Add Prefix on File Upload Security & Risk Analysis

wordpress.org/plugins/add-prefix-on-file-upload

Add a custom prefix after uploading a file

0 active installs v0.5 PHP + WP 4.0+ Updated Feb 6, 2023
add-prefixfile-uploadprefixrenameupload
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Add Prefix on File Upload Safe to Use in 2026?

Generally Safe

Score 85/100

Add Prefix on File Upload has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "add-prefix-on-file-upload" v0.5 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, direct SQL queries (all are prepared), properly escaped output, file operations, or external HTTP requests is highly commendable. Furthermore, the lack of any recorded vulnerabilities, including critical or high severity issues, in its history suggests a well-maintained and secure codebase. The presence of a capability check indicates at least some consideration for access control.

However, a significant concern arises from the complete absence of identified entry points, including AJAX handlers, REST API routes, shortcodes, and cron events. While this indicates no *exposed* attack surface in the static analysis, it's unusual for a plugin that likely interacts with user actions or site functionality to have absolutely zero entry points. This could suggest that the plugin's functionality is not being triggered or analyzed correctly by the static analysis tool, or that the plugin is extremely limited in scope. The taint analysis also shows zero flows, which, in conjunction with the zero entry points, further raises questions about the depth of the analysis or the plugin's actual interaction points. Without any identified taint flows or exposed attack surface, it's difficult to definitively assess potential risks beyond the positive indicators already present. The plugin's strength lies in its apparent lack of exploitable code patterns, but the analysis might be missing critical interaction points.

Key Concerns

  • Zero identified entry points
  • Zero taint flows analyzed
  • Zero nonce checks
Vulnerabilities
None known

Add Prefix on File Upload Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Add Prefix on File Upload Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Add Prefix on File Upload Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

Add Prefix on File Upload Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuadd-prefix-file-upload.php:26
actionadmin_initadd-prefix-file-upload.php:77
filterwp_handle_upload_prefilteradd-prefix-file-upload.php:88
Maintenance & Trust

Add Prefix on File Upload Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 6, 2023
PHP min version
Downloads871

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Add Prefix on File Upload Developer Profile

DRF Designer

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add Prefix on File Upload

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrap
FAQ

Frequently Asked Questions about Add Prefix on File Upload