
QQWorld Share Security & Risk Analysis
wordpress.org/plugins/qqworld-sharePowerful share tools for SNS, MicroBlog, Blog, Bootmark, Mainly for China.
Is QQWorld Share Safe to Use in 2026?
Generally Safe
Score 85/100QQWorld Share has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'qqworld-share' plugin version 1.2.3 exhibits a mixed security posture. On the positive side, it has a minimal attack surface with no detected AJAX handlers, REST API routes, shortcodes, or cron events that are exposed externally. Furthermore, all SQL queries are secured using prepared statements, and there are no recorded CVEs, indicating a potentially stable and less targeted plugin. The absence of external HTTP requests and file operations is also a good sign for security.
However, significant concerns arise from the static code analysis. The plugin uses the dangerous `unserialize` function four times, which is a major security risk as it can lead to Remote Code Execution if it processes untrusted input. Crucially, none of the 12 detected output operations are properly escaped. This means that any data rendered to the user could be vulnerable to Cross-Site Scripting (XSS) attacks, especially if the data originates from user input or external sources. The complete lack of nonce and capability checks is another critical weakness, leaving any functionality vulnerable to unauthorized access and manipulation, particularly in conjunction with the use of `unserialize`.
Given the absence of known vulnerabilities, the plugin might appear safe, but the internal code analysis reveals substantial latent risks. The reliance on `unserialize` without proper input validation or sanitization, coupled with pervasive unescaped output and the absence of authorization checks, creates a high probability of severe security issues such as RCE and XSS. The plugin's security is heavily dependent on the assumption that its internal functions are never called with untrusted data, which is an unrealistic and dangerous assumption in a web application environment. Therefore, while the attack surface is small and there are no known exploits, the potential for critical vulnerabilities is significant.
Key Concerns
- Use of unserialize()
- Output escaping is not properly implemented
- Missing nonce checks
- Missing capability checks
QQWorld Share Security Vulnerabilities
QQWorld Share Code Analysis
Dangerous Functions Found
Output Escaping
QQWorld Share Attack Surface
WordPress Hooks 6
Maintenance & Trust
QQWorld Share Maintenance & Trust
Maintenance Signals
Community Trust
QQWorld Share Alternatives
China-AddThis
china-addthis
专为中国网友设计的社交网络分享插件--China-AddThis
Forethemes Functions
forethemes-functions
This plugin adds some widgets, share buttons, post types and functions that are necessary for ForeThemes's themes.
Share Theme Plugin
share-theme
This is a extension for Share Theme
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
QQWorld Share Developer Profile
8 plugins · 660 total installs
How We Detect QQWorld Share
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qqworld-share/style/qqworld.css/wp-content/plugins/qqworld-share/style/wood.css/wp-content/plugins/qqworld-share/style/dark-metal.css/wp-content/plugins/qqworld-share/style/stone.css/wp-content/plugins/qqworld-share/style/red-earth.css/wp-content/plugins/qqworld-share/style/blueprint.css/wp-content/plugins/qqworld-share/style/light-metal.css/wp-content/plugins/qqworld-share/style/jiathis.css/wp-content/plugins/qqworld-share/js/share.jsqqworld-share/style/qqworld_share/js/share.jsHTML / DOM Fingerprints
qqworld-share-stylename="qqworld-share-theme"name="qqworld-share-settings[]"name="qqworld-share-posttypes[]"name="qqworld-share-mode"qqworld_share_dataglobal $qqworld_share;
echo $qqworld_share->get_share();