QQ旺旺客服 Security & Risk Analysis

wordpress.org/plugins/qq-kefu

This pulgin can add the Customer Service QQ or TaobaoWangwang.

60 active installs v1.7.6 PHP + WP 2.0.2+ Updated Jun 19, 2013
customer-serviceqqtaobao%e6%97%ba%e6%97%ba
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is QQ旺旺客服 Safe to Use in 2026?

Generally Safe

Score 85/100

QQ旺旺客服 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "qq-kefu" plugin v1.7.6 demonstrates a mixed security posture. On the positive side, the plugin has no known vulnerabilities (CVEs) and no recorded history of security issues, suggesting a potentially well-maintained codebase. The static analysis also indicates no direct use of dangerous functions, no raw SQL queries, and no file operations or external HTTP requests, which are generally good security practices.

However, significant concerns arise from the lack of output escaping. With 100% of its total outputs not being properly escaped, this presents a high risk of cross-site scripting (XSS) vulnerabilities. Any data rendered by the plugin that originates from user input or external sources could be maliciously manipulated and executed in a victim's browser. Furthermore, the absence of nonce checks and capability checks on its single shortcode entry point is a notable weakness, as it could allow unauthorized users to trigger plugin functionality.

Given the lack of known CVEs and the absence of critical taint analysis findings, the plugin avoids major systemic security flaws. However, the unescaped outputs and missing authorization checks on its entry point are critical areas that need immediate attention to prevent potentially severe security breaches, particularly XSS.

Key Concerns

  • Output escaping is not implemented
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

QQ旺旺客服 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

QQ旺旺客服 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

QQ旺旺客服 Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[qqkefu] qq-kefu-in.php:951
WordPress Hooks 2
actionadmin_menuqq-kefu-in.php:935
actionget_footerqq-kefu-in.php:973
Maintenance & Trust

QQ旺旺客服 Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJun 19, 2013
PHP min version
Downloads23K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

QQ旺旺客服 Developer Profile

bxl0103

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect QQ旺旺客服

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/qq-kefu/qqkefu.css
Script Paths
http://lib.sinaapp.com/js/jquery/1.7/jquery.min.js
Version Parameters
qq-kefu/qqkefu.css?ver=

HTML / DOM Fingerprints

CSS Classes
qqkefu_sectionrm_titlerm_options
Data Attributes
id="qqAdmin"name="enable"name="enbleNavlog"name="enableIndex"name="enableSingle"name="enableBigIcoShowTxt"+13 more
JS Globals
jQuery
FAQ

Frequently Asked Questions about QQ旺旺客服