[凹凸曼]自动同步七牛云对象存储KODO Security & Risk Analysis

wordpress.org/plugins/apoyl-qiniukodo

设计理念,这是绿色无任何污染,可以随时关闭插件,实现手动和自动同步,让网站图片和附件自动同步到七牛云对象存储KODO,实现图片附件和网站代码分离,流量分流让网站打开速度更快。

10 active installs v2.2.0 PHP 7.4+ WP 6.0+ Updated Jan 21, 2026
%e8%87%aa%e5%8a%a8%e5%90%8c%e6%ad%a5kodooss%e5%af%b9%e8%b1%a1%e5%ad%98%e5%82%a8%e4%b8%83%e7%89%9b%e4%ba%91
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is [凹凸曼]自动同步七牛云对象存储KODO Safe to Use in 2026?

Generally Safe

Score 100/100

[凹凸曼]自动同步七牛云对象存储KODO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

Based on the static analysis and vulnerability history, the plugin 'apoyl-qiniukodo' v2.2.0 presents a generally strong security posture. The absence of any known CVEs and the plugin's apparent lack of exploitable entry points like unprotected AJAX handlers, REST API routes, or shortcodes are positive indicators. The code also demonstrates good practices regarding SQL queries, exclusively using prepared statements, and a respectable percentage of output escaping. However, there are areas that warrant attention. The fact that 26% of outputs are not properly escaped, while not critical given the lack of direct attack vectors, still represents a potential for XSS vulnerabilities if unexpected input channels were to be discovered. Additionally, the presence of file operations and external HTTP requests, while not inherently insecure, could become a risk if not handled with utmost care in terms of input validation and sanitization, though the taint analysis currently shows no unsanitized paths. The vulnerability history being entirely empty is reassuring but could also indicate a lack of thorough historical security auditing. Overall, the plugin appears to be developed with security in mind, but a small number of unescaped outputs and the inherent risks associated with file operations and external requests prevent it from being considered completely risk-free. Continued vigilance and potentially a more thorough review of output handling would be beneficial.

Key Concerns

  • Unescaped output detected
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

[凹凸曼]自动同步七牛云对象存储KODO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

[凹凸曼]自动同步七牛云对象存储KODO Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

[凹凸曼]自动同步七牛云对象存储KODO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
39 escaped
Nonce Checks
2
Capability Checks
0
File Operations
16
External Requests
2
Bundled Libraries
0

Output Escaping

74% escaped53 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
<setting> (admin/partials/setting.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

[凹凸曼]自动同步七牛云对象存储KODO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedincludes/qiniukodo.php:50
actionadmin_menuincludes/qiniukodo.php:56
actionwp_generate_attachment_metadataincludes/qiniukodo.php:59
filterwp_get_attachment_urlincludes/qiniukodo.php:60
filterwp_calculate_image_srcsetincludes/qiniukodo.php:67
actionthe_contentincludes/qiniukodo.php:68
Maintenance & Trust

[凹凸曼]自动同步七牛云对象存储KODO Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 21, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

[凹凸曼]自动同步七牛云对象存储KODO Developer Profile

apoyl

29 plugins · 740 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect [凹凸曼]自动同步七牛云对象存储KODO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apoyl-qiniukodo/admin/css/admin.css/wp-content/plugins/apoyl-qiniukodo/admin/js/admin.js
Version Parameters
apoyl-qiniukodo?ver=apoyl-qiniukodo-settings?page=apoyl-qiniukodo-settingsapoyl-qiniukodo-settings

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about [凹凸曼]自动同步七牛云对象存储KODO