微信机器人高级版 Security & Risk Analysis

wordpress.org/plugins/weixin-robot

微信机器人你高级版 WordPress 插件。

10 active installs v4.6.8 PHP + WP 3.6+ Updated Unknown
weixin%e5%be%ae%e4%bf%a1
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 微信机器人高级版 Safe to Use in 2026?

Generally Safe

Score 100/100

微信机器人高级版 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The weixin-robot plugin v4.6.8 exhibits a mixed security posture. On the positive side, it has a clean vulnerability history with no known CVEs, indicating a historically stable codebase. Furthermore, the plugin demonstrates good practices by implementing a significant number of nonce and capability checks, and by utilizing prepared statements for a majority of its SQL queries. The absence of shortcodes and REST API routes also reduces the potential attack surface in those areas. However, the static analysis reveals some significant concerns that warrant attention. The presence of the `create_function` dangerous function is a red flag, as it can be exploited for code injection if not handled with extreme care. More critically, the taint analysis shows a high number of flows with unsanitized paths, with 18 identified as high severity. This suggests a significant risk of data being processed without proper sanitization, potentially leading to vulnerabilities like cross-site scripting (XSS) or SQL injection if these flows are not adequately protected by other security mechanisms not immediately apparent in this summary. The low percentage of properly escaped output (19%) further exacerbates this risk, indicating that data displayed to users may not be properly neutralized, increasing the likelihood of XSS attacks.

Key Concerns

  • High severity taint flows found
  • Low output escaping percentage
  • Dangerous function: create_function used
Vulnerabilities
None known

微信机器人高级版 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

微信机器人高级版 Code Analysis

Dangerous Functions
2
Raw SQL Queries
52
102 prepared
Unescaped Output
178
43 escaped
Nonce Checks
31
Capability Checks
24
File Operations
7
External Requests
6
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_filter('weixin_title', create_function('','return "积分历史";'));template\user\credit-history.php:2
create_function<?php add_filter('weixin_title', create_function('','return "积分规则";'));?>template\user\credit-rules.php:1

SQL Query Safety

66% prepared154 total queries

Output Escaping

19% escaped221 total outputs
Data Flows
28 unsanitized

Data Flow Analysis

25 flows28 with unsanitized paths
weixin_robot_message_summary_page (admin\message-stats.php:192)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

