Increase upload file size & Maximum Execution Time limit Security & Risk Analysis

wordpress.org/plugins/increase-upload-file-size-maximum-execution-time-limit

Discontinued! Please use Additional WP options

700 active installs v3.0 PHP + WP 5.0+ Updated Oct 10, 2024
executionfilelimitsizeupload
91
A · Safe
CVEs total1
Unpatched0
Last CVEOct 10, 2024
Safety Verdict

Is Increase upload file size & Maximum Execution Time limit Safe to Use in 2026?

Generally Safe

Score 91/100

Increase upload file size & Maximum Execution Time limit has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 10, 2024Updated 1yr ago
Risk Assessment

The static analysis of "increase-upload-file-size-maximum-execution-time-limit" v3.0 reveals an exceptionally small attack surface, with no detected AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code adheres to secure coding practices by avoiding dangerous functions, using prepared statements for all SQL queries, and properly escaping output. There are no apparent file operations or external HTTP requests. However, the complete absence of nonce and capability checks on all entry points, coupled with the fact that all entry points are unprotected, is a significant concern. This suggests that if any entry points were to exist, they would be highly vulnerable.

The plugin's vulnerability history is a mixed bag. While there are no currently unpatched vulnerabilities, the single known CVE was a medium-severity Cross-Site Scripting (XSS) vulnerability. This pattern, even with a single instance, indicates a historical weakness in input sanitization or output escaping that was exploited. Although the current version's static analysis shows good output escaping, the historical XSS suggests that past implementations may have been flawed. In conclusion, while the current code base appears robust in its implementation of secure coding practices, the lack of robust authorization checks on its minimal attack surface and the past XSS vulnerability warrant careful consideration. The plugin's strengths lie in its clean code and SQL handling, but its weakness lies in the fundamental security principle of access control.

Key Concerns

  • No capability checks on entry points
  • No nonce checks on entry points
  • All entry points unprotected
  • Past medium severity XSS vulnerability
Vulnerabilities
1

Increase upload file size & Maximum Execution Time limit Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-9611medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Increase upload file size & Maximum Execution Time limit <= 2.0 - Reflected Cross-Site Scripting

Oct 10, 2024 Patched in 3.0 (1d)
Code Analysis
Analyzed Mar 16, 2026

Increase upload file size & Maximum Execution Time limit Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Increase upload file size & Maximum Execution Time limit Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Increase upload file size & Maximum Execution Time limit Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 10, 2024
PHP min version
Downloads22K

Community Trust

Rating74/100
Number of ratings3
Active installs700
Developer Profile

Increase upload file size & Maximum Execution Time limit Developer Profile

ttodua

4 plugins · 2K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
271 days
View full developer profile
Detection Fingerprints

How We Detect Increase upload file size & Maximum Execution Time limit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
increase-upload-file-size-maximum-execution-time-limit/style.css?ver=increase-upload-file-size-maximum-execution-time-limit/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Increase upload file size & Maximum Execution Time limit