微信群发助手(WeChat Helper) Security & Risk Analysis

wordpress.org/plugins/weixin-helper

使用微信公众号、微博粉丝服务的[高级群发接口]实现WordPress自动群发给用户

10 active installs v1.0.1 PHP + WP 3.5+ Updated Mar 16, 2021
weixin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 微信群发助手(WeChat Helper) Safe to Use in 2026?

Generally Safe

Score 85/100

微信群发助手(WeChat Helper) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The weixin-helper v1.0.1 plugin presents a concerning security posture despite a clean vulnerability history and an absence of identified taint flows. The static analysis reveals a significant weakness in output escaping, with 0% of 38 outputs being properly escaped. This is a critical oversight, as unescaped output can lead to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages viewed by other users. Furthermore, the complete lack of nonce checks and capability checks on any potential entry points, while the attack surface is reported as zero, is still a point of vigilance. If any functionality were to be inadvertently exposed, these checks would be absent, leaving it vulnerable to unauthorized actions.

Key Concerns

  • All outputs are unescaped
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

微信群发助手(WeChat Helper) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

微信群发助手(WeChat Helper) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped38 total outputs
Attack Surface

微信群发助手(WeChat Helper) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitweixin-helper.php:17
actionadmin_menuweixin-helper.php:19
Maintenance & Trust

微信群发助手(WeChat Helper) Maintenance & Trust

Maintenance Signals

WordPress version tested1.0.1
Last updatedMar 16, 2021
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

微信群发助手(WeChat Helper) Developer Profile

smyx

6 plugins · 150 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 微信群发助手(WeChat Helper)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/weixin-helper/images/icon_weixin.png/wp-content/plugins/weixin-helper/images/weixin-logo.png
Version Parameters
weixin-helper/style.css?ver=weixin-helper/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wptao-containerwptao-gridwptao-mainwptao-sidebarwptao-boxwptao-box.yellowinput-panel
HTML Comments
<!-- end of inside --><!-- end of postbox --><!-- end of group -->
Data Attributes
upid="helper_image"name="helper[post_types][]"name="helper[item]"name="helper[nopic]"name="helper[image]"name="helper[top]"+9 more
JS Globals
weixin_url
FAQ

Frequently Asked Questions about 微信群发助手(WeChat Helper)