微信机器人高级版 Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_weixin_replyadmin\messages.php:303
noprivwp_ajax_weixin_replyadmin\messages.php:304
authwp_ajax_weixin_viewapi\jssdk.php:3
noprivwp_ajax_weixin_viewapi\jssdk.php:4
authwp_ajax_weixin_shareapi\jssdk.php:66
noprivwp_ajax_weixin_shareapi\jssdk.php:67
WordPress Hooks 85
filterwpjam_pagesadmin\admin.php:33
actionadmin_initadmin\admin.php:150
filterpre_update_option_active_pluginsadmin\admin.php:175
actiondelete_blogadmin\admin.php:199
filterweixin_extend_tabsadmin\extend.php:2
actionweixin-robot-extends_field_validateadmin\extend.php:73
actionweixin-robot-extends_option_pageadmin\extend.php:79
filterweixin-robot-extend_fieldsadmin\extend.php:236
actionweixin-robot-user_page_loadadmin\messages.php:2
filterweixin-robot-qrcode-stats_fieldsadmin\qrcode.php:2
filterwpjam_settingsadmin\setting.php:3
actionweixin-robot_option_pageadmin\setting.php:91
filterwpmu_drop_tablesadmin\table.php:228
filterweixin_users_stats_tabsadmin\user-stats.php:2
actionweixin_users_stats_page_loadadmin\user-stats.php:25
filterweixin-robot_defaultsapi\api.php:54
filterwpjam_rewrite_rulesapi\api.php:429
filterwpjam_templateapi\api.php:435
actionwp_enqueue_scriptsapi\jssdk.php:138
actionweixin_send_future_mass_messageapi\send.php:2
filterweixin-robot-replies_tabsextends\admin\advanced-reply.php:4
filterweixin_reply_settingextends\admin\advanced-reply.php:14
filterweixin_default_optionextends\admin\advanced-reply.php:42
filterwpjam_post_optionsextends\admin\advanced-share.php:2
filterweixin_settingextends\admin\air-quality.php:3
filterweixin_response_typesextends\admin\air-quality.php:15
filterweixin_response_typesextends\admin\baidu-map.php:2
filterweixin_settingextends\admin\baidu-map.php:11
filterweixin_reply_settingextends\admin\baidu-map.php:28
filterweixin_response_typesextends\admin\flight.php:2
filterwpjam_pagesextends\admin\pageviews-hook.php:3
filterweixin_users_columnsextends\admin\pageviews-hook.php:43
actionweixin-robot-user_page_loadextends\admin\pageviews-hook.php:51
filterweixin-robot-users-stats_tabsextends\admin\pageviews-hook.php:127
filterweixin-robot-user_tabsextends\admin\pageviews-hook.php:142
filterweixin_tablesextends\admin\pageviews-hook.php:149
actionweixin_extends_updatedextends\admin\pageviews-hook.php:157
filterweixin_response_typesextends\admin\renpin.php:3
filterweixin_response_typesextends\admin\stock.php:3
filterweixin_settingextends\admin\stock.php:9
filterweixin_response_typesextends\admin\yiji.php:2
filterweixin_response_typesextends\admin\youdao-translate.php:3
filterweixin_settingextends\admin\youdao-translate.php:9
filterweixin_builtin_replyextends\advanced-reply.php:11
filterweixin_queryextends\advanced-reply.php:41
filterweixin_queryextends\advanced-reply.php:50
filterweixin_queryextends\advanced-reply.php:60
filterweixin_queryextends\advanced-reply.php:71
filterweixin_queryextends\advanced-reply.php:81
filterposts_whereextends\advanced-reply.php:82
filterweixin_queryextends\advanced-reply.php:87
filterposts_whereextends\advanced-reply.php:88
filterweixin_queryextends\advanced-reply.php:93
filterposts_whereextends\advanced-reply.php:94
filterweixin_queryextends\advanced-reply.php:99
filterposts_whereextends\advanced-reply.php:100
filterweixin_default_optionextends\baidu-map.php:10
filterweixin_builtin_replyextends\baidu-map.php:21
filterweixin_builtin_replyextends\emotion.php:10
filterweixin_response_typesextends\emotion.php:28
actionweixin_subscribeextends\local-user-tag.php:348
actionweixin_scanextends\local-user-tag.php:349
filterweixin_builtin_replyextends\youdao-translate.php:10
filterweixin_default_optionextends\youdao-translate.php:94
actionweixin_replyreply\custom.php:3
filterweixin_queryreply\custom.php:74
actionweixin_robotreply\messages.php:3
actionplugins_loadedreply\messages.php:173
actionweixin_delete_messagesreply\messages.php:188
filterweixin_queryreply\query.php:158
filterweixin_urlreply\query.php:188
actionparse_queryreply\reply.php:18
filterweixin_titletemplate\user\credit-history.php:2
filterweixin_titletemplate\user\credit-rules.php:1
actionweixin_headtemplate\user\edit.php:2
filterweixin_hide_option_menutemplate\user\header.php:12
filterweixin_hide_toolbartemplate\user\header.php:13
filterweixin_hide_option_menutemplate\user\top-credits.php:10
actionwp_headtemplate\user\top-credits.php:17
actionplugins_loadeduser\advanced.php:50
actionweixin_get_user_listuser\advanced.php:66
actionweixin_get_usersuser\advanced.php:134
actionweixin_get_tag_user_listuser\tag.php:111
actionwp_loadedweixin-robot-advanced.php:57
filterdo_parse_requestweixin-robot-advanced.php:117

Scheduled Events 12

weixin_send_future_mass_message
weixin_send_future_mass_message
weixin_delete_messages
weixin_get_user_list
weixin_get_user_list
weixin_get_user_list
weixin_get_users
weixin_get_users
weixin_get_tag_user_list
weixin_get_tag_user_list
weixin_get_tag_user_list
weixin_get_users
Maintenance & Trust

