
微信分身 Security & Risk Analysis
wordpress.org/plugins/weixin-cloned在微信中隐藏网站主域名,使用其他域名代替,防止微信封杀网站主域名。
Is 微信分身 Safe to Use in 2026?
Generally Safe
Score 100/100微信分身 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "weixin-cloned" plugin v1.0 exhibits a concerning security posture despite an apparently limited attack surface and no recorded vulnerability history. While the plugin boasts zero AJAX handlers, REST API routes, shortcodes, and cron events, and importantly, all SQL queries are prepared, the static analysis reveals significant weaknesses. Specifically, 100% of output is not properly escaped, meaning sensitive data could be exposed to cross-site scripting (XSS) attacks. Furthermore, taint analysis indicates two flows with unsanitized paths, which, while not classified as critical or high, still represent potential vulnerabilities if the data within these paths is user-controlled and displayed without proper sanitization. The absence of nonce and capability checks across all entry points (even if they are zero) is a theoretical concern that could become a practical one if functionality is added in the future without proper security measures. The lack of recorded vulnerabilities could be due to the plugin's obscurity or simply its age; it does not negate the identified code-level risks.
Key Concerns
- Unescaped output detected
- Unsanitized paths in taint analysis
- Lack of nonce checks
- Lack of capability checks
微信分身 Security Vulnerabilities
微信分身 Code Analysis
Output Escaping
Data Flow Analysis
微信分身 Attack Surface
WordPress Hooks 1
Maintenance & Trust
微信分身 Maintenance & Trust
Maintenance Signals
Community Trust
微信分身 Alternatives
Payment gateway for WooCommerce – Woo WeChatPay
woo-wechatpay
WeChat Pay payment gateway for WooCommerce.
[Aotuman] Grab WeChat Articles
apoyl-grabweixin
Enter the WeChat Official Account article link in the editor, click "Grab WeChat Articles," and the content will be automatically captured i …
[凹凸曼]一键微信登录
apoyl-weixin
这是一款实现微信互联一键登录网站,让用户不在繁琐去注册用户,一键实现微信登录,可以让电脑版网站扫描登录和手机微信登录,多个公众号,甚至以后需要移动APP应用微信登录,统一用户账号的需求,极大的方便用户登录网站.
zhanzhangb-share
zhanzhangb-share
插件功能:支持微信分享:带缩略图与摘要、朋友圈分享带缩略图与摘要(均支持未认证公众号);QQ分享:带缩略图;QQ空间分享:带缩略图与摘要;微博分享:带缩略图与摘要;LinkedIn分享:带缩略图与摘要;邮件分享:调起系统默认邮箱客户端
微信二维码登陆
qrcode-login-for-weixin
请注意:
微信分身 Developer Profile
6 plugins · 150 total installs
How We Detect 微信分身
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/weixin-cloned/weixin-cloned.js/wp-content/plugins/weixin-cloned/weixin-cloned.jsweixin-cloned/weixin-cloned.js?ver=