Issuu PDF Sync Security & Risk Analysis

wordpress.org/plugins/issuu-pdf-sync

Allows to create PDF Flipbooks with the http://issuu.com service. You just need to get a free key and all your PDF will synchronised on the site.

1K active installs v3.1.2 PHP + WP 3.5+ Updated Apr 9, 2018
flipbookissuupdfsynchronisationupload
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Issuu PDF Sync Safe to Use in 2026?

Generally Safe

Score 85/100

Issuu PDF Sync has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "issuu-pdf-sync" v3.1.2 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the thorough use of prepared statements for SQL queries are strong indicators of responsible development practices. The code also demonstrates a decent level of output escaping and the presence of nonce and capability checks, which are crucial for preventing common web vulnerabilities. The plugin also avoids dangerous functions and file operations, further contributing to its security. However, there is a notable concern regarding an unprotected AJAX handler. This creates a potential entry point that could be exploited if not properly secured through other means, such as input validation or user role checks at the application level. While taint analysis showed no critical or high severity flows, the unprotected AJAX handler remains the most significant risk identified in the code.

Overall, the plugin appears to be well-maintained with no historical vulnerabilities. The main area for improvement is to ensure that all AJAX handlers, including the one identified, have robust authentication and authorization checks implemented. The plugin's strengths lie in its adherence to secure coding practices for database interactions and output handling. The presence of a single unprotected entry point, while a concern, is a manageable risk if addressed promptly. The absence of critical issues in taint analysis and historical CVEs suggests a developer who is attentive to security, but this one oversight needs attention to solidify its security.

Key Concerns

  • Unprotected AJAX handler
  • Output escaping not fully comprehensive (77%)
Vulnerabilities
None known

Issuu PDF Sync Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Issuu PDF Sync Release Timeline

v3.1.2Current
v3.1.1
v3.1
v3.0
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.3@703432
v2.2.2
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.1
v2.0
Code Analysis
Analyzed Mar 16, 2026

Issuu PDF Sync Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
50 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

77% escaped65 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
check_js_pdf_edition (classes\admin\main.php:199)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Issuu PDF Sync Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_ips_shortcodePrinterclasses\admin\main.php:22

Shortcodes 1

[pdf] classes\shortcodes.php:5
WordPress Hooks 11
filterattachment_fields_to_editclasses\admin\main.php:8
filtermedia_send_to_editorclasses\admin\main.php:9
actionadmin_headclasses\admin\main.php:12
actionadmin_initclasses\admin\main.php:15
actionadmin_menuclasses\admin\main.php:16
actionadmin_initclasses\admin\main.php:18
actionadmin_initclasses\admin\main.php:21
filtermce_external_pluginsclasses\admin\main.php:316
filtermce_buttonsclasses\admin\main.php:317
actionadd_attachmentclasses\main.php:5
actionplugins_loadedissuu-pdf-sync.php:63
Maintenance & Trust

Issuu PDF Sync Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 9, 2018
PHP min version
Downloads85K

Community Trust

Rating46/100
Number of ratings9
Active installs1K
Developer Profile

Issuu PDF Sync Developer Profile

benjaminniess

4 plugins · 1K total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Issuu PDF Sync

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/issuu-pdf-sync/css/admin.css/wp-content/plugins/issuu-pdf-sync/js/admin-main.js
Script Paths
/wp-content/plugins/issuu-pdf-sync/js/admin-main.js
Version Parameters
issuu-pdf-sync/css/admin.css?ver=issuu-pdf-sync/js/admin-main.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- The Issuu sync/unsync link HTML structure + javascript --><!-- The extra data array just for debugging info --><!-- Check on post meta if the PDF has already been uploaded on Issuu --><!-- Only add the extra button if the attachment is a PDF file -->+4 more
Data Attributes
issuu_pdf_syncissuu_pdf_sync_idissuu_pdf_usernameissuu_pdf_nameissuu_pdf_urldisable_auto_upload
Shortcode Output
[pdf
FAQ

Frequently Asked Questions about Issuu PDF Sync