
{eac}Doojigger Simple AWS Extension for WordPress Security & Risk Analysis
wordpress.org/plugins/eacsimpleawsEnables the AWS SDK for PHP; adds a Webhook for WooCommerce to write to an S3 bucket; adds a REST endpoint for EventBridge to post to WordPress.
Is {eac}Doojigger Simple AWS Extension for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100{eac}Doojigger Simple AWS Extension for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the 'eacsimpleaws' plugin v1.1.1 exhibits a generally strong security posture. The absence of any recorded vulnerabilities (CVEs) or identified critical/high severity issues in the taint analysis is a positive indicator. The code also demonstrates good practices in its use of prepared statements for SQL queries and proper output escaping, with 100% of analyzed instances adhering to these security measures. Furthermore, there are no external HTTP requests, file operations, or exposed AJAX/REST API endpoints identified, significantly reducing the potential attack surface. The plugin's adherence to capability checks and nonce checks is also noteworthy.
However, a significant concern arises from the complete lack of identified nonce checks and capability checks. While the attack surface is currently zero, this suggests a potential blind spot in the plugin's security implementation. If functionality were to be added in the future that exposed any of the entry points (AJAX, REST API, shortcodes, cron events), the absence of these fundamental security mechanisms would immediately create vulnerabilities. The bundling of the Guzzle library, while not inherently a security risk, does introduce a dependency that could potentially be outdated or contain its own vulnerabilities if not managed carefully. A perfect score would ideally see these foundational checks in place, even with a minimal attack surface.
In conclusion, 'eacsimpleaws' v1.1.1 is commendably free of known vulnerabilities and demonstrates robust handling of SQL and output. The developers have clearly taken steps to minimize the attack surface. The primary weakness lies in the absence of nonce and capability checks, which represent a latent risk should the plugin's functionality expand. Careful monitoring and proactive implementation of these checks would be advisable to maintain this strong security record.
Key Concerns
- No nonce checks identified
- No capability checks identified
- Bundled Guzzle library
{eac}Doojigger Simple AWS Extension for WordPress Security Vulnerabilities
{eac}Doojigger Simple AWS Extension for WordPress Release Timeline
{eac}Doojigger Simple AWS Extension for WordPress Code Analysis
Bundled Libraries
{eac}Doojigger Simple AWS Extension for WordPress Attack Surface
WordPress Hooks 20
Maintenance & Trust
{eac}Doojigger Simple AWS Extension for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
{eac}Doojigger Simple AWS Extension for WordPress Alternatives
Fast AWS
fast-aws
Enable Amazon File Protection for Fast Member
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
Amazon Web Services
amazon-web-services
Houses the Amazon Web Services (AWS) PHP SDK v2 libraries and manages access keys.
C3 Cloudfront Cache Controller
c3-cloudfront-clear-cache
This is simple plugin that clear all cloudfront cache if you publish posts.
SMTP for Amazon SES – YaySMTP
smtp-amazon-ses
Send WordPress emails through Amazon SES server using YaySMTP
{eac}Doojigger Simple AWS Extension for WordPress Developer Profile
11 plugins · 60 total installs
How We Detect {eac}Doojigger Simple AWS Extension for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eacsimpleaws/admin/css/styles.css/wp-content/plugins/eacsimpleaws/admin/js/eacsimpleaws.js/wp-content/plugins/eacsimpleaws/admin/js/eacsimpleaws.jseacsimpleaws/admin/css/styles.css?ver=eacsimpleaws/admin/js/eacsimpleaws.js?ver=HTML / DOM Fingerprints
eacsimpleaws-admin-noticeconstructor methodAdd filters and actions - called from main pluginWooCommerce Webhooks - send data as file to AWS S3 bucketdata-eacsimpleaws-settings-linkdata-eacsimpleaws-documentation-linkdata-eacsimpleaws-support-linkeacsimpleaws/wp-json/eac/eventbridge/v1/wc-webhook/wp-json/eac/eventbridge/v1/s3-event