Amazon Web Services Security & Risk Analysis

wordpress.org/plugins/amazon-web-services

Houses the Amazon Web Services (AWS) PHP SDK v2 libraries and manages access keys.

6K active installs v1.0.5 PHP + WP 4.6+ Updated Feb 20, 2018
amazonamazon-web-services
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Amazon Web Services Safe to Use in 2026?

Generally Safe

Score 85/100

Amazon Web Services has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'amazon-web-services' plugin version 1.0.5 demonstrates a strong security posture based on the provided static analysis. The absence of any identified attack surface entry points, including AJAX handlers, REST API routes, shortcodes, and cron events, significantly limits the plugin's exposure to external manipulation. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests, all of which are excellent indicators of secure coding practices. The presence of nonce checks and capability checks further reinforces this. The plugin also has a clean vulnerability history with zero recorded CVEs of any severity, suggesting a history of stable and secure development.

However, the static analysis does highlight a minor concern: 70% of output escaping is considered properly escaped, leaving 30% of outputs potentially vulnerable to cross-site scripting (XSS) attacks. While the total number of outputs is small (10), this is still a point of potential risk that could be improved. The taint analysis showing zero flows with unsanitized paths is positive, but the lack of analyzed flows means we cannot definitively rule out all taint-related issues. The bundling of Guzzle, while a powerful library, also presents a potential risk if it's an outdated version, which would require a separate scan to confirm its security status.

In conclusion, the 'amazon-web-services' plugin appears to be a robustly secured piece of software with a commendable lack of common vulnerabilities and attack vectors. The primary area for improvement lies in ensuring 100% of its output is properly escaped. The current findings indicate a high level of security, with only minor, addressable concerns.

Key Concerns

  • 30% of outputs not properly escaped
Vulnerabilities
None known

Amazon Web Services Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Amazon Web Services Release Timeline

v1.0.5Current
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0
v0.3.7
v0.3.6
v0.3
v0.2.2
v0.2.1
v0.2
v0.1
Code Analysis
Analyzed Mar 16, 2026

Amazon Web Services Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
7 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

70% escaped10 total outputs
Attack Surface

Amazon Web Services Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitamazon-web-services.php:37
actionnetwork_admin_menuclasses\amazon-web-services.php:45
actionadmin_menuclasses\amazon-web-services.php:48
filterplugin_action_linksclasses\amazon-web-services.php:55
filternetwork_admin_plugin_action_linksclasses\amazon-web-services.php:56
actionadmin_print_stylesclasses\amazon-web-services.php:89
actionadmin_noticesclasses\wp-aws-compatibility-check.php:109
actionnetwork_admin_noticesclasses\wp-aws-compatibility-check.php:110
Maintenance & Trust

Amazon Web Services Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedFeb 20, 2018
PHP min version
Downloads820K

Community Trust

Rating78/100
Number of ratings7
Active installs6K
Developer Profile

Amazon Web Services Developer Profile

WP Engine

16 plugins · 3.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
831 days
View full developer profile
Detection Fingerprints

How We Detect Amazon Web Services

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/amazon-web-services/assets/css/amazon-web-services.css/wp-content/plugins/amazon-web-services/assets/js/amazon-web-services.js
Script Paths
/wp-content/plugins/amazon-web-services/assets/js/amazon-web-services.js
Version Parameters
amazon-web-services/assets/css/amazon-web-services.css?ver=amazon-web-services/assets/js/amazon-web-services.js?ver=

HTML / DOM Fingerprints

CSS Classes
aws-plugin-settings
HTML Comments
Copyright (c) 2013 Delicious Brains. All rights reserved.Released under the GPL licensehttp://www.opensource.org/licenses/gpl-license.phpThis program is distributed in the hope that it will be useful, but+2 more
JS Globals
aws_compat_checkamazon_web_services
FAQ

Frequently Asked Questions about Amazon Web Services