ForumHub论坛/帖子/问答/社区/话题插件 Security & Risk Analysis

wordpress.org/plugins/luntan

主要功能是论坛/帖子/问答/社区/话题。包含登录、注册、邮箱系统、发布帖子、回复帖子、评论、点赞、踩、帖子分类、帖子审核、帖子管理(转移分类、删除帖子)等功能。

10 active installs v0.0.8 PHP 7.4+ WP 5.3+ Updated Unknown
%e7%a4%be%e5%8c%ba%e9%97%ae%e7%ad%94%e8%ae%ba%e5%9d%9b%e8%af%9d%e9%a2%98%e5%b8%96%e5%ad%90
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ForumHub论坛/帖子/问答/社区/话题插件 Safe to Use in 2026?

Generally Safe

Score 100/100

ForumHub论坛/帖子/问答/社区/话题插件 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "luntan" plugin v0.0.8 exhibits a generally strong security posture based on the provided static analysis. The plugin has a significant attack surface with 39 AJAX handlers, but the absence of unprotected entry points is a positive indicator, suggesting that most, if not all, of these handlers have implemented authentication checks. The code signals also show good practices, with a high percentage of SQL queries using prepared statements (89%) and a considerable number of outputs being properly escaped (81%). The presence of 32 nonce checks and 16 capability checks further reinforces the attempt to secure these entry points.

However, a few areas warrant attention. The plugin makes 7 external HTTP requests, which can introduce risks if the target servers are compromised or if data transmitted is not handled securely. While no critical or high-severity taint flows were identified, the analysis of only 7 total flows might not be exhaustive, and it's always prudent to consider the potential for unforeseen vulnerabilities in complex interactions. The plugin's vulnerability history is completely clean, with no recorded CVEs. This, combined with the relatively good code hygiene observed, suggests a low risk of known exploits.

In conclusion, "luntan" v0.0.8 appears to be a well-developed plugin from a security perspective, with a strong emphasis on input validation and output sanitization. The main areas of potential concern are the external HTTP requests and the possibility of undiscovered vulnerabilities within the analyzed taint flows. Nevertheless, its lack of historical vulnerabilities and good implementation of common security practices provide a good foundation.

Key Concerns

  • External HTTP requests detected
Vulnerabilities
None known

ForumHub论坛/帖子/问答/社区/话题插件 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ForumHub论坛/帖子/问答/社区/话题插件 Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
47 prepared
Unescaped Output
123
536 escaped
Nonce Checks
32
Capability Checks
16
File Operations
0
External Requests
7
Bundled Libraries
0

SQL Query Safety

89% prepared53 total queries

Output Escaping

81% escaped659 total outputs
Data Flows
All sanitized

Data Flow Analysis

7 flows
luntan_xieyi (inc\post.php:98)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ForumHub论坛/帖子/问答/社区/话题插件 Attack Surface

Entry Points39
Unprotected0

AJAX Handlers 39

authwp_ajax_luntan_avatarinc\post.php:5
noprivwp_ajax_luntan_sendemailinc\post.php:6
authwp_ajax_luntan_sendemailinc\post.php:7
authwp_ajax_luntan_get_userinc\post.php:8
noprivwp_ajax_luntan_get_userinc\post.php:9
authwp_ajax_luntan_get_postinc\post.php:10
authwp_ajax_luntan_delete_postinc\post.php:11
authwp_ajax_luntan_add_cateinc\post.php:12
authwp_ajax_luntan_update_cateinc\post.php:13
authwp_ajax_luntan_delete_cateinc\post.php:14
authwp_ajax_luntan_zhuanyi_cateinc\post.php:15
authwp_ajax_luntan_get_cateinc\post.php:16
authwp_ajax_luntan_manage_postinc\post.php:17
authwp_ajax_luntan_shenhe_postinc\post.php:18
authwp_ajax_luntan_zhuanyi_postinc\post.php:19
noprivwp_ajax_luntan_cate_listinc\post.php:21
authwp_ajax_luntan_cate_listinc\post.php:22
noprivwp_ajax_luntan_post_listinc\post.php:23
authwp_ajax_luntan_post_listinc\post.php:24
noprivwp_ajax_luntan_post_detailinc\post.php:25
authwp_ajax_luntan_post_detailinc\post.php:26
authwp_ajax_luntan_post_imginc\post.php:28
authwp_ajax_luntan_comment_likeinc\post.php:30
noprivwp_ajax_luntan_comment_likeinc\post.php:31
authwp_ajax_luntan_delete_plinc\post.php:32
authwp_ajax_luntan_post_publishinc\post.php:34
authwp_ajax_luntan_post_plinc\post.php:36
authwp_ajax_luntan_post_editinc\post.php:38
authwp_ajax_luntan_smtp_baocuninc\post.php:39
authwp_ajax_luntan_get_smtp_baocuninc\post.php:40
authwp_ajax_luntan_smtp_baocun_csinc\post.php:41
authwp_ajax_luntan_post_topinc\post.php:43
authwp_ajax_luntan_get_vipinc\post.php:45
authwp_ajax_luntan_vipinc\post.php:46
authwp_ajax_luntan_xieyiinc\post.php:48
authwp_ajax_luntan_get_xieyiinc\post.php:50
noprivwp_ajax_luntan_get_xieyiinc\post.php:51
authwp_ajax_luntan_url_guanliinc\post.php:53
authwp_ajax_luntan_get_url_guanliinc\post.php:55
WordPress Hooks 22
actionadmin_menuinc\index.php:7
actionadmin_enqueue_scriptsinc\index.php:8
actioninitinc\index.php:10
actiontemplate_includeinc\index.php:11
actionwp_enqueue_scriptsinc\index.php:12
actionwp_logoutinc\index.php:13
filterluntan_dhdfkdksjinc\index.php:17
filterluntan_dssddinc\index.php:18
filterlogin_redirectinc\index.php:21
actionadmin_initinc\index.php:22
filtersanitize_userinc\index.php:23
filterregistration_errorsinc\index.php:24
filteruser_registration_errorsinc\index.php:25
filterscript_loader_taginc\index.php:422
filterscript_loader_taginc\index.php:504
actionphpmailer_initinc\post.php:42
actioninitluntan.php:24
filtertemplate_includeluntan.php:102
actionwp_enqueue_scriptsluntan.php:103
filterblock_template_directoriesluntan.php:136
actionlogin_enqueue_scriptsluntan.php:166
filterwp_new_user_notification_emailluntan.php:175
Maintenance & Trust

ForumHub论坛/帖子/问答/社区/话题插件 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads767

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ForumHub论坛/帖子/问答/社区/话题插件 Developer Profile

沃之涛

8 plugins · 1K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
98 days
View full developer profile
Detection Fingerprints

How We Detect ForumHub论坛/帖子/问答/社区/话题插件

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/luntan/wztTheme.css/wp-content/plugins/luntan/wztTheme.js
Script Paths
/wp-content/plugins/luntan/wztTheme.js
Version Parameters
ver=0.0.8

HTML / DOM Fingerprints

JS Globals
wp_vars
FAQ

Frequently Asked Questions about ForumHub论坛/帖子/问答/社区/话题插件