Seoceo Reward & Share Poster (打赏分享海报插件) Security & Risk Analysis

wordpress.org/plugins/rewardshareposter

Including functions such as tipping, sharing, and generating posters from article inner pages.

0 active installs v0.0.1 PHP 7.4+ WP 5.3+ Updated Mar 2, 2026
poster%e6%89%93%e8%b5%8freward%e5%88%86%e4%ba%ab%e6%89%93%e8%b5%8f%e6%b5%b7%e6%8a%a5%e5%9b%be
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Seoceo Reward & Share Poster (打赏分享海报插件) Safe to Use in 2026?

Generally Safe

Score 100/100

Seoceo Reward & Share Poster (打赏分享海报插件) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "rewardshareposter" v0.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of direct SQL injection risks due to 100% prepared statement usage and no discovered critical or high severity taint flows is a significant positive. Furthermore, the plugin utilizes nonces for all its AJAX handlers, which is a crucial security practice for preventing CSRF attacks. The limited number of external HTTP requests also reduces the potential for certain types of vulnerabilities.

However, there are areas for concern. The lack of capability checks on all AJAX handlers, despite the presence of nonce checks, leaves a potential gap. While nonces protect against cross-site request forgery, they do not inherently restrict access to privileged actions. This means that if an attacker can trick an authenticated user into triggering an AJAX request, the action might be performed even if the user shouldn't have permission. The output escaping rate, while not alarmingly low at 74%, indicates that a portion of the plugin's output is not properly escaped, which could lead to stored or reflected XSS vulnerabilities if user-supplied data is involved in those unescaped outputs.

The plugin's vulnerability history shows no recorded CVEs, which is excellent. This suggests a lack of known exploitable flaws in previous versions and a responsible development approach so far. However, as this is a very early version (0.0.1), this lack of history is less indicative of sustained security and more reflective of its nascent stage. In conclusion, the plugin has good foundational security practices in place but requires attention to capability checks and output escaping to achieve a more robust security profile.

Key Concerns

  • Missing capability checks on AJAX handlers
  • 74% output escaping - potential XSS
Vulnerabilities
None known

Seoceo Reward & Share Poster (打赏分享海报插件) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Seoceo Reward & Share Poster (打赏分享海报插件) Release Timeline

v0.0.1Current
Code Analysis
Analyzed Apr 16, 2026

Seoceo Reward & Share Poster (打赏分享海报插件) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
26 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

74% escaped35 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
rewardshareposter_vip (inc/post.php:11)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Seoceo Reward & Share Poster (打赏分享海报插件) Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_rewardshareposter_get_vipinc/post.php:5
authwp_ajax_rewardshareposter_vipinc/post.php:6
authwp_ajax_rewardshareposter_rewardshareposterinc/post.php:7
authwp_ajax_rewardshareposter_get_rewardshareposterinc/post.php:8
WordPress Hooks 4
actionwp_enqueue_scriptsinc/header.php:6
actionthe_contentinc/header.php:8
actionadmin_enqueue_scriptsinc/index.php:7
actionadmin_menuinc/index.php:9
Maintenance & Trust

Seoceo Reward & Share Poster (打赏分享海报插件) Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 2, 2026
PHP min version7.4
Downloads137

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Seoceo Reward & Share Poster (打赏分享海报插件) Developer Profile

沃之涛

9 plugins · 1K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
98 days
View full developer profile
Detection Fingerprints

How We Detect Seoceo Reward & Share Poster (打赏分享海报插件)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rewardshareposter/inc/css/header.css/wp-content/plugins/rewardshareposter/threeAndone/dist/css/share.min.css/wp-content/plugins/rewardshareposter/inc/rewardshareposter/js/header.js/wp-content/plugins/rewardshareposter/threeAndone/ewm.js/wp-content/plugins/rewardshareposter/threeAndone/jieping.js/wp-content/plugins/rewardshareposter/threeAndone/dom-to-image.js/wp-content/plugins/rewardshareposter/threeAndone/dist/js/social-share.min.js
Script Paths
/wp-content/plugins/rewardshareposter/inc/rewardshareposter/js/header.js/wp-content/plugins/rewardshareposter/threeAndone/ewm.js/wp-content/plugins/rewardshareposter/threeAndone/jieping.js/wp-content/plugins/rewardshareposter/threeAndone/dom-to-image.js/wp-content/plugins/rewardshareposter/threeAndone/dist/js/social-share.min.js
Version Parameters
ver=0.0.1

HTML / DOM Fingerprints

CSS Classes
wztkj_footer_shy_conwztkj_f_s_btnwztkj_f_s_c_hbwztkj_f_s_c_dswztkj_f_s_c_fx
Data Attributes
id="wztkj_f_s_c_hb"id="wztkj_f_s_c_ds"id="wztkj_f_s_c_fx"
JS Globals
rewardshareposterDatawztkej_ewmwztkej_jiepingwztkej_dom-to-imagewztkej_dist_socialwztkej_texiao_headerJs
REST Endpoints
/wp-json/rewardshareposter/v1/some_endpoint
Shortcode Output
<div class="wztkj_footer_shy_con"><button class="wztkj_f_s_btn" id="wztkj_f_s_c_hb">海报</button><button class="wztkj_f_s_btn" id="wztkj_f_s_c_ds">打赏</button><button class="wztkj_f_s_btn" id="wztkj_f_s_c_fx">分享</button></div>
FAQ

Frequently Asked Questions about Seoceo Reward & Share Poster (打赏分享海报插件)