WP-TO-WEIBO Security & Risk Analysis

wordpress.org/plugins/wp-to-weibo

synchronize your post to sina weibo when you publisded.

10 active installs v1.2 PHP 5.2.4+ WP 5.0+ Updated Oct 22, 2019
sinaweibo%e5%90%8c%e6%ad%a5%e5%a4%b4%e6%9d%a1%e5%be%ae%e5%8d%9a
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-TO-WEIBO Safe to Use in 2026?

Generally Safe

Score 85/100

WP-TO-WEIBO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The wp-to-weibo v1.2 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The complete absence of any recorded CVEs and a clean taint analysis indicates a history of responsible development and a lack of exploitable vulnerabilities. The code signals also suggest good practices, with all SQL queries using prepared statements and a capability check present, which is a positive sign for access control. However, there are areas for improvement. The 70% output escaping rate means that 30% of outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs. The lack of nonce checks on the identified entry points (though there are none listed) is a potential concern if any were to be introduced in future versions without adequate protection. Overall, the plugin is in a good state, but the unescaped outputs represent a tangible risk that should be addressed to achieve a truly robust security profile.

Key Concerns

  • Output escaping is not fully implemented (30% unescaped)
Vulnerabilities
None known

WP-TO-WEIBO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP-TO-WEIBO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
7 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

70% escaped10 total outputs
Attack Surface

WP-TO-WEIBO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedwp-to-weibo.php:27
actiontransition_post_statuswp-to-weibo.php:30
actiontransition_post_statuswp-to-weibo.php:34
actionadmin_menuwp-to-weibo.php:37
actionadmin_initwp-to-weibo.php:40
Maintenance & Trust

WP-TO-WEIBO Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedOct 22, 2019
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP-TO-WEIBO Developer Profile

hjyl

2 plugins · 40 total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect WP-TO-WEIBO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrapmetabox-holderhas-right-sidebarinner-sidebarmeta-box-sortablessui-sortablepostboxhndle+4 more
Data Attributes
name="hjyl_share_toutiao"id="hjyl_share"id="hjyl_toutiao"name="hjyl_name"id="hjyl_name"name="hjyl_password"+3 more
FAQ

Frequently Asked Questions about WP-TO-WEIBO