BaiduXZH Submit(百度熊掌号) Security & Risk Analysis

wordpress.org/plugins/i3geek-baiduxzh

I3geek Baidu Xiongzhang Submit. 百度熊掌号(原百家号、百度站长平台)链接提交,原创保护内容提交,自动提交最新文章以保证24小时内可被百度收录,提高站点SEO

70 active installs v1.4.6 PHP 5.2.4+ WP 4.0.1+ Updated Dec 30, 2018
baidu%e7%99%be%e5%ba%a6linksubmitseositemap
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEAug 7, 2025
Safety Verdict

Is BaiduXZH Submit(百度熊掌号) Safe to Use in 2026?

Use With Caution

Score 63/100

BaiduXZH Submit(百度熊掌号) has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Aug 7, 2025Updated 7yr ago
Risk Assessment

The i3geek-baiduxzh plugin v1.4.6 exhibits a mixed security posture. On the positive side, the static analysis shows a complete absence of known dangerous functions, all SQL queries are properly prepared, and there's a single nonce check present. This suggests some adherence to secure coding practices.

However, several concerns arise from the analysis. The taint analysis revealed one flow with an unsanitized path, which is a significant risk as it indicates potential for vulnerabilities like local file inclusion or path traversal if not handled carefully. Furthermore, only 33% of output is properly escaped, leaving a considerable portion vulnerable to Cross-Site Scripting (XSS) attacks. The presence of file operations and external HTTP requests also increases the attack surface, especially if not implemented with strict input validation.

The vulnerability history is a major red flag. With one known medium severity CVE that remains unpatched, and the common vulnerability type being XSS, this indicates a recurring weakness in how the plugin handles user input and generates output. The fact that the last vulnerability was in the future (2025-08-07) is concerning and suggests potential data inaccuracies or future exploitability. The absence of capability checks is also a significant oversight, leaving many functionalities potentially accessible without proper authorization.

Key Concerns

  • Unpatched medium severity CVE
  • Flow with unsanitized path
  • Low output escaping percentage (33%)
  • Missing capability checks
  • File operations present
  • External HTTP requests present
Vulnerabilities
1

BaiduXZH Submit(百度熊掌号) Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49063medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaiduXZH Submit(百度熊掌号) <= 1.4.6 - Reflected Cross-Site Scripting

Aug 7, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

BaiduXZH Submit(百度熊掌号) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
8 escaped
Nonce Checks
1
Capability Checks
0
File Operations
3
External Requests
3
Bundled Libraries
0

Output Escaping

33% escaped24 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<i3geek_baiduXZH_html> (i3geek_baiduXZH_html.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BaiduXZH Submit(百度熊掌号) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_initi3geek_baiduXZH.php:14
actionplugins_loadedi3geek_baiduXZH.php:15
actiondo_meta_boxesi3geek_baiduXZH.php:19
actionadmin_enqueue_scriptsi3geek_baiduXZH.php:20
filterthe_contenti3geek_baiduXZH.php:44
filterplugin_action_linksi3geek_baiduXZH.php:128
actionadmin_menui3geek_baiduXZH.php:142
Maintenance & Trust

BaiduXZH Submit(百度熊掌号) Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 30, 2018
PHP min version5.2.4
Downloads20K

Community Trust

Rating46/100
Number of ratings3
Active installs70
Developer Profile

BaiduXZH Submit(百度熊掌号) Developer Profile

i3geek

2 plugins · 80 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BaiduXZH Submit(百度熊掌号)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/i3geek-baiduxzh/scripts/xzh.css/wp-content/plugins/i3geek-baiduxzh/scripts/xzh.js
Script Paths
/wp-content/plugins/i3geek-baiduxzh/scripts/xzh.js
Version Parameters
i3geek-baiduxzh/scripts/xzh.css?ver=i3geek-baiduxzh/scripts/xzh.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Page reform for Baidu by 爱上极客熊掌号 (i3geek.com) -->
Data Attributes
id="sd-i3geek-xzh"name="i3geek_xzh_submit_CHECK"id="original"name="original"id="i3geek_contentonclick="i3geek_xzh_submit(
FAQ

Frequently Asked Questions about BaiduXZH Submit(百度熊掌号)