WeChat (连接微信) Security & Risk Analysis

wordpress.org/plugins/wechat

微信/易信/微博私信搜索搜索Wordpress文章,关键字自定义回复,消息记录和数据分析,创建自定义菜单等。

40 active installs v0.5 PHP + WP 2.8+ Updated Apr 3, 2018
postweixinwidgetyixin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WeChat (连接微信) Safe to Use in 2026?

Generally Safe

Score 85/100

WeChat (连接微信) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'wechat' v0.5 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-sized attack surface. Furthermore, the code signals indicate a lack of dangerous functions, reliance on prepared statements for all SQL queries, and no file operations or external HTTP requests. This suggests a well-contained plugin with minimal opportunities for external manipulation.

However, a significant concern emerges from the complete absence of output escaping. With 100% of outputs not properly escaped, this presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data processed and displayed by the plugin, even if not originating from user input directly, could potentially be manipulated to execute malicious scripts in a user's browser. The lack of nonce checks and capability checks further exacerbates this, as there are no built-in mechanisms to verify user intent or permissions for actions that might involve outputting data.

The vulnerability history is clean, with no known CVEs, which is a positive indicator of the plugin's past security. However, the absence of past vulnerabilities does not negate the critical XSS risk identified in the current static analysis. In conclusion, while the plugin's limited attack surface and secure data handling practices are commendable, the severe lack of output escaping creates a substantial security weakness that needs immediate attention.

Key Concerns

  • 0% output escaping
  • 0 capability checks
  • 0 nonce checks
Vulnerabilities
None known

WeChat (连接微信) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WeChat (连接微信) Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

WeChat (连接微信) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

WeChat (连接微信) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitwechat.php:14
actionadmin_menuwechat.php:16
Maintenance & Trust

WeChat (连接微信) Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedApr 3, 2018
PHP min version
Downloads14K

Community Trust

Rating20/100
Number of ratings1
Active installs40
Developer Profile

WeChat (连接微信) Developer Profile

smyx

7 plugins · 190 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WeChat (连接微信)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wechat/images/small-weixin.gif/wp-content/plugins/wechat/images/icon_weixin.png

HTML / DOM Fingerprints

CSS Classes
wrap
FAQ

Frequently Asked Questions about WeChat (连接微信)