
WPJAM Basic Security & Risk Analysis
wordpress.org/plugins/wpjam-basicWPJAM Basic 是我爱水煮鱼博客多年来使用 WordPress 来整理的优化插件,WPJAM Basic 除了能够优化你的 WordPress,也是 WordPress 果酱团队进行 WordPress 二次开发的基础。
Is WPJAM Basic Safe to Use in 2026?
Generally Safe
Score 96/100WPJAM Basic has a strong security track record. Known vulnerabilities have been patched promptly.
The wpjam-basic plugin version 6.9.4 presents a mixed security posture. While it demonstrates good practices such as a low attack surface with only one entry point (a shortcode) and a significant percentage of SQL queries using prepared statements, there are notable areas of concern. The presence of two dangerous 'unserialize' functions, coupled with two flows with unsanitized paths identified in the taint analysis, suggests potential vulnerabilities, even though no critical or high severity taint issues were found. The plugin has a history of one medium severity CVE related to Cross-site Scripting, which, despite being patched, indicates that input sanitization and output escaping are areas that have required attention in the past. The low percentage of properly escaped outputs (34%) is a significant weakness, increasing the risk of XSS vulnerabilities if not handled carefully in all code paths. The limited number of external HTTP requests and file operations are positive aspects. Overall, while the plugin has a controlled attack surface and generally uses prepared statements, the identified 'unserialize' functions, unsanitized paths, and particularly the poor output escaping percentage warrant careful monitoring and potential further investigation to mitigate risks.
Key Concerns
- Dangerous function unserialize detected
- Flows with unsanitized paths detected
- Low percentage of properly escaped outputs
- Past medium CVE for XSS
WPJAM Basic Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WPJAM Basic <= 6.9.2 - Authenticated (Subscriber+) Arbitrary File Upload
WPJAM Basic <= 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WPJAM Basic Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WPJAM Basic Attack Surface
Shortcodes 1
WordPress Hooks 121
Maintenance & Trust
WPJAM Basic Maintenance & Trust
Maintenance Signals
Community Trust
WPJAM Basic Alternatives
Object Cache 4 everyone
object-cache-4-everyone
Memcached or disk backend support for the WP Object Cache. Memcached server running and PHP Memcached class needed for better performance.
atec Cache Info
atec-cache-info
Show system cache status and statistics for OPcache, JIT, Object Cache, APCu, Redis, Memcached, and SQLite Cache.
MemcacheD Is Your Friend
memcached-is-your-friend
Adds MemcacheD object cache support to WordPress and auto-configures your cache setup.
Batcache
batcache
Batcache uses Memcached to store and serve rendered pages.
Cache Master
cache-master
Cache Master is an extremely lightweight, high-performance cache plugin that speeds up your WordPress sites on the fly. The core of Cache Master is dr …
WPJAM Basic Developer Profile
8 plugins · 4K total installs
How We Detect WPJAM Basic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpjam-basic/static/style.css/wp-content/plugins/wpjam-basic/static/script.js/wp-content/plugins/wpjam-basic/static/form.js/wp-content/plugins/wpjam-basic/static/script.js/wp-content/plugins/wpjam-basic/static/form.jswpjam-style?ver=wpjam-script?ver=wpjam-form?ver=HTML / DOM Fingerprints
wpjam-page-settingwpjam-page-actionwpjam-querywpjam-uploadwpjam_page_setting/wpjam-api/