
WP CN Excerpt Security & Risk Analysis
wordpress.org/plugins/cn-excerptWordPress高级摘要插件。支持在后台设置摘要长度,摘要最后的显示字符,以及允许哪些html标记在摘要中显示。
Is WP CN Excerpt Safe to Use in 2026?
Generally Safe
Score 85/100WP CN Excerpt has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cn-excerpt" v4.4.1 plugin exhibits a mixed security posture. On the positive side, it shows no known vulnerabilities (CVEs) and has a minimal attack surface with zero identified entry points like AJAX handlers, REST API routes, or shortcodes. Furthermore, all SQL queries are secured using prepared statements, and nonce checks are present, indicating good development practices in these areas.
However, a significant concern arises from the static analysis of its code. A striking 0% of output is properly escaped, meaning that user-supplied data, if it were to enter the plugin's processing, could potentially be rendered directly into the HTML, leading to cross-site scripting (XSS) vulnerabilities. The taint analysis, while limited in scope, also identified two flows with unsanitized paths, suggesting potential avenues for malicious input to be processed without adequate cleaning. The absence of capability checks on any potential entry points, though the attack surface is currently zero, leaves room for future expansion to be insecure if not handled properly.
In conclusion, while the plugin's current lack of CVEs and small attack surface are strengths, the severe lack of output escaping and the presence of unsanitized taint flows are critical weaknesses that expose users to XSS risks. The plugin's vulnerability history being clean might be due to its limited functionality or perhaps due to the fact that the critical code flaws have not yet been exploited or discovered.
Key Concerns
- 0% of outputs properly escaped
- 2 flows with unsanitized paths
- No capability checks on entry points
WP CN Excerpt Security Vulnerabilities
WP CN Excerpt Release Timeline
WP CN Excerpt Code Analysis
Output Escaping
Data Flow Analysis
WP CN Excerpt Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP CN Excerpt Maintenance & Trust
Maintenance Signals
Community Trust
WP CN Excerpt Alternatives
WP-Chinese-Excerpt
wp-chinese-excerpt
Install this plugin,You can show a excerpt on your weblog homepage,You can omit the "more" tags.
Advanced Excerpt
advanced-excerpt
Control the appearance of WordPress post excerpts
Toggle wpautop
toggle-wpautop
Easily disable the default wpautop filter on a post by post basis.
Easy Custom Auto Excerpt
easy-custom-auto-excerpt
Auto Excerpt for your posts on home, search and archive pages. Customize Read More button and thumbnail image. Easy to configure and have a lot of opt …
Page Excerpt
page-excerpt
This plugin adds the same functionality of the excerpt feature in posts to pages.
WP CN Excerpt Developer Profile
4 plugins · 130 total installs
How We Detect WP CN Excerpt
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cn-excerpt/wp-cn-excerpt.js/wp-content/plugins/cn-excerpt/wp-cn-excerpt.jsHTML / DOM Fingerprints
read-more