
QQ 微信 微博 抖音登陆 Security & Risk Analysis
wordpress.org/plugins/mark-social-sso第一个版本没有做用户绑定功能!用户用不同的社交媒体登陆之后,会自动的为用户创建一个新用户并登陆。 新创建的用户仅用最基本的订阅者权限。
Is QQ 微信 微博 抖音登陆 Safe to Use in 2026?
Generally Safe
Score 85/100QQ 微信 微博 抖音登陆 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'mark-social-sso' plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any detected vulnerabilities in its history, coupled with a clean taint analysis, suggests a well-developed and tested codebase. The code signals also indicate good practices, with all SQL queries using prepared statements and a high percentage of output properly escaped. The limited attack surface with no unprotected entry points is a significant positive. However, there are a couple of areas that warrant attention. The plugin performs external HTTP requests, which can introduce risks if not handled securely, especially if the target of these requests is not fully trusted or if data is not validated upon return. Additionally, the absence of capability checks on any potential entry points (though the attack surface is zero here) is a theoretical concern that could become a risk if the plugin evolves and new entry points are introduced without proper authorization checks. Overall, the plugin appears secure for its current version, but attention to external interactions and a proactive approach to authorization checks would further enhance its robustness.
Key Concerns
- External HTTP requests without clear validation context
- No capability checks present
QQ 微信 微博 抖音登陆 Security Vulnerabilities
QQ 微信 微博 抖音登陆 Code Analysis
SQL Query Safety
Output Escaping
QQ 微信 微博 抖音登陆 Attack Surface
WordPress Hooks 5
Maintenance & Trust
QQ 微信 微博 抖音登陆 Maintenance & Trust
Maintenance Signals
Community Trust
QQ 微信 微博 抖音登陆 Alternatives
i7avatar 头像服务插件
i7avatar
这是一个基于“i7avatar 头像服务”的插件,安装并启用此插件后,就能在您的博客中使用更优秀的头像服务了。
QQ Weibo Plugin for WordPress
qq-weibo-plugin-for-wordpress
A very simple plugin shows the recent tweets from your QQ Weibo.
微博同步工具
qqpress
支持将新日志标题和链接同步到腾讯微博,同时支持自定义文章内容预览长度。
胖鼠采集(Fat Rat Collect)
fat-rat-collect
胖鼠采集(Fat Rat Collect) 是一款能够帮助你网站自动化的采集工具. 支持采集、微信、简书、知乎、自定义列表页、自定义详情页面、还有许多特色功能、 还可一键采集历史文章, 一键设置自动采集, 自动发布, 为您节省精力, 快来体验一下吧!
Online Contact Widget-多合一在线客服插件
online-contact-widget
Online Contact Widget(多合一在线客服插件),旨在为WordPress网站提供一系列可配置在线客服支持,包括QQ、微信(微信号、公众号和小程序QR-code)、电话、Email和工单等。
QQ 微信 微博 抖音登陆 Developer Profile
2 plugins · 20 total installs
How We Detect QQ 微信 微博 抖音登陆
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mark-social-sso/mksso.cssmark-social-sso/mksso.css?ver=HTML / DOM Fingerprints
sso-itemssso-itemsso-weixinsso-qqsso-weibosso-douyindata-nonce<div class="sso-items"><div class="sso-item sso-weixin"><a href="">微信登陆</a></div><div class="sso-item sso-qq"><a href="