QQWorld Woocommerce助手精简版 Security & Risk Analysis

wordpress.org/plugins/qqworld-woocommerce-assistant-lite

QQWorld WooCommerce助手,包含品牌、送货、物流查询等扩展设置。

10 active installs v1.0.1 PHP + WP 3.0+ Updated Feb 14, 2017
chinaspeed
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is QQWorld Woocommerce助手精简版 Safe to Use in 2026?

Generally Safe

Score 85/100

QQWorld Woocommerce助手精简版 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

Based on the static analysis, "qqworld-woocommerce-assistant-lite" v1.0.1 exhibits a strong security posture in several key areas. The plugin has zero identified entry points for direct attacks such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. Furthermore, it demonstrates good practices by avoiding dangerous functions and performing all SQL queries using prepared statements, mitigating the risk of SQL injection vulnerabilities. The absence of file operations and external HTTP requests also limits potential attack vectors. The plugin also boasts no known CVEs in its history, suggesting a history of stable and secure development.

However, a significant concern arises from the low percentage (19%) of properly escaped output. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where unescaped data could be injected and executed within a user's browser. The complete lack of nonce checks and capability checks, coupled with zero AJAX handlers and REST API routes without permission callbacks, is concerning. While the attack surface is reported as zero, the absence of these fundamental security mechanisms means that if any entry points were to be discovered or introduced in the future, they would likely be unprotected. In conclusion, while the plugin avoids common vulnerabilities like SQL injection and has a clean vulnerability history, the inadequate output escaping and lack of authentication/authorization checks on potential (even if currently non-existent) entry points represent significant weaknesses that require attention.

Key Concerns

  • Low output escaping rate
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

QQWorld Woocommerce助手精简版 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

QQWorld Woocommerce助手精简版 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

19% escaped16 total outputs
Attack Surface

QQWorld Woocommerce助手精简版 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
filterqqworld-woocommerce-assistant-extensionsextensions\brand-taxonomy.php:14
actionadmin_menuextensions\brand-taxonomy.php:15
actionadmin_initextensions\brand-taxonomy.php:16
actioninitextensions\brand-taxonomy.php:20
actioncreated_termextensions\brand-taxonomy.php:24
actionedit_termextensions\brand-taxonomy.php:25
actionadmin_enqueue_scriptsextensions\brand-taxonomy.php:26
filterqqworld-woocommerce-assistant-extensionsextensions\chinization.php:12
filterqqworld-woocommerce-assistant-extensionsextensions\logistics-query.php:12
filterqqworld-woocommerce-assistant-extensionsextensions\shipping-status.php:12
actionadmin_menuextensions\shipping-status.php:14
actionadmin_initextensions\shipping-status.php:15
actioninitextensions\shipping-status.php:19
filterwc_order_statusesextensions\shipping-status.php:20
actionplugins_loadedqawc.php:32
actionplugins_loadedqawc.php:33
actionadmin_menuqawc.php:34
actionadmin_initqawc.php:35
actionadmin_enqueue_scriptsqawc.php:36
filterplugin_action_linksqawc.php:37
Maintenance & Trust

QQWorld Woocommerce助手精简版 Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedFeb 14, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

QQWorld Woocommerce助手精简版 Developer Profile

Michael Wang

8 plugins · 660 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect QQWorld Woocommerce助手精简版

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/qqworld-woocommerce-assistant-lite/css/style.css/wp-content/plugins/qqworld-woocommerce-assistant-lite/js/admin.js
Script Paths
/wp-content/plugins/qqworld-woocommerce-assistant-lite/js/admin.js
Version Parameters
qqworld-woocommerce-assistant-lite/css/style.css?ver=qqworld-woocommerce-assistant-lite/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
qqworld-woocommerce-assistant-containerforminp
Data Attributes
data-headerdata-content
JS Globals
QAWC_EXTENSION
FAQ

Frequently Asked Questions about QQWorld Woocommerce助手精简版