站长帮 – WordPress CDN 缓存管理插件 Security & Risk Analysis

wordpress.org/plugins/zhanzhangb-tcdn

专业的 WordPress CDN 缓存自动化管理解决方案,无缝对接腾讯云 CDN 和 EdgeOne 服务。当您发布或更新文章、发表评论或评论通过审核时,系统将自动触发相关页面的 CDN 缓存刷新,确保访客始终获取最新内容。

30 active installs v2.0.0 PHP 7.0+ WP 5.5+ Updated Jun 25, 2025
cachecdnedgeoneperformancetencent-cloud
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 站长帮 – WordPress CDN 缓存管理插件 Safe to Use in 2026?

Generally Safe

Score 100/100

站长帮 – WordPress CDN 缓存管理插件 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "zhanzhangb-tcdn" plugin v2.0.0 exhibits a generally good security posture, but with notable areas for improvement. The absence of any recorded CVEs, combined with the lack of identified critical or high severity taint flows, suggests a low risk of known exploits and a lack of immediately obvious severe vulnerabilities. The plugin also demonstrates good practices in SQL query handling by exclusively using prepared statements. However, the static analysis does reveal potential weaknesses.

The most significant concern is the complete lack of nonce and capability checks on its entry points. With zero AJAX handlers, REST API routes, shortcodes, or cron events, this might indicate a very simple plugin. However, if any of these entry points were to be added in future updates without proper authorization checks, it would open the door to significant security risks. Furthermore, only 67% of output is properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs are exposed to user-controlled data. The presence of file operations and external HTTP requests, while not inherently dangerous, warrants careful review to ensure they are implemented securely and do not introduce other vulnerabilities.

In conclusion, while the plugin currently benefits from a clean vulnerability history and good SQL practices, the absence of authorization checks on its entry points and imperfect output escaping are critical areas that require immediate attention. These weaknesses, if left unaddressed, could become significant vulnerabilities with future development or changes in how the plugin is used. The plugin's strengths lie in its SQL handling and lack of past major issues, but its current lack of protective mechanisms on its attack surface is a substantial risk.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
  • Improper output escaping (33% not escaped)
Vulnerabilities
None known

站长帮 – WordPress CDN 缓存管理插件 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

站长帮 – WordPress CDN 缓存管理插件 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
4
Bundled Libraries
0

Output Escaping

67% escaped9 total outputs
Attack Surface

站长帮 – WordPress CDN 缓存管理插件 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuoptions.php:9
actionadmin_initoptions.php:10
actionadmin_noticesoptions.php:11
actionpublish_postrefresh-url.php:122
actionpublish_pagerefresh-url.php:123
actioncomment_postrefresh-url.php:124
actioncomment_unapproved_to_approvedrefresh-url.php:125
filterplugin_row_metazhanzhangb-tcdn.php:26
Maintenance & Trust

站长帮 – WordPress CDN 缓存管理插件 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 25, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

站长帮 – WordPress CDN 缓存管理插件 Developer Profile

站长帮

3 plugins · 2K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 站长帮 – WordPress CDN 缓存管理插件

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about 站长帮 – WordPress CDN 缓存管理插件