludes\grabdouyin.php:55
Maintenance & Trust

[凹凸曼]一键采集抖音视频 Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 20, 2024
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

[凹凸曼]一键采集抖音视频 Developer Profile

apoyl

27 plugins · 710 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect [凹凸曼]一键采集抖音视频

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apoyl-grabdouyin/admin/css/admin.css/wp-content/plugins/apoyl-grabdouyin/admin/js/admin.js
Version Parameters
apoyl-grabdouyin/admin/css/admin.css?ver=apoyl-grabdouyin/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
apoyl-grabdouyin-editor-url
Data Attributes
data-nonce
JS Globals
apoyl_grabdouyin_ajax_object
REST Endpoints
/wp-json/apoyl-grabdouyin/v1/ajax
FAQ

Frequently Asked Questions about [凹凸曼]一键采集抖音视频