QQWorld收银台 初级版 / QQWorld Checkout Lite Security & Risk Analysis

wordpress.org/plugins/qqworld-checkout-lite

QQWorld收银台 初级版,为WooCommerce打造的QQWorld收银台初级版,仅支持桌面端的微信扫描二维码支付,需要更多支付方式如微信全平台支付、支付宝、银联支付、有赞支付等请购买专业版。

10 active installs v1.1.2 PHP + WP 4.3+ Updated Oct 10, 2020
checkoutpaymentqqworldwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is QQWorld收银台 初级版 / QQWorld Checkout Lite Safe to Use in 2026?

Generally Safe

Score 85/100

QQWorld收银台 初级版 / QQWorld Checkout Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "qqworld-checkout-lite" v1.1.2 exhibits a concerning security posture due to a significant number of unprotected entry points, specifically two AJAX handlers that lack authentication checks. While the code signals show no dangerous functions or raw SQL queries, indicating good practices in database interaction and a lack of external requests or file operations, the absence of nonce and capability checks on critical AJAX endpoints leaves them vulnerable to unauthorized access and potential manipulation. The low percentage of properly escaped output also poses a risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of recorded CVEs and a clean vulnerability history is a positive sign, suggesting the developers may have a good understanding of security fundamentals. However, this history does not compensate for the immediate risks identified in the static analysis. The plugin's strengths lie in its SQL handling and lack of external dependencies, but these are overshadowed by the exposed attack surface and insufficient input/output validation.

Key Concerns

  • Unprotected AJAX handlers
  • Low percentage of proper output escaping
  • Missing nonce checks on AJAX handlers
  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

QQWorld收银台 初级版 / QQWorld Checkout Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

QQWorld收银台 初级版 / QQWorld Checkout Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

4% escaped25 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
check_order_status (qqworld-checkout-lite.php:49)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

QQWorld收银台 初级版 / QQWorld Checkout Lite Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_qqworld_checkout_check_order_statusqqworld-checkout-lite.php:45
noprivwp_ajax_qqworld_checkout_check_order_statusqqworld-checkout-lite.php:46
WordPress Hooks 10
actionadmin_noticespayments\wepay\class.wc_wepay.php:64
actionwoocommerce_update_options_payment_gatewayspayments\wepay\class.wc_wepay.php:65
actionwoocommerce_admin_order_data_after_billing_addresspayments\wepay\class.wc_wepay.php:74
filterwoocommerce_payment_gatewayspayments\wepay\init.php:20
actionplugins_loadedqqworld-checkout-lite.php:37
actionadmin_menuqqworld-checkout-lite.php:38
filterplugin_action_linksqqworld-checkout-lite.php:39
actionadmin_enqueue_scriptsqqworld-checkout-lite.php:40
actionadmin_initqqworld-checkout-lite.php:41
actionplugins_loadedqqworld-checkout-lite.php:43
Maintenance & Trust

QQWorld收银台 初级版 / QQWorld Checkout Lite Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 10, 2020
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

QQWorld收银台 初级版 / QQWorld Checkout Lite Developer Profile

Michael Wang

8 plugins · 660 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect QQWorld收银台 初级版 / QQWorld Checkout Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/qqworld-checkout-lite/css/style.css/wp-content/plugins/qqworld-checkout-lite/images/banner-772x250.png/wp-content/plugins/qqworld-checkout-lite/images/wepay/featured.png
Version Parameters
qqworld-checkout-lite/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
qqworld-checkout-containericon32-qqworld-checkout-settings
Data Attributes
data-colname
JS Globals
qqworld_checkout_payments
REST Endpoints
/wp-json/qqworld-checkout/v1/check_order_status
FAQ

Frequently Asked Questions about QQWorld收银台 初级版 / QQWorld Checkout Lite