
QQ Weibo Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/qq-weibo-plugin-for-wordpressA very simple plugin shows the recent tweets from your QQ Weibo.
Is QQ Weibo Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100QQ Weibo Plugin for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "qq-weibo-plugin-for-wordpress" v1.1 plugin presents a mixed security posture. On one hand, the lack of known CVEs and a clean vulnerability history is a positive indicator, suggesting a relatively stable codebase concerning documented security flaws. The plugin also demonstrates good practices in SQL query handling, with 100% of queries using prepared statements, and no critical or high-severity taint flows found during static analysis. However, significant security concerns arise from the code signals. The presence of the `create_function` dangerous function, coupled with a very low percentage of properly escaped output (11%), indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the absence of nonce checks and capability checks on what appears to be an attack surface of 0 entry points, while seemingly safe, could become a critical weakness if any entry points were to be introduced or if existing file operations or external HTTP requests are not properly secured against unauthorized access or manipulation. The unsanitized paths in taint analysis also warrant attention, despite their classification as not critical or high. In conclusion, while the plugin avoids common documented vulnerabilities, its internal code quality and lack of robust authorization and input sanitization present substantial inherent risks.
Key Concerns
- Presence of dangerous function create_function
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
- Flows with unsanitized paths
QQ Weibo Plugin for WordPress Security Vulnerabilities
QQ Weibo Plugin for WordPress Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
QQ Weibo Plugin for WordPress Attack Surface
WordPress Hooks 3
Maintenance & Trust
QQ Weibo Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
QQ Weibo Plugin for WordPress Alternatives
微博同步工具
qqpress
支持将新日志标题和链接同步到腾讯微博,同时支持自定义文章内容预览长度。
Sina Weibo Plugin for WordPress
sina-weibo-plugin-for-wordpress
A very simple plugin shows the recent tweets from your Sina Weibo.
weibo2wp plugin
weibo2wp
The goal of this plugin is to help people Synchronize their Weibo( which is a very popular light blog in China) to WP
SNS Count Cache
sns-count-cache
This plugin gets and caches SNS counts in the background, and help you to shorten page loading time through the use of cache mechanism.
Saitama Addon Pack
cc-addon-pack
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
QQ Weibo Plugin for WordPress Developer Profile
1 plugin · 10 total installs
How We Detect QQ Weibo Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qq-weibo-plugin-for-wordpress/css/qqweibo.css/wp-content/plugins/qq-weibo-plugin-for-wordpress/js/qqweibo.js/wp-content/plugins/qq-weibo-plugin-for-wordpress/js/qqweibo.jsqq-weibo-plugin-for-wordpress/css/qqweibo.css?ver=qq-weibo-plugin-for-wordpress/js/qqweibo.js?ver=HTML / DOM Fingerprints
weibo_linkfollow_meclearid="weibo"qqWeibo_Widget