
多说社会化评论框 Security & Risk Analysis
wordpress.org/plugins/duoshuo追求最佳用户体验的社会化评论框,为中小网站提供新浪微博、QQ、人人、开心、豆瓣等多帐号登录并评论功能。
Is 多说社会化评论框 Safe to Use in 2026?
High Risk
Score 42/100多说社会化评论框 carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The duoshuo v1.2 plugin presents a significant security risk due to several critical weaknesses. While the plugin does not utilize dangerous functions or make external HTTP requests, its static analysis reveals a concerning lack of security checks on its entry points. Specifically, both of the identified AJAX handlers lack authentication checks, creating a wide attack surface that could be exploited by unauthenticated users. Furthermore, the plugin exhibits poor output escaping practices, with only 26% of outputs being properly escaped, which can lead to cross-site scripting vulnerabilities. The vulnerability history further exacerbates these concerns, with two known unpatched medium severity CVEs, both related to Cross-Site Request Forgery and Cross-Site Scripting. These recurring vulnerability types suggest a pattern of insecure coding practices related to input handling and user interaction. While the presence of capability checks and prepared statements for SQL queries are positive signs, they are overshadowed by the critical flaws in authentication and output sanitization, alongside the unpatched vulnerabilities, leading to an overall poor security posture.
Key Concerns
- AJAX handlers without authentication checks
- High number of flows with unsanitized paths
- Low percentage of properly escaped outputs
- Two unpatched medium severity CVEs
- No nonce checks on entry points
多说社会化评论框 Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
多说社会化评论框 <= 1.2 - Cross-Site Request Forgery to Settings Update
多说社会化评论框 <= 1.2 - Reflected Cross-Site Scripting
多说社会化评论框 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
多说社会化评论框 Attack Surface
AJAX Handlers 2
WordPress Hooks 37
Scheduled Events 1
Maintenance & Trust
多说社会化评论框 Maintenance & Trust
Maintenance Signals
Community Trust
多说社会化评论框 Alternatives
Social Share, Social Login and Social Comments Plugin – Super Socializer
super-socializer
The unique Social Plugin to let you integrate Social Login, Social Share, Social Comments and Social Media follow at your website
FoxyBookmark
foxy-bookmark
For content by the visitor in social networks
Social Monster
social-features-for-wp
This plugin adds some social functionality to Wordpress. Such as FB comments, VK comments, share buttons etc.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
多说社会化评论框 Developer Profile
1 plugin · 70 total installs
How We Detect 多说社会化评论框
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/duoshuo/script.js/wp-content/plugins/duoshuo/comments.js/wp-content/plugins/duoshuo/admin.js/wp-content/plugins/duoshuo/images/menu-icon.png/wp-content/plugins/duoshuo/widgets.php/wp-content/plugins/duoshuo/script.js/wp-content/plugins/duoshuo/comments.js/wp-content/plugins/duoshuo/admin.jsHTML / DOM Fingerprints
ds-threadds-inline-feedds-meta<!-- 多说评论 start --><!-- 多说评论 end --><!-- 多说登录 start --><!-- 多说登录 end -->data-thread-keydata-urldata-titledata-slugdata-categorydata-author-key+3 moreDUOSHUOduoshuo