[凹凸曼]直传阿里云视频点播 Security & Risk Analysis

wordpress.org/plugins/apoyl-aliyunvideo

实现视频上传到阿里云,实现文章能播放视频,大量节约服务器带宽流量,视频点播是集视频采集、编辑、上传、媒体资源管理、自动化转码处理(窄带高清™)、视频审核分析、分发加速于一体的一站式音视频点播解决方案

0 active installs v1.3.0 PHP 7.4+ WP 6.0+ Updated Jun 24, 2025
%e7%9b%b4%e4%bc%a0%e8%a7%86%e9%a2%91%e9%98%bf%e9%87%8c%e4%ba%91video%e5%8a%a0%e5%af%86%e6%92%ad%e6%94%be%e8%a7%86%e9%a2%91
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is [凹凸曼]直传阿里云视频点播 Safe to Use in 2026?

Generally Safe

Score 100/100

[凹凸曼]直传阿里云视频点播 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "apoyl-aliyunvideo" v1.3.0 plugin exhibits a generally positive security posture based on the static analysis. The absence of any known CVEs and a history of zero recorded vulnerabilities are strong indicators of good security practices and ongoing maintenance. Furthermore, the code analysis reveals a very limited attack surface with no unprotected AJAX handlers, REST API routes, or shortcodes. The extensive use of output escaping (93%) and the presence of nonce checks are also commendable security measures.

However, there are a few areas that warrant attention. The plugin's single SQL query does not utilize prepared statements, presenting a potential risk of SQL injection, especially if the data originates from user input. While the taint analysis did not reveal any unsanitized paths, this single raw SQL query remains a concern. The lack of capability checks on any entry points, though currently not a direct risk due to the absence of unprotected points, could become an issue if new, unprotected entry points are introduced in future versions without proper authorization checks. Overall, the plugin is reasonably secure, but the raw SQL query is the primary technical concern to address.

Key Concerns

  • Raw SQL query without prepared statements
Vulnerabilities
None known

[凹凸曼]直传阿里云视频点播 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

[凹凸曼]直传阿里云视频点播 Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
2
28 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

93% escaped30 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<setting> (admin\partials\setting.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

[凹凸曼]直传阿里云视频点播 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filtercron_schedulescron\cron_media.php:13
actionapoyl_aliyunvideo_add_cron_intervalcron\cron_media.php:35
actionplugins_loadedincludes\aliyunvideo.php:48
actionadmin_menuincludes\aliyunvideo.php:55
actionwp_generate_attachment_metadataincludes\aliyunvideo.php:57
actionthe_contentincludes\aliyunvideo.php:65

Scheduled Events 2

apoyl_aliyunvideo_add_cron_interval
apoyl_aliyunvideo_cronjob_getmediaid
Maintenance & Trust

[凹凸曼]直传阿里云视频点播 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 24, 2025
PHP min version7.4
Downloads586

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

[凹凸曼]直传阿里云视频点播 Developer Profile

apoyl

27 plugins · 710 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect [凹凸曼]直传阿里云视频点播

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apoyl-aliyunvideo/admin/css/admin.css/wp-content/plugins/apoyl-aliyunvideo/admin/js/admin.js
Script Paths
/wp-content/plugins/apoyl-aliyunvideo/admin/js/admin.js
Version Parameters
apoyl-aliyunvideo/admin/css/admin.css?ver=apoyl-aliyunvideo/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
apoyl-aliyunvideo
HTML Comments
<!-- @link http://www.girltm.com/ --><!-- @since 1.0.0 --><!-- @package APOYL_ALIYUNVIDEO --><!-- @subpackage APOYL_ALIYUNVIDEO/admin -->+1 more
Data Attributes
data-aliyunvideo-region
FAQ

Frequently Asked Questions about [凹凸曼]直传阿里云视频点播