微信机器人高级版 Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedUnknown
PHP min version
Downloads23K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

微信机器人高级版 Developer Profile

denishua

8 plugins · 4K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
143 days
View full developer profile
Detection Fingerprints

How We Detect 微信机器人高级版

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/weixin-robot/assets/css/admin.css/wp-content/plugins/weixin-robot/assets/js/admin.js/wp-content/plugins/weixin-robot/assets/js/jquery.upload.js/wp-content/plugins/weixin-robot/assets/js/kindeditor/kindeditor.js/wp-content/plugins/weixin-robot/assets/js/kindeditor/lang/zh_CN.js/wp-content/plugins/weixin-robot/assets/js/kindeditor/plugins/image/image.js/wp-content/plugins/weixin-robot/assets/js/kindeditor/plugins/insertfile/insertfile.js/wp-content/plugins/weixin-robot/assets/js/kindeditor/plugins/media/media.js+20 more
Script Paths
/wp-content/plugins/weixin-robot/assets/js/admin.js/wp-content/plugins/weixin-robot/assets/js/jquery.upload.js/wp-content/plugins/weixin-robot/assets/js/kindeditor/kindeditor.js/wp-content/plugins/weixin-robot/assets/js/kindeditor/lang/zh_CN.js/wp-content/plugins/weixin-robot/assets/js/kindeditor/plugins/image/image.js/wp-content/plugins/weixin-robot/assets/js/kindeditor/plugins/insertfile/insertfile.js+18 more
Version Parameters
weixin-robot/assets/css/admin.css?ver=weixin-robot/assets/js/admin.js?ver=weixin-robot/assets/js/jquery.upload.js?ver=weixin-robot/assets/js/kindeditor/kindeditor.js?ver=weixin-robot/assets/js/kindeditor/lang/zh_CN.js?ver=weixin-robot/assets/js/kindeditor/plugins/image/image.js?ver=weixin-robot/assets/js/kindeditor/plugins/insertfile/insertfile.js?ver=weixin-robot/assets/js/kindeditor/plugins/media/media.js?ver=weixin-robot/assets/js/kindeditor/plugins/emoticons/emoticons.js?ver=weixin-robot/assets/js/kindeditor/plugins/preview/preview.js?ver=weixin-robot/assets/js/kindeditor/plugins/code/code.js?ver=weixin-robot/assets/js/kindeditor/plugins/table/table.js?ver=weixin-robot/assets/js/kindeditor/plugins/pagebreak/pagebreak.js?ver=weixin-robot/assets/js/kindeditor/plugins/wordpaste/wordpaste.js?ver=weixin-robot/assets/js/kindeditor/plugins/baidumap/baidumap.js?ver=weixin-robot/assets/js/kindeditor/plugins/link/link.js?ver=weixin-robot/assets/js/kindeditor/plugins/source/source.js?ver=weixin-robot/assets/js/kindeditor/plugins/fullscreen/fullscreen.js?ver=weixin-robot/assets/js/kindeditor/plugins/spellchecker/spellchecker.js?ver=weixin-robot/assets/js/kindeditor/plugins/autoresize/autoresize.js?ver=weixin-robot/assets/js/kindeditor/plugins/copy/copy.js?ver=weixin-robot/assets/js/wechat.js?ver=weixin-robot/assets/js/qrcode.js?ver=weixin-robot/assets/js/wxqrcode.js?ver=weixin-robot/assets/css/qrcode.css?ver=weixin-robot/assets/css/wechat.css?ver=weixin-robot/assets/css/wxqrcode.css?ver=weixin-robot/assets/js/weixin_robot_admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
weixin-robot-admin-wrapweixin-robot-settings-wrapweixin-robot-qrcode-wrapweixin-robot-wechat-wrapweixin-robot-wxqrcode-wrap
HTML Comments
<!--高级回复--><!--高级分享--><!--百度地图-->
Data Attributes
data-weixin-robot-plugin-version
JS Globals
weixin_robot_admin_optionsweixin_robot_kindeditor_options
REST Endpoints
/wp-json/weixin-robot/v1/settings
FAQ

Frequently Asked Questions about 微信机器人高级版