多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 Security & Risk Analysis

wordpress.org/plugins/baidu-submit-link

多合一搜索自动推送管理插件(原百度搜索推送管理插件)是一款针对WP开发的功能非常强大的百度、Google、Bing、IndexNow、Yandex和头条搜索引擎链接推送插件。协助站长将网站资源快速推送至各大搜索引擎,有利于提升网站的搜索引擎收录效率;该插件还提供文章百度收录查询功能。

3K active installs v4.2.11 PHP 7.0.0+ WP 6.0+ Updated Jul 4, 2024
baidubinggoogleseotoutiao
92
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 24, 2023
Safety Verdict

Is 多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 Safe to Use in 2026?

Generally Safe

Score 92/100

多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Feb 24, 2023Updated 1yr ago
Risk Assessment

The "baidu-submit-link" plugin v4.2.11 demonstrates generally good security practices. The static analysis reveals a well-secured attack surface, with all identified entry points (AJAX handlers) protected by authentication checks. The code shows a high percentage of SQL queries utilizing prepared statements and a near-perfect rate of output escaping, significantly mitigating common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The absence of critical or high-severity taint flows further reinforces this positive posture.

However, a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability, though patched, warrants attention. While the current version shows no unpatched CVEs, the existence of a previous CSRF issue suggests that such vulnerabilities could potentially reappear if input handling or nonce management were to be relaxed in future updates. The plugin also makes a significant number of external HTTP requests, which, while not inherently a vulnerability, could become a vector for other types of attacks if the target endpoints are compromised or if the plugin fails to properly validate responses from these external sources.

Overall, the plugin appears to be developed with security in mind, exhibiting strong adherence to best practices for sanitization and authorization. The limited attack surface and robust code signaling are commendable. The primary area for continued vigilance would be the prevention of CSRF, given its history, and careful management of external HTTP requests.

Key Concerns

  • Past medium severity CSRF vulnerability
  • Significant number of external HTTP requests
Vulnerabilities
1 published

多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-26531medium · 4.3Cross-Site Request Forgery (CSRF)

多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 <= 4.2.5 - Cross-Site Request Forgery

Feb 24, 2023 Patched in 4.2.6 (333d)
Version History

多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 Release Timeline

v4.2.11Current
v4.2.10
v4.2.9
v4.2.8
v4.2.7
v4.2.6
v4.2.51 CVE
v4.2.41 CVE
v4.2.31 CVE
v4.2.21 CVE
v4.2.11 CVE
v4.2.01 CVE
v4.1.11 CVE
v4.1.01 CVE
v4.0.91 CVE
v4.0.81 CVE
v4.0.71 CVE
v4.0.61 CVE
v4.0.51 CVE
v4.0.31 CVE
Code Analysis
Analyzed Mar 16, 2026

多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 Code Analysis

Dangerous Functions
0
Raw SQL Queries
25
87 prepared
Unescaped Output
2
81 escaped
Nonce Checks
1
Capability Checks
7
File Operations
5
External Requests
33
Bundled Libraries
0

SQL Query Safety

78% prepared112 total queries

Output Escaping

98% escaped83 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<admin.class> (classes\admin.class.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_wb_baidu_push_urlclasses\admin.class.php:68
authwp_ajax_wb_baidu_push_urlclasses\admin.class.php:69
WordPress Hooks 37
actionbsl_check_all_404_urlclasses\admin.class.php:30
actionparse_requestclasses\admin.class.php:47
actionadmin_noticesclasses\admin.class.php:48
actionwb_bsl_add_push_logclasses\admin.class.php:49
actionadmin_menuclasses\admin.class.php:56
filterplugin_action_linksclasses\admin.class.php:57
actionadmin_enqueue_scriptsclasses\admin.class.php:60
filterplugin_row_metaclasses\admin.class.php:62
actionparse_queryclasses\admin.class.php:64
actionrestrict_manage_postsclasses\admin.class.php:66
actionadd_meta_boxesclasses\admin.class.php:71
actionsave_postclasses\admin.class.php:73
filterstyle_loader_tagclasses\admin.class.php:1619
filterscript_loader_tagclasses\admin.class.php:1620
actionwp_insert_postclasses\app.class.php:15
actionwb_push_postclasses\app.class.php:16
actionwp_insert_postclasses\bing.class.php:14
actionwb_push_postclasses\bing.class.php:15
filtercron_schedulesclasses\cron.class.php:15
actionbsl_single_push_urlclasses\cron.class.php:16
actionbaidu_push_url_cron_action_v3classes\cron.class.php:17
actionbaidu_push_url_cron_action_v4classes\cron.class.php:18
actionwp_insert_postclasses\daily.class.php:23
actionwb_push_postclasses\daily.class.php:26
actionwp_insert_postclasses\google.class.php:15
actionwb_push_postclasses\google.class.php:16
actionwp_trash_postclasses\google.class.php:17
actionparse_requestclasses\indexnow.class.php:17
actionwp_insert_postclasses\indexnow.class.php:19
actionwb_push_postclasses\indexnow.class.php:20
actionwp_headclasses\site.class.php:13
actionwp_insert_postclasses\site.class.php:17
actionwb_push_postclasses\site.class.php:18
actionwp_footerclasses\site.class.php:224
actionadmin_initclasses\yandex.class.php:19
actionwp_insert_postclasses\yandex.class.php:21
actionwb_push_postclasses\yandex.class.php:22

Scheduled Events 4

bsl_check_all_404_url
bsl_single_push_url
baidu_push_url_cron_action_v4
baidu_push_url_cron_action_v3
Maintenance & Trust

多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJul 4, 2024
PHP min version7.0.0
Downloads237K

Community Trust

Rating52/100
Number of ratings5
Active installs3K
Developer Profile

多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 Developer Profile

wbolt.com

11 plugins · 17K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
202 days
View full developer profile
Detection Fingerprints

How We Detect 多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/baidu-submit-link/assets/css/bsl-backend.css/wp-content/plugins/baidu-submit-link/assets/css/bsl-frontend.css/wp-content/plugins/baidu-submit-link/assets/js/bsl-backend.js/wp-content/plugins/baidu-submit-link/assets/js/bsl-frontend.js
Script Paths
/wp-content/plugins/baidu-submit-link/assets/js/bsl-backend.js/wp-content/plugins/baidu-submit-link/assets/js/bsl-frontend.js
Version Parameters
baidu-submit-link/assets/css/bsl-backend.css?ver=baidu-submit-link/assets/css/bsl-frontend.css?ver=baidu-submit-link/assets/js/bsl-backend.js?ver=baidu-submit-link/assets/js/bsl-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
bsl-backend-wrapbsl-push-wrapper
HTML Comments
<!-- WBOLT<!-- WBOLT--><!--WBOLT--><!-- WBOLT
Data Attributes
data-bsl-iddata-bsl-nonce
JS Globals
bsl_options
REST Endpoints
/wp-json/bsl/v1/push_urls
FAQ

Frequently Asked Questions about 多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条