
QQ旺旺客服 Security & Risk Analysis
wordpress.org/plugins/qq-kefuThis pulgin can add the Customer Service QQ or TaobaoWangwang.
Is QQ旺旺客服 Safe to Use in 2026?
Generally Safe
Score 85/100QQ旺旺客服 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "qq-kefu" plugin v1.7.6 demonstrates a mixed security posture. On the positive side, the plugin has no known vulnerabilities (CVEs) and no recorded history of security issues, suggesting a potentially well-maintained codebase. The static analysis also indicates no direct use of dangerous functions, no raw SQL queries, and no file operations or external HTTP requests, which are generally good security practices.
However, significant concerns arise from the lack of output escaping. With 100% of its total outputs not being properly escaped, this presents a high risk of cross-site scripting (XSS) vulnerabilities. Any data rendered by the plugin that originates from user input or external sources could be maliciously manipulated and executed in a victim's browser. Furthermore, the absence of nonce checks and capability checks on its single shortcode entry point is a notable weakness, as it could allow unauthorized users to trigger plugin functionality.
Given the lack of known CVEs and the absence of critical taint analysis findings, the plugin avoids major systemic security flaws. However, the unescaped outputs and missing authorization checks on its entry point are critical areas that need immediate attention to prevent potentially severe security breaches, particularly XSS.
Key Concerns
- Output escaping is not implemented
- No capability checks on entry points
- No nonce checks on entry points
QQ旺旺客服 Security Vulnerabilities
QQ旺旺客服 Code Analysis
Output Escaping
QQ旺旺客服 Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
QQ旺旺客服 Maintenance & Trust
Maintenance Signals
Community Trust
QQ旺旺客服 Alternatives
QQ旺旺Skype微信电话二维码客服WordPress插件 5usujian super serv
5usujian-super-serv
在网站侧边添加优美的电话、QQ、旺旺客服悬浮窗
Online Contact Widget-多合一在线客服插件
online-contact-widget
Online Contact Widget(多合一在线客服插件),旨在为WordPress网站提供一系列可配置在线客服支持,包括QQ、微信(微信号、公众号和小程序QR-code)、电话、Email和工单等。
n8n Chat Widget
n8n-chat-widget
Adds a customizable n8n chat widget to your website frontend. It allows visitors to interact with n8n chat workflows directly from your website throug …
Chat Floating Button BY XD
chat-floating-button-by-xd
Floating button for chatting with your visitors via WhatsApp.
ChinaDS – Tmall-Taobao Dropshipping for WooCommerce
chinads-dropshipping-taobao-woocommerce
Transfer data from Taobao products to WooCommerce effortlessly.
QQ旺旺客服 Developer Profile
1 plugin · 60 total installs
How We Detect QQ旺旺客服
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qq-kefu/qqkefu.csshttp://lib.sinaapp.com/js/jquery/1.7/jquery.min.jsqq-kefu/qqkefu.css?ver=HTML / DOM Fingerprints
qqkefu_sectionrm_titlerm_optionsid="qqAdmin"name="enable"name="enbleNavlog"name="enableIndex"name="enableSingle"name="enableBigIcoShowTxt"+13 morejQuery