Copy Media url Security & Risk Analysis

wordpress.org/plugins/copy-media-url

All new Wordpress plugin by which an admin can copy media url to clipboard.

10 active installs v1.0.1 PHP + WP 3.6+ Updated Mar 6, 2018
mediauploads
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Copy Media url Safe to Use in 2026?

Generally Safe

Score 85/100

Copy Media url has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "copy-media-url" plugin version 1.0.1 exhibits a concerning security posture due to its minimal attack surface but significant lack of proper security checks. While the plugin uses prepared statements for its SQL queries and has no recorded vulnerability history, these positive aspects are overshadowed by critical security oversights. Specifically, the plugin exposes one AJAX handler without any authentication or capability checks, presenting a direct entry point for unauthorized actions. Furthermore, the code analysis reveals that 100% of its outputs are not properly escaped, and taint analysis shows two flows with unsanitized paths. This combination of unprotected entry points and unescaped output, coupled with unsanitized data flows, creates a high risk of cross-site scripting (XSS) attacks and potential arbitrary file access or manipulation if the unsanitized paths relate to file operations (though file operations are listed as 0). The absence of nonce checks on the AJAX handler is a particularly glaring omission that significantly elevates the risk profile. Despite the lack of known CVEs, the presence of these fundamental security flaws within the code itself warrants serious attention and remediation.

Key Concerns

  • AJAX handler without auth check
  • Unescaped output
  • Flows with unsanitized paths
  • Missing nonce checks
Vulnerabilities
None known

Copy Media url Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Copy Media url Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
dc_get_attachment_url_callback (dc-media-url.php:24)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Copy Media url Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_get_attachment_urldc-media-url.php:13
WordPress Hooks 1
actionadmin_enqueue_scriptsdc-media-url.php:11
Maintenance & Trust

Copy Media url Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedMar 6, 2018
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Copy Media url Developer Profile

DualCube

4 plugins · 830 total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
102 days
View full developer profile
Detection Fingerprints

How We Detect Copy Media url

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/copy-media-url/assets/js/ZeroClipboard.js/wp-content/plugins/copy-media-url/assets/js/media-new.js
Script Paths
assets/js/ZeroClipboard.jsassets/js/media-new.js
Version Parameters
copy-media-url/assets/js/ZeroClipboard.js?ver=copy-media-url/assets/js/media-new.js?ver=

HTML / DOM Fingerprints

JS Globals
media_script
FAQ

Frequently Asked Questions about Copy Media url