wptaoAPP Security & Risk Analysis

wordpress.org/plugins/wptao-app

WordPress淘宝客APP/小程序 配置工具

0 active installs v0.1 PHP + WP 3.5+ Updated Apr 29, 2020
androidappwptao%e5%be%ae%e4%bf%a1%e5%b0%8f%e7%a8%8b%e5%ba%8f%e6%b7%98%e5%ae%9d%e5%ae%a2
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is wptaoAPP Safe to Use in 2026?

Generally Safe

Score 85/100

wptaoAPP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of the "wptao-app" v0.1 plugin reveals a strong security posture with no identified attack surface, dangerous functions, raw SQL queries, file operations, external HTTP requests, or taint flows. This indicates that the developers have implemented robust security practices within the provided code. The absence of known vulnerabilities in the plugin's history further reinforces this positive assessment. However, the complete absence of nonce checks and capability checks across all entry points is a significant concern. While there are currently no direct entry points detected, any future additions without proper authentication and authorization mechanisms would expose the plugin to severe risks. Therefore, while the current state of the code is commendable, there is a critical need for the implementation of proper security checks on all new functionalities.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

wptaoAPP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

wptaoAPP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

wptaoAPP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menuwptao-app.php:11
Maintenance & Trust

wptaoAPP Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 29, 2020
PHP min version
Downloads989

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

wptaoAPP Developer Profile

smyx

6 plugins · 150 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect wptaoAPP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<div class="updated"> <p>★安卓app下载链接: <a href="http://go.wptao.com/youhuimeapp" target="_blank" rel="noopener noreferrer">点击下载</a></p> <p>★微信小程序:</p> <p><a href="http://img2.wptao.cn/images/mpweixin-youhuime.jpg" target="_blank" rel="noopener noreferrer"><img style="margin: 0;display:inline" src="http://img2.wptao.cn/images/mpweixin-youhuime.jpg" alt="" /></a></p> <p></p> <p>如需查看本插件后台请看:<a href="http://youhuime.com/wp-admin/admin.php?page=wptao-app" target="_blank" rel="noopener noreferrer">点击这里</a>(帐号和密码都是<code>test</code>)</p> <p></p> <p>如需购买APP/小程序请看:<a href="https://wptao.com/wptao-app.html" target="_blank" rel="noopener noreferrer">https://wptao.com/wptao-app.html</a></p> </div>
FAQ

Frequently Asked Questions about wptaoAPP