同步博客 Security & Risk Analysis

wordpress.org/plugins/wp-blog

支持同步全文到 QQ空间日志、新浪博客、网易博客、人人网日志、开心网日记、点点网等。

20 active installs v0.3 PHP + WP 3.0+ Updated Jun 19, 2014
blogpostqzonewp-blog
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 同步博客 Safe to Use in 2026?

Generally Safe

Score 85/100

同步博客 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "wp-blog" v0.3 plugin exhibits a strong security posture regarding its attack surface and vulnerability history. The static analysis reveals no detectable AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no direct entry points for attackers to exploit. Furthermore, the plugin has no recorded vulnerabilities or CVEs, indicating a history of secure development or a lack of prior security scrutiny. The code signals also show a lack of dangerous functions, file operations, external HTTP requests, and bundled libraries, all of which are positive indicators. However, a significant concern is the complete lack of output escaping. With one output detected and 0% properly escaped, this creates a high risk for Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface. Despite the absence of known vulnerabilities and a minimal attack surface, the unescaped output presents a critical weakness that needs immediate attention.

Key Concerns

  • No output escaping detected
Vulnerabilities
None known

同步博客 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

同步博客 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

同步博客 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_noticeswp-blog.php:38
Maintenance & Trust

同步博客 Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJun 19, 2014
PHP min version
Downloads3K

Community Trust

Rating20/100
Number of ratings1
Active installs20
Developer Profile

同步博客 Developer Profile

smyx

6 plugins · 150 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 同步博客

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
updated
FAQ

Frequently Asked Questions about 同步博客