
DX-Contribute Security & Risk Analysis
wordpress.org/plugins/dx-contributeThe shortcut Submission wordpress plugin. 快捷投稿插件
Is DX-Contribute Safe to Use in 2026?
Generally Safe
Score 85/100DX-Contribute has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dx-contribute" plugin v1.4.0 exhibits a mixed security posture. While it has a very small attack surface and no recorded vulnerability history, several code signals raise concerns. The complete lack of nonce checks and capability checks is a significant weakness, especially given that it has an entry point via a shortcode. Although there are no directly exploitable critical or high-severity taint flows identified in the static analysis, the presence of unsanitized paths in taint analysis suggests potential for more subtle vulnerabilities that could be triggered through user input. Furthermore, the extremely low percentage of properly escaped output is a major concern, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-controlled data is likely being rendered without adequate sanitization. The absence of dangerous functions and the use of prepared statements for SQL queries are positive indicators, but they do not mitigate the risks posed by missing authorization and output escaping.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Low percentage of properly escaped output
- Unsanitized paths in taint analysis
DX-Contribute Security Vulnerabilities
DX-Contribute Code Analysis
Output Escaping
Data Flow Analysis
DX-Contribute Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
DX-Contribute Maintenance & Trust
Maintenance Signals
Community Trust
DX-Contribute Alternatives
No alternatives data available yet.
DX-Contribute Developer Profile
3 plugins · 320 total installs
How We Detect DX-Contribute
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dx-contribute/icon.pngHTML / DOM Fingerprints
daxiawp-contactDXC-inputDXC-exclude-catid="contribute-metadata"id="contribute-site"name="DXC-title-num"name="DXC-textarea-num"name="DXC-textarea-rows"name="DXC-category"+9 moreDX_Contribute<div class="daxiawp-contact"><div id="contribute-metadata"><div id="contribute-site">