KODO Qiniu Security & Risk Analysis

wordpress.org/plugins/kodo-qiniu

使用七牛云海量存储系统 KODO 作为附件存储空间。(This is a plugin that uses Qiniu Cloud KODO for attachments remote saving.)

300 active installs v1.5.8 PHP 7.1+ WP 4.6+ Updated Dec 5, 2025
kodoqiniu%e5%af%b9%e8%b1%a1%e5%ad%98%e5%82%a8%e6%b5%b7%e9%87%8f%e5%ad%98%e5%82%a8%e4%b8%83%e7%89%9b%e4%ba%91
100
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 23, 2024
Safety Verdict

Is KODO Qiniu Safe to Use in 2026?

Generally Safe

Score 100/100

KODO Qiniu has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 23, 2024Updated 4mo ago
Risk Assessment

The "kodo-qiniu" plugin v1.5.8 exhibits a generally strong security posture based on the static analysis. It demonstrates good practices by utilizing prepared statements for all SQL queries and performing a high percentage of output escaping. Furthermore, the absence of dangerous functions, external HTTP requests, and unsanitized paths in taint flows are positive indicators.

However, a notable concern is the presence of a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability, even though it is currently patched. While the plugin shows no active vulnerabilities and the static analysis reveals a very small attack surface with no immediately apparent unprotected entry points, the historical CSRF issue suggests a potential area for future attention. The single file operation and limited nonce/capability checks, while not inherently problematic given the limited attack surface, could become risk factors if the plugin's functionality or attack surface were to expand significantly.

In conclusion, the "kodo-qiniu" plugin v1.5.8 is relatively secure, with diligent coding practices observed in its current state. The historical CSRF vulnerability is the most significant indicator of past risk and warrants continued vigilance. The minimal attack surface and the lack of critical static analysis findings are strengths, but the plugin's security should be reassessed if its features or integrations evolve.

Key Concerns

  • Past medium CVE
Vulnerabilities
1

KODO Qiniu Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-85e17f3a-cec1-41de-b3e2-ac06a9c9290f-kodo-qiniumedium · 4.3Cross-Site Request Forgery (CSRF)

KODO Qiniu <= 1.5.0 - Cross-Site Request Forgery

Feb 23, 2024 Patched in 1.5.1 (1d)
Code Analysis
Analyzed Mar 16, 2026

KODO Qiniu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
6
40 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

87% escaped46 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
kodo_setting_page (qiniu-kodo-wordpress.php:661)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

KODO Qiniu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
filterwp_get_attachment_urlqiniu-kodo-wordpress.php:196
filterwp_get_attachment_thumb_urlqiniu-kodo-wordpress.php:197
filterwp_get_original_image_urlqiniu-kodo-wordpress.php:198
filterwp_prepare_attachment_for_jsqiniu-kodo-wordpress.php:199
filterimage_get_intermediate_sizeqiniu-kodo-wordpress.php:200
filterwp_handle_uploadqiniu-kodo-wordpress.php:321
filterwp_generate_attachment_metadataqiniu-kodo-wordpress.php:322
filterwp_save_image_editor_fileqiniu-kodo-wordpress.php:323
filterwp_update_attachment_metadataqiniu-kodo-wordpress.php:400
actiondelete_attachmentqiniu-kodo-wordpress.php:474
filterwp_get_attachment_urlqiniu-kodo-wordpress.php:484
filtersanitize_file_nameqiniu-kodo-wordpress.php:500
filterplugin_action_linksqiniu-kodo-wordpress.php:550
filterwp_calculate_image_srcsetqiniu-kodo-wordpress.php:570
filterwp_prepare_attachment_for_jsqiniu-kodo-wordpress.php:572
filterthe_contentqiniu-kodo-wordpress.php:610
filterpost_thumbnail_htmlqiniu-kodo-wordpress.php:631
actionadmin_menuqiniu-kodo-wordpress.php:658
Maintenance & Trust

KODO Qiniu Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version7.1
Downloads14K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

KODO Qiniu Developer