
中文超级工具箱(China Super ToolS) Security & Risk Analysis
wordpress.org/plugins/china-super很多站长喜欢在主题的functions.php添加代码来扩充网站功能,本插件提供一个在线管理代码片段的功能。
Is 中文超级工具箱(China Super ToolS) Safe to Use in 2026?
Generally Safe
Score 85/100中文超级工具箱(China Super ToolS) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'china-super' v2.0 plugin exhibits a concerning security posture primarily due to a significant number of unprotected entry points. While the plugin does not appear to utilize dangerous functions, perform raw SQL queries without prepared statements, or have any recorded vulnerability history, the static analysis reveals critical weaknesses. Specifically, the presence of three AJAX handlers that completely lack authentication checks creates a direct pathway for unauthenticated attackers to interact with the plugin's functionality. Furthermore, the absence of any nonce checks on these handlers exacerbates this risk, as it allows for potential cross-site request forgery (CSRF) attacks. The taint analysis, though limited in scope with only two flows analyzed, did identify two flows with unsanitized paths, indicating that user-supplied data might not be properly validated or handled before being used in file operations. This, combined with the fact that 100% of observed output is not properly escaped, presents a high risk of cross-site scripting (XSS) vulnerabilities. The plugin's strength lies in its lack of known historical vulnerabilities, suggesting a potentially diligent development approach in the past, but the current static analysis reveals immediate and significant security flaws that require urgent attention.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX handlers
- Taint flows with unsanitized paths
- Unescaped output
中文超级工具箱(China Super ToolS) Security Vulnerabilities
中文超级工具箱(China Super ToolS) Release Timeline
中文超级工具箱(China Super ToolS) Code Analysis
Output Escaping
Data Flow Analysis
中文超级工具箱(China Super ToolS) Attack Surface
AJAX Handlers 3
WordPress Hooks 4
Maintenance & Trust
中文超级工具箱(China Super ToolS) Maintenance & Trust
Maintenance Signals
Community Trust
中文超级工具箱(China Super ToolS) Alternatives
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
Header Footer Code Manager
header-footer-code-manager
Easily add tracking code snippets, conversion pixels, or other scripts required by third party services for analytics, marketing, or chat features.
Admin Menu Editor
admin-menu-editor
Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.
Adminimize
adminimize
Adminimize that lets you hide 'unnecessary' items from the WordPress backend
中文超级工具箱(China Super ToolS) Developer Profile
1 plugin · 10 total installs
How We Detect 中文超级工具箱(China Super ToolS)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/china-super/static/css/comm.css/wp-content/plugins/china-super/static/css/page.css/wp-content/plugins/china-super/static/js/comm.js/wp-content/plugins/china-super/static/js/page.js/wp-content/plugins/china-super/static/images/loading.gif/wp-content/plugins/china-super/static/js/comm.js/wp-content/plugins/china-super/static/js/page.jschina-super/static/css/comm.css?ver=china-super/static/css/page.css?ver=china-super/static/js/comm.js?ver=china-super/static/js/page.js?ver=HTML / DOM Fingerprints
dmcst_uninstallcst_installwcthxyzdydatacstAjaxwct_loading/wp-json/cst/v1/...<a id="sms" href="javascript:;" class="button button-primary">扫描系统内置扩展</a><a id="yykz" href="javascript:;" class="button button-primary">生成系统扩展引用文件</a><a id="smzd" href="javascript:;" class="button button-primary">扫描自定义扩展</a><a id="yyzd" href="javascript:;" class="button button-primary">生成自定义扩展引用文件</a>