QQ 微信 微博 抖音登陆 Security & Risk Analysis

wordpress.org/plugins/mark-social-sso

第一个版本没有做用户绑定功能!用户用不同的社交媒体登陆之后,会自动的为用户创建一个新用户并登陆。 新创建的用户仅用最基本的订阅者权限。

10 active installs v1.0.0 PHP 5.6+ WP 4.7+ Updated Aug 3, 2019
qq%e5%be%ae%e5%8d%9a%e5%be%ae%e4%bf%a1%e6%8a%96%e9%9f%b3%e4%b8%80%e9%94%ae%e7%99%bb%e9%99%86
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is QQ 微信 微博 抖音登陆 Safe to Use in 2026?

Generally Safe

Score 85/100

QQ 微信 微博 抖音登陆 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'mark-social-sso' plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any detected vulnerabilities in its history, coupled with a clean taint analysis, suggests a well-developed and tested codebase. The code signals also indicate good practices, with all SQL queries using prepared statements and a high percentage of output properly escaped. The limited attack surface with no unprotected entry points is a significant positive. However, there are a couple of areas that warrant attention. The plugin performs external HTTP requests, which can introduce risks if not handled securely, especially if the target of these requests is not fully trusted or if data is not validated upon return. Additionally, the absence of capability checks on any potential entry points (though the attack surface is zero here) is a theoretical concern that could become a risk if the plugin evolves and new entry points are introduced without proper authorization checks. Overall, the plugin appears secure for its current version, but attention to external interactions and a proactive approach to authorization checks would further enhance its robustness.

Key Concerns

  • External HTTP requests without clear validation context
  • No capability checks present
Vulnerabilities
None known

QQ 微信 微博 抖音登陆 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

QQ 微信 微博 抖音登陆 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
3
19 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

86% escaped22 total outputs
Attack Surface

QQ 微信 微博 抖音登陆 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuadmin\settings.php:5
actionadmin_initadmin\settings.php:81
actionlogin_enqueue_scriptssso.php:30
actionparse_requestsso.php:37
actionlogin_formsso.php:101
Maintenance & Trust

QQ 微信 微博 抖音登陆 Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedAug 3, 2019
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

QQ 微信 微博 抖音登陆 Developer Profile

markchenlife

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect QQ 微信 微博 抖音登陆

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mark-social-sso/mksso.css
Version Parameters
mark-social-sso/mksso.css?ver=

HTML / DOM Fingerprints

CSS Classes
sso-itemssso-itemsso-weixinsso-qqsso-weibosso-douyin
Data Attributes
data-nonce
Shortcode Output
<div class="sso-items"><div class="sso-item sso-weixin"><a href="">微信登陆</a></div><div class="sso-item sso-qq"><a href="
FAQ

Frequently Asked Questions about QQ 微信 微博 抖音登陆