[凹凸曼]腾讯云云点播VOD Security & Risk Analysis

wordpress.org/plugins/apoyl-tencentvideo

实现视频上传到腾讯云云点播,实现文章能播放视频,大量节约服务器带宽流量,腾讯云点播(Video on Demand,VOD)面向音视频、图片等媒体,提供制作上传、存储、转码、媒体处理、媒体 AI、加速分发播放、版权保护等一体化的高品质媒体服务

0 active installs v1.1.0 PHP 7.4+ WP 6.0+ Updated May 5, 2025
%e8%85%be%e8%ae%af%e4%ba%91%e8%a7%86%e9%a2%91video%e6%92%ad%e6%94%be%e8%a7%86%e9%a2%91
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is [凹凸曼]腾讯云云点播VOD Safe to Use in 2026?

Generally Safe

Score 100/100

[凹凸曼]腾讯云云点播VOD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "apoyl-tencentvideo" v1.1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified CVEs, critical taint flows, dangerous functions, file operations, or unescaped output is highly positive. The plugin also demonstrates good practices by performing nonce checks. However, there are a few areas that warrant attention. The plugin uses SQL queries without prepared statements, which could be a potential vulnerability if not handled carefully. Additionally, while the overall attack surface is minimal, the lack of capability checks on the cron events means that any user, regardless of their role, could potentially trigger these events. The plugin's vulnerability history is clean, suggesting a commitment to security or a lack of past significant issues, which is a good sign. Overall, the plugin appears to be well-developed from a security perspective, but the lack of SQL preparedness and capability checks on cron events are minor concerns that could be improved.

Key Concerns

  • Raw SQL without prepared statements
  • Cron events without capability checks
Vulnerabilities
None known

[凹凸曼]腾讯云云点播VOD Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

[凹凸曼]腾讯云云点播VOD Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
2
24 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

92% escaped26 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<setting> (admin\partials\setting.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

[凹凸曼]腾讯云云点播VOD Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filtercron_schedulescron\cron_media.php:13
actionapoyl_tencentvideo_add_cron_intervalcron\cron_media.php:35
actionplugins_loadedincludes\tencentvideo.php:48
actionadmin_menuincludes\tencentvideo.php:55
actionwp_generate_attachment_metadataincludes\tencentvideo.php:57
actionthe_contentincludes\tencentvideo.php:65

Scheduled Events 2

apoyl_tencentvideo_add_cron_interval
apoyl_tencentvideo_cronjob_getmediaid
Maintenance & Trust

[凹凸曼]腾讯云云点播VOD Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 5, 2025
PHP min version7.4
Downloads444

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

[凹凸曼]腾讯云云点播VOD Developer Profile

apoyl

27 plugins · 710 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect [凹凸曼]腾讯云云点播VOD

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apoyl-tencentvideo/admin/css/admin.css/wp-content/plugins/apoyl-tencentvideo/admin/js/admin.js
Version Parameters
/wp-content/plugins/apoyl-tencentvideo/admin/css/admin.css?ver=/wp-content/plugins/apoyl-tencentvideo/admin/js/admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about [凹凸曼]腾讯云云点播VOD