Push Message To WeChat Security & Risk Analysis

wordpress.org/plugins/push-message-to-wechat

基于PushBear服务提供WordPress内容更新微信订阅推送的插件

0 active installs v2.0.0 PHP 5.6.0+ WP 4.2+ Updated Mar 7, 2020
messagepushpushbearsubscribe
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Push Message To WeChat Safe to Use in 2026?

Generally Safe

Score 85/100

Push Message To WeChat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "push-message-to-wechat" plugin version 2.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly minimizes the plugin's attack surface. Furthermore, the analysis shows no critical or high-severity taint flows, no dangerous functions, and a complete absence of direct SQL queries, relying entirely on prepared statements. This indicates robust coding practices for data handling and database interaction.

However, a notable concern arises from the output escaping analysis, where only 38% of total outputs are properly escaped. This percentage is a significant weakness, as improperly escaped output can lead to Cross-Site Scripting (XSS) vulnerabilities. While the plugin demonstrates good practices in other areas, this deficiency leaves the door open for attackers to inject malicious scripts through user-generated or plugin-generated content that is displayed to other users without proper sanitization. The vulnerability history being clean is positive, but it does not negate the risks identified in the current code analysis.

In conclusion, while the plugin has a very small attack surface and generally employs secure coding for critical functions like SQL queries, the low rate of proper output escaping presents a tangible risk. The strength lies in the limited entry points and absence of critical code vulnerabilities. The weakness lies specifically in the insufficient output escaping, which requires immediate attention to prevent potential XSS attacks. Addressing the output escaping issue should be the priority for improving the plugin's overall security.

Key Concerns

  • Insufficient output escaping (38%)
Vulnerabilities
None known

Push Message To WeChat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Push Message To WeChat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
6 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped16 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
pmtw_submit_options (push-message-to-wechat.php:345)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Push Message To WeChat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitpush-message-to-wechat.php:12
actionsave_postpush-message-to-wechat.php:16
filtermanage_post_posts_columnspush-message-to-wechat.php:17
actionmanage_posts_custom_columnpush-message-to-wechat.php:18
actionadmin_noticespush-message-to-wechat.php:154
actionadmin_menupush-message-to-wechat.php:220
actionadmin_menupush-message-to-wechat.php:234
actionpost_submitbox_misc_actionspush-message-to-wechat.php:237
actionadmin_initpush-message-to-wechat.php:299
filterplugin_action_linkspush-message-to-wechat.php:319
Maintenance & Trust

Push Message To WeChat Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedMar 7, 2020
PHP min version5.6.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Push Message To WeChat Developer Profile

沈唁

13 plugins · 4K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
143 days
View full developer profile
Detection Fingerprints

How We Detect Push Message To WeChat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
notice-successnotice-erroris-dismissible
FAQ

Frequently Asked Questions about Push Message To WeChat