中文超级工具箱(China Super ToolS) Security & Risk Analysis

wordpress.org/plugins/china-super

很多站长喜欢在主题的functions.php添加代码来扩充网站功能,本插件提供一个在线管理代码片段的功能。

10 active installs v2.0 PHP + WP 3.5+ Updated Jan 10, 2015
adminfunctions-php%e5%90%8e%e5%8f%b0%e4%bb%a3%e7%a0%81%e7%ae%a1%e7%90%86
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 中文超级工具箱(China Super ToolS) Safe to Use in 2026?

Generally Safe

Score 85/100

中文超级工具箱(China Super ToolS) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'china-super' v2.0 plugin exhibits a concerning security posture primarily due to a significant number of unprotected entry points. While the plugin does not appear to utilize dangerous functions, perform raw SQL queries without prepared statements, or have any recorded vulnerability history, the static analysis reveals critical weaknesses. Specifically, the presence of three AJAX handlers that completely lack authentication checks creates a direct pathway for unauthenticated attackers to interact with the plugin's functionality. Furthermore, the absence of any nonce checks on these handlers exacerbates this risk, as it allows for potential cross-site request forgery (CSRF) attacks. The taint analysis, though limited in scope with only two flows analyzed, did identify two flows with unsanitized paths, indicating that user-supplied data might not be properly validated or handled before being used in file operations. This, combined with the fact that 100% of observed output is not properly escaped, presents a high risk of cross-site scripting (XSS) vulnerabilities. The plugin's strength lies in its lack of known historical vulnerabilities, suggesting a potentially diligent development approach in the past, but the current static analysis reveals immediate and significant security flaws that require urgent attention.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX handlers
  • Taint flows with unsanitized paths
  • Unescaped output
Vulnerabilities
None known

中文超级工具箱(China Super ToolS) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

中文超级工具箱(China Super ToolS) Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

中文超级工具箱(China Super ToolS) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
26
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped18 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
cst_install (private\ini.c.php:345)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

中文超级工具箱(China Super ToolS) Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_cstprivate\ini.c.php:12
authwp_ajax_cst_installprivate\ini.c.php:13
authwp_ajax_cst_uninstallprivate\ini.c.php:14
WordPress Hooks 4
actionadmin_enqueue_scriptsprivate\ini.c.php:16
actionadmin_menuprivate\ini.c.php:19
actioninitprivate\system\GoogleFontsSYS.php:12
filterget_avatarprivate\system\GravatarSYS.php:11
Maintenance & Trust

中文超级工具箱(China Super ToolS) Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedJan 10, 2015
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

中文超级工具箱(China Super ToolS) Developer Profile

nocase

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 中文超级工具箱(China Super ToolS)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/china-super/static/css/comm.css/wp-content/plugins/china-super/static/css/page.css/wp-content/plugins/china-super/static/js/comm.js/wp-content/plugins/china-super/static/js/page.js/wp-content/plugins/china-super/static/images/loading.gif
Script Paths
/wp-content/plugins/china-super/static/js/comm.js/wp-content/plugins/china-super/static/js/page.js
Version Parameters
china-super/static/css/comm.css?ver=china-super/static/css/page.css?ver=china-super/static/js/comm.js?ver=china-super/static/js/page.js?ver=

HTML / DOM Fingerprints

CSS Classes
dmcst_uninstallcst_installwcthxyzdy
Data Attributes
data
JS Globals
cstAjaxwct_loading
REST Endpoints
/wp-json/cst/v1/...
Shortcode Output
<a id="sms" href="javascript:;" class="button button-primary">扫描系统内置扩展</a><a id="yykz" href="javascript:;" class="button button-primary">生成系统扩展引用文件</a><a id="smzd" href="javascript:;" class="button button-primary">扫描自定义扩展</a><a id="yyzd" href="javascript:;" class="button button-primary">生成自定义扩展引用文件</a>
FAQ

Frequently Asked Questions about 中文超级工具箱(China Super ToolS)