
Traffic/Crawler网站蜘蛛/访客记录 Security & Risk Analysis
wordpress.org/plugins/key-spider网站蜘蛛/访客记录,主要包含了各大搜索引擎的蜘蛛访问记录,以及网站的访问流量进行监控。
Is Traffic/Crawler网站蜘蛛/访客记录 Safe to Use in 2026?
Generally Safe
Score 100/100Traffic/Crawler网站蜘蛛/访客记录 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "key-spider" plugin version 1.0.9 exhibits a generally good security posture with several strengths, including a lack of known vulnerabilities in its history and the absence of dangerous functions. The majority of its SQL queries utilize prepared statements, which is a strong defense against SQL injection. Furthermore, all identified AJAX entry points appear to have authentication checks, and there are no shortcodes, reducing potential attack vectors. However, some areas warrant attention. The static analysis reveals a significant number of AJAX handlers (25), and while they are reported as protected, a single unsanitized path identified in the taint analysis flow is a critical concern that could lead to vulnerabilities if exploited. Additionally, the output escaping is only 60% properly implemented, indicating a potential risk of cross-site scripting (XSS) vulnerabilities in the remaining 40% of outputs. The lack of any recorded capability checks is also a notable weakness, suggesting that privileged actions might not be adequately restricted.
Key Concerns
- Taint flow with unsanitized path (critical)
- Output escaping only 60% proper
- No capability checks
Traffic/Crawler网站蜘蛛/访客记录 Security Vulnerabilities
Traffic/Crawler网站蜘蛛/访客记录 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Traffic/Crawler网站蜘蛛/访客记录 Attack Surface
AJAX Handlers 25
WordPress Hooks 10
Scheduled Events 2
Maintenance & Trust
Traffic/Crawler网站蜘蛛/访客记录 Maintenance & Trust
Maintenance Signals
Community Trust
Traffic/Crawler网站蜘蛛/访客记录 Alternatives
No alternatives data available yet.
Traffic/Crawler网站蜘蛛/访客记录 Developer Profile
8 plugins · 1K total installs
How We Detect Traffic/Crawler网站蜘蛛/访客记录
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/key-spider/assets/css/backend.css/wp-content/plugins/key-spider/assets/css/frontend.css/wp-content/plugins/key-spider/assets/js/backend.js/wp-content/plugins/key-spider/assets/js/frontend.js/wp-content/plugins/key-spider/assets/js/backend.js/wp-content/plugins/key-spider/assets/js/frontend.jskey-spider/assets/css/backend.css?ver=key-spider/assets/css/frontend.css?ver=key-spider/assets/js/backend.js?ver=key-spider/assets/js/frontend.js?ver=HTML / DOM Fingerprints
keyspider-admin-pagekeyspider-liuliang-log-tablekeyspider-seo-pagekeyspider-zhizhu-log-tabledata-keyspider-noncekey_spider_ajax_object/wp-json/keyspider/v1/logs/wp-json/keyspider/v1/settings[key_spider_display_logs][key_spider_visitor_map][key_spider_traffic_stats]