{eac}Doojigger Simple AWS Extension for WordPress Security & Risk Analysis

wordpress.org/plugins/eacsimpleaws

Enables the AWS SDK for PHP; adds a Webhook for WooCommerce to write to an S3 bucket; adds a REST endpoint for EventBridge to post to WordPress.

0 active installs v1.1.1 PHP 7.4+ WP 5.8+ Updated Jul 30, 2025
amazon-web-servicesawsaws-php-sdkeventbridges3-bucket
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is {eac}Doojigger Simple AWS Extension for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

{eac}Doojigger Simple AWS Extension for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'eacsimpleaws' plugin v1.1.1 exhibits a generally strong security posture. The absence of any recorded vulnerabilities (CVEs) or identified critical/high severity issues in the taint analysis is a positive indicator. The code also demonstrates good practices in its use of prepared statements for SQL queries and proper output escaping, with 100% of analyzed instances adhering to these security measures. Furthermore, there are no external HTTP requests, file operations, or exposed AJAX/REST API endpoints identified, significantly reducing the potential attack surface. The plugin's adherence to capability checks and nonce checks is also noteworthy.

However, a significant concern arises from the complete lack of identified nonce checks and capability checks. While the attack surface is currently zero, this suggests a potential blind spot in the plugin's security implementation. If functionality were to be added in the future that exposed any of the entry points (AJAX, REST API, shortcodes, cron events), the absence of these fundamental security mechanisms would immediately create vulnerabilities. The bundling of the Guzzle library, while not inherently a security risk, does introduce a dependency that could potentially be outdated or contain its own vulnerabilities if not managed carefully. A perfect score would ideally see these foundational checks in place, even with a minimal attack surface.

In conclusion, 'eacsimpleaws' v1.1.1 is commendably free of known vulnerabilities and demonstrates robust handling of SQL and output. The developers have clearly taken steps to minimize the attack surface. The primary weakness lies in the absence of nonce and capability checks, which represent a latent risk should the plugin's functionality expand. Careful monitoring and proactive implementation of these checks would be advisable to maintain this strong security record.

Key Concerns

  • No nonce checks identified
  • No capability checks identified
  • Bundled Guzzle library
Vulnerabilities
None known

{eac}Doojigger Simple AWS Extension for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

{eac}Doojigger Simple AWS Extension for WordPress Release Timeline

v1.1.1Current
v1.1.0
v1.0.4
v1.0.2
v1.0.1
Code Analysis
Analyzed Apr 16, 2026

{eac}Doojigger Simple AWS Extension for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle
Attack Surface

{eac}Doojigger Simple AWS Extension for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionadmin_initExtensions/class.simple_aws.extension.php:61
actionoptions_settings_pageExtensions/class.simple_aws.extension.php:65
actionoptions_settings_helpExtensions/class.simple_aws.extension.php:67
filterSimpleAWS_versionExtensions/class.simple_aws.extension.php:139
filterSimpleAWS_regionExtensions/class.simple_aws.extension.php:140
filterSimpleAWS_access_keyExtensions/class.simple_aws.extension.php:141
filterSimpleAWS_access_secretExtensions/class.simple_aws.extension.php:142
filterSimpleAWS_credentialsExtensions/class.simple_aws.extension.php:143
filterSimpleAWS_client_paramsExtensions/class.simple_aws.extension.php:144
filterSimpleAWS_endpointsExtensions/class.simple_aws.extension.php:146
filterSimpleAWS_regionsExtensions/class.simple_aws.extension.php:147
actionadmin_initExtensions/class.simple_aws_s3_events.extension.php:71
actionoptions_settings_pageExtensions/class.simple_aws_s3_events.extension.php:74
actionrest_api_initExtensions/class.simple_aws_s3_events.extension.php:78
actioneventbridge_objectExtensions/class.simple_aws_s3_events.extension.php:144
filterhttp_originExtensions/class.simple_aws_s3_events.extension.php:207
filterallowed_http_originsExtensions/class.simple_aws_s3_events.extension.php:210
filterhttp_originExtensions/class.simple_aws_s3_events.extension.php:361
filterallowed_http_originsExtensions/class.simple_aws_s3_events.extension.php:364
filtereacDoojigger_load_extensionseacSimpleAWS.php:52
Maintenance & Trust

{eac}Doojigger Simple AWS Extension for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 30, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

{eac}Doojigger Simple AWS Extension for WordPress Developer Profile

Kevin Burkholder

11 plugins · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect {eac}Doojigger Simple AWS Extension for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eacsimpleaws/admin/css/styles.css/wp-content/plugins/eacsimpleaws/admin/js/eacsimpleaws.js
Script Paths
/wp-content/plugins/eacsimpleaws/admin/js/eacsimpleaws.js
Version Parameters
eacsimpleaws/admin/css/styles.css?ver=eacsimpleaws/admin/js/eacsimpleaws.js?ver=

HTML / DOM Fingerprints

CSS Classes
eacsimpleaws-admin-notice
HTML Comments
constructor methodAdd filters and actions - called from main pluginWooCommerce Webhooks - send data as file to AWS S3 bucket
Data Attributes
data-eacsimpleaws-settings-linkdata-eacsimpleaws-documentation-linkdata-eacsimpleaws-support-link
JS Globals
eacsimpleaws
REST Endpoints
/wp-json/eac/eventbridge/v1/wc-webhook/wp-json/eac/eventbridge/v1/s3-event
FAQ

Frequently Asked Questions about {eac}Doojigger Simple AWS Extension for WordPress