
WPICP License Security & Risk Analysis
wordpress.org/plugins/wpicp-licenseThis plugin is free forever, and its purpose is to supplement the essential functions that the Chinese version of WordPress lacks.
Is WPICP License Safe to Use in 2026?
Generally Safe
Score 92/100WPICP License has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wpicp-license" v1.3.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and a lack of external HTTP requests are all positive indicators. The plugin also shows no known vulnerabilities in its history, which is a strong sign of diligent development and testing. However, there are areas for improvement. The static analysis indicates that 40% of outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is ever rendered without proper sanitization. Furthermore, the complete absence of nonce checks and capability checks across all entry points (shortcodes in this case) represents a significant oversight. While there are no unprotected AJAX handlers or REST API routes, shortcodes can still be executed by users in certain contexts, and without proper authorization or nonce verification, malicious actors could potentially trigger unwanted actions or manipulate data. The taint analysis also shows no flows analyzed, which might mean the analysis was limited or that there are no complex data flows susceptible to such analysis within the plugin's code.
Key Concerns
- Unescaped output detected
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Taint analysis not performed or shows no flows
WPICP License Security Vulnerabilities
WPICP License Release Timeline
WPICP License Code Analysis
Output Escaping
WPICP License Attack Surface
Shortcodes 10
WordPress Hooks 5
Maintenance & Trust
WPICP License Maintenance & Trust
Maintenance Signals
Community Trust
WPICP License Alternatives
ICPBEIAN
icpbeian
Adds ICP information to your site footer with shortcode.
Ad Invalid Click Protector (AICP)
ad-invalid-click-protector
One plugin to save your AdSense account from Click Bombings and Invalid Click Activities
VS Event List
very-simple-event-list
With this lightweight plugin you can create an event list.
VS Contact Form
very-simple-contact-form
With this lightweight plugin you can create a contact form.
VS Meta Description
very-simple-meta-description
With this lightweight plugin you can add a meta description to your website.
WPICP License Developer Profile
3 plugins · 1K total installs
How We Detect WPICP License
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpicp-license/style.css/wp-content/plugins/wpicp-license/script.js/wp-content/plugins/wpicp-license/script.jswpicp-license/style.css?ver=wpicp-license/script.js?ver=HTML / DOM Fingerprints
wpicp-license-container<!-- WPICP License Start --><!-- WPICP License End -->data-wpicp-license-iddata-wpicp-license-urlwpicp_license_params<div class="wpicp-license-container"><a href="" target="_blank" rel="noopener"></a>