
ICPBEIAN Security & Risk Analysis
wordpress.org/plugins/icpbeianAdds ICP information to your site footer with shortcode.
Is ICPBEIAN Safe to Use in 2026?
Generally Safe
Score 85/100ICPBEIAN has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "icpbeian" plugin v1.00.0 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests is highly positive. Furthermore, the use of prepared statements for all SQL queries and proper escaping for 80% of its outputs indicates a conscious effort towards secure coding practices. The plugin also has a clean vulnerability history, with no recorded CVEs, suggesting a lack of previously discovered exploitable flaws.
However, there are some areas for concern. The lack of nonce checks and capability checks, particularly when dealing with the single shortcode entry point, represents a potential weakness. While the attack surface is currently small, the absence of these critical security mechanisms means that any functionality exposed by the shortcode could be triggered without proper authorization or verification. Taint analysis also shows no flows, which is good, but this could also indicate limited analysis or that the plugin's functionality doesn't expose sensitive data in a way that the tools could detect.
In conclusion, "icpbeian" v1.00.0 has a solid foundation in terms of preventing common vulnerabilities like SQL injection and dangerous function usage. Its clean history is also reassuring. The primary risk lies in the potential for unauthorized execution of its shortcode functionality due to the missing nonce and capability checks. This, combined with the high percentage of properly escaped outputs (leaving room for potential unescaped data), warrants careful consideration.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
- Some output not properly escaped
ICPBEIAN Security Vulnerabilities
ICPBEIAN Release Timeline
ICPBEIAN Code Analysis
Output Escaping
ICPBEIAN Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
ICPBEIAN Maintenance & Trust
Maintenance Signals
Community Trust
ICPBEIAN Alternatives
WPICP License
wpicp-license
This plugin is free forever, and its purpose is to supplement the essential functions that the Chinese version of WordPress lacks.
Ad Invalid Click Protector (AICP)
ad-invalid-click-protector
One plugin to save your AdSense account from Click Bombings and Invalid Click Activities
VS Event List
very-simple-event-list
With this lightweight plugin you can create an event list.
VS Contact Form
very-simple-contact-form
With this lightweight plugin you can create a contact form.
VS Meta Description
very-simple-meta-description
With this lightweight plugin you can add a meta description to your website.
ICPBEIAN Developer Profile
1 plugin · 0 total installs
How We Detect ICPBEIAN
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
beianflagdata-label_forname="icpbeianID"id="icpbeianID"<a id="beianflag" class="beianflag" href="https://beian.miit.gov.cn/">