WPStore.app 中文语法检查 Security & Risk Analysis

wordpress.org/plugins/wpstoreapp-spellcheck

WPStore.app 中文语法检查插件可以帮助作者获得类似于微信公众号后台的纠错功能,帮助作者写出更好的文章。

0 active installs v0.0.5 PHP 8.0+ WP 5.0+ Updated Feb 27, 2022
chinesespellcheck
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPStore.app 中文语法检查 Safe to Use in 2026?

Generally Safe

Score 85/100

WPStore.app 中文语法检查 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The wpstoreapp-spellcheck plugin v0.0.5 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis indicates robust security practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and all identified outputs being properly escaped. Furthermore, the absence of file operations and the handling of external HTTP requests with a capability check suggest careful development. The plugin also has a clean vulnerability history, with no known CVEs recorded, indicating a history of stable and secure releases.

While the plugin's current state appears secure, a few points warrant attention. The presence of a single REST API route without explicit permission callbacks is a potential, albeit currently unrealized, attack vector. Similarly, the lack of nonce checks on AJAX handlers, even though there are none currently, suggests a potential area for future vulnerabilities if new handlers are introduced without proper authorization. The total attack surface is small, and importantly, there are no unprotected entry points, which is a significant strength. Overall, the plugin is well-secured, but maintaining vigilance regarding its limited attack surface and adhering to authorization checks for any future additions will be crucial for continued security.

Key Concerns

  • REST API route without permission callbacks
  • 0 Nonce checks on AJAX handlers
Vulnerabilities
None known

WPStore.app 中文语法检查 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WPStore.app 中文语法检查 Release Timeline

v0.0.5Current
v0.0.4
v0.0.3
v0.0.1
Code Analysis
Analyzed Apr 16, 2026

WPStore.app 中文语法检查 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

WPStore.app 中文语法检查 Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

POST/wp-json/chinese-spell-check/v1/check/WPStoreApp_API.php:12
WordPress Hooks 6
actionrest_api_initWPStoreApp_API.php:8
actioninitWPStoreApp_Gutenberg.php:7
actionenqueue_block_editor_assetsWPStoreApp_Gutenberg.php:8
actionadmin_initWPStoreApp_Option.php:6
filterplugin_row_metaWPStoreApp_Option.php:7
filterplugin_action_linksWPStoreApp_Option.php:8
Maintenance & Trust

WPStore.app 中文语法检查 Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 27, 2022
PHP min version8.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WPStore.app 中文语法检查 Developer Profile

Bestony

12 plugins · 180 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPStore.app 中文语法检查

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpstoreapp-spellcheck/build/index.js

HTML / DOM Fingerprints

REST Endpoints
/wp-json/chinese-spell-check/v1/check/
FAQ

Frequently Asked Questions about WPStore.app 中文语法检查