QQWorld Speed for China Security & Risk Analysis

wordpress.org/plugins/qqworld-speed-4-china

如果你的主机在中国内地,你可能需要这个插件使你的网站跑得更快。If your host is in china mainland, you might need this plugin to make your website to running faster.

100 active installs v1.6.6.3 PHP + WP 3.0+ Updated Jan 3, 2021
chinaspeed
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is QQWorld Speed for China Safe to Use in 2026?

Generally Safe

Score 85/100

QQWorld Speed for China has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin 'qqworld-speed-4-china' v1.6.6.3 exhibits a strong security posture from a static analysis perspective, with no identified attack surface through common entry points like AJAX handlers, REST API routes, or shortcodes. The code also demonstrates good practices regarding SQL queries, exclusively using prepared statements, and the absence of dangerous functions, file operations, or external HTTP requests. Furthermore, the vulnerability history is clear, with no recorded CVEs, indicating a potentially well-maintained and secure codebase in these areas.

However, a significant concern arises from the complete lack of output escaping. With 100% of outputs being unescaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered to the user interface that is influenced by user input, even if indirectly, could be exploited. The absence of nonce and capability checks, while not directly indicated as an attack surface in this static analysis, is a general security practice that is missing and could be leveraged if any unintended entry points were discovered or if the plugin's functionality evolved.

In conclusion, while the plugin appears robust in its handling of data storage and execution, the critical deficiency in output escaping leaves it highly vulnerable to XSS attacks. The lack of historical vulnerabilities is positive, but it does not mitigate the immediate and severe risk posed by unescaped output. Addressing the output escaping is paramount to improving the plugin's security.

Key Concerns

  • No output escaping detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

QQWorld Speed for China Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

QQWorld Speed for China Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

QQWorld Speed for China Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionadmin_menuqqworld-speed4china.php:27
actionadmin_initqqworld-speed4china.php:28
filterplugin_row_metaqqworld-speed4china.php:29
actionplugins_loadedqqworld-speed4china.php:30
actionadmin_enqueue_scriptsqqworld-speed4china.php:31
actioninitqqworld-speed4china.php:146
actionshutdownqqworld-speed4china.php:147
actioninitqqworld-speed4china.php:151
actionshutdownqqworld-speed4china.php:152
filterget_avatarqqworld-speed4china.php:157
filterget_avatarqqworld-speed4china.php:159
actioninitqqworld-speed4china.php:163
filterpre_site_transient_update_coreqqworld-speed4china.php:167
filterpre_site_transient_update_pluginsqqworld-speed4china.php:175
filterpre_site_transient_update_themesqqworld-speed4china.php:191
filteruser_has_capqqworld-speed4china.php:206
filterpre_http_requestqqworld-speed4china.php:207
actionadmin_initqqworld-speed4china.php:211
actionwp_dashboard_setupqqworld-speed4china.php:215
filtertiny_mce_pluginsqqworld-speed4china.php:270
Maintenance & Trust

QQWorld Speed for China Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedJan 3, 2021
PHP min version
Downloads17K

Community Trust

Rating80/100
Number of ratings4
Active installs100
Developer Profile

QQWorld Speed for China Developer Profile

Michael Wang

8 plugins · 660 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect QQWorld Speed for China

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/qqworld-speed-4-china/assets/css/admin.css/wp-content/plugins/qqworld-speed-4-china/assets/js/admin.js
Version Parameters
qqworld-speed-4-china/assets/css/admin.css?ver=qqworld-speed-4-china/assets/js/admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- ʵ��ӿ� --><!-- ��������Ϣ����HTTP API�ӿڣ������������ںˡ���������� --><!-- ����SSLЭ��汾�� --><!-- Ĭ��ʹ��HTTP���� -->+1 more
FAQ

Frequently Asked Questions about QQWorld Speed for China