淘宝客(官方接口) Security & Risk Analysis

wordpress.org/plugins/nines-taoke

功能一:在一个新的页面中显示淘客商品(高额优惠券);

10 active installs v2.8.2 PHP + WP 4.8+ Updated Jul 2, 2022
%e8%81%9a%e5%88%92%e7%ae%97%e6%b7%98%e5%ae%9d%e6%b7%98%e5%ae%9d%e5%ae%a2%e6%b7%98%e5%ae%a2%e4%bc%98%e6%83%a0%e5%88%b8
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 淘宝客(官方接口) Safe to Use in 2026?

Generally Safe

Score 85/100

淘宝客(官方接口) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "nines-taoke" plugin v2.8.2 exhibits a generally good security posture, with no known vulnerabilities in its history and a strong emphasis on security best practices within its code. The absence of dangerous functions, file operations, and external HTTP requests is positive. Furthermore, all SQL queries are prepared, and a significant portion of output is properly escaped, indicating a conscious effort to prevent common web vulnerabilities. The plugin also implements nonce and capability checks on its AJAX handlers, limiting the attack surface.

However, the static analysis did reveal three flows with unsanitized paths. While not classified as critical or high severity, these represent potential entry points for malicious data manipulation if not handled carefully. The lack of REST API routes and shortcodes simplifies the attack surface, which is beneficial. The plugin's clean vulnerability history is a strong indicator of its past security diligence, suggesting a commitment to maintaining a secure codebase.

In conclusion, "nines-taoke" v2.8.2 is a relatively secure plugin, primarily due to its proactive security measures and lack of historical vulnerabilities. The primary area of concern lies in the identified unsanitized paths, which, while not currently leading to severe issues, warrant attention to ensure robust input validation and sanitization to prevent future potential exploits.

Key Concerns

  • Flows with unsanitized paths
Vulnerabilities
None known

淘宝客(官方接口) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

淘宝客(官方接口) Release Timeline

v2.7
Code Analysis
Analyzed Apr 16, 2026

淘宝客(官方接口) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
216
630 escaped
Nonce Checks
6
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

74% escaped846 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

6 flows3 with unsanitized paths
show (inc/page.php:23)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

淘宝客(官方接口) Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_csf-get-iconsinc/functions/actions.php:50
authwp_ajax_csf-exportinc/functions/actions.php:87
authwp_ajax_csf-importinc/functions/actions.php:123
authwp_ajax_csf-resetinc/functions/actions.php:150
authwp_ajax_csf-choseninc/functions/actions.php:189
WordPress Hooks 17
filtertemplate_includeNinesTaoKe.php:318
actionwp_enqueue_scriptsinc/classes/abstract.class.php:20
actionadmin_menuinc/classes/admin-options.class.php:111
actionadmin_bar_menuinc/classes/admin-options.class.php:112
actionnetwork_admin_menuinc/classes/admin-options.class.php:116
filteradmin_footer_textinc/classes/admin-options.class.php:481
actionafter_setup_themeinc/classes/setup.class.php:74
actioninitinc/classes/setup.class.php:75
actionswitch_themeinc/classes/setup.class.php:76
actionadmin_enqueue_scriptsinc/classes/setup.class.php:77
actionwp_enqueue_scriptsinc/classes/setup.class.php:78
actionwp_headinc/classes/setup.class.php:79
filteradmin_body_classinc/classes/setup.class.php:80
actionadmin_footerinc/fields/icon/icon.php:46
actioncustomize_controls_print_footer_scriptsinc/fields/icon/icon.php:47
actionadmin_print_footer_scriptsinc/fields/link/link.php:70
actionprint_default_editor_scriptsinc/fields/wp_editor/wp_editor.php:62
Maintenance & Trust

淘宝客(官方接口) Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 2, 2022
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Alternatives

淘宝客(官方接口) Alternatives

Developer Profile

淘宝客(官方接口) Developer Profile

不问归期_

3 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 淘宝客(官方接口)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nines-taoke/assets/css/style.css/wp-content/plugins/nines-taoke/assets/js/global.js/wp-content/plugins/nines-taoke/assets/js/app.js
Script Paths
/wp-content/plugins/nines-taoke/assets/js/global.js/wp-content/plugins/nines-taoke/assets/js/app.js
Version Parameters
nines-taoke/assets/css/style.css?ver=nines-taoke/assets/js/global.js?ver=nines-taoke/assets/js/app.js?ver=

HTML / DOM Fingerprints

CSS Classes
tbk_pagetbk_search_formtbk_item_listtbk_itemtbk_item_imagetbk_item_titletbk_item_pricetbk_item_coupon_price+3 more
HTML Comments
<!-- tbk_page_header --><!-- tbk_search_results --><!-- tbk_item_template --><!-- tbk_page_footer -->
Data Attributes
data-tbk-product-iddata-tbk-keyworddata-tbk-pagedata-tbk-page-size
JS Globals
window.ninesTbkConfigvar tbk_search_params
REST Endpoints
/wp-json/nines-taoke/v1/search/wp-json/nines-taoke/v1/suggestions
Shortcode Output
[nines_taoke_search][nines_taoke_products][nines_taoke_recommendations]
FAQ

Frequently Asked Questions about 淘宝客(官方接口)