
微信侯斯特 WordPress 伴侣插件 Security & Risk Analysis
wordpress.org/plugins/weixinhost一键实现 WordPress 博客与微信侯斯特的连接,可以方便使用侯斯特功能并同时连接微信。
Is 微信侯斯特 WordPress 伴侣插件 Safe to Use in 2026?
Generally Safe
Score 100/100微信侯斯特 WordPress 伴侣插件 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The weixinhost v1.0.3 plugin exhibits a generally good security posture concerning its attack surface and SQL query handling. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for attackers. Furthermore, all detected SQL queries utilize prepared statements, which is a strong defense against SQL injection vulnerabilities. However, concerns arise from the output escaping and the presence of external HTTP requests. Only 50% of output is properly escaped, indicating a potential risk of Cross-Site Scripting (XSS) vulnerabilities if the unescaped output is rendered within a user's browser. The two external HTTP requests, while not inherently vulnerable, represent potential attack vectors if the plugin relies on untrusted external sources for data or functionality without proper validation. The taint analysis, while showing no critical or high-severity flows, did reveal two flows with unsanitized paths, which warrants further investigation as these could potentially lead to issues if not handled carefully. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a lack of previously exploited weaknesses. This is a positive indicator, but it does not guarantee future security. Overall, the plugin has strengths in its limited attack surface and secure SQL practices, but weaknesses in output escaping and the handling of external requests require attention.
Key Concerns
- Output escaping is not consistently applied
- Taint analysis indicates unsanitized paths
- External HTTP requests are present
微信侯斯特 WordPress 伴侣插件 Security Vulnerabilities
微信侯斯特 WordPress 伴侣插件 Code Analysis
Output Escaping
Data Flow Analysis
微信侯斯特 WordPress 伴侣插件 Attack Surface
WordPress Hooks 4
Maintenance & Trust
微信侯斯特 WordPress 伴侣插件 Maintenance & Trust
Maintenance Signals
Community Trust
微信侯斯特 WordPress 伴侣插件 Alternatives
[凹凸曼]一键微信登录
apoyl-weixin
这是一款实现微信互联一键登录网站,让用户不在繁琐去注册用户,一键实现微信登录,可以让电脑版网站扫描登录和手机微信登录,多个公众号,甚至以后需要移动APP应用微信登录,统一用户账号的需求,极大的方便用户登录网站.
微信二维码登陆
qrcode-login-for-weixin
请注意:
微信机器人高级版
weixin-robot
微信机器人你高级版 WordPress 插件。
Wechat Crossborder for WooCommerce
woo-wechat-crossborder
WooCommerce微信支付跨境官方直连插件,支持PC扫码支付,支持退款.
胖鼠采集(Fat Rat Collect)
fat-rat-collect
胖鼠采集(Fat Rat Collect) 是一款能够帮助你网站自动化的采集工具. 支持采集、微信、简书、知乎、自定义列表页、自定义详情页面、还有许多特色功能、 还可一键采集历史文章, 一键设置自动采集, 自动发布, 为您节省精力, 快来体验一下吧!
微信侯斯特 WordPress 伴侣插件 Developer Profile
1 plugin · 10 total installs
How We Detect 微信侯斯特 WordPress 伴侣插件
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/weixinhost/static/js/weixinhost.js/wp-content/plugins/weixinhost/static/css/weixinhost.css/wp-content/plugins/weixinhost/static/js/weixinhost.jsweixinhost/style.css?ver=weixinhost/script.js?ver=HTML / DOM Fingerprints
data-weixinhost-tokenweixinhost_tokenweixinhost_api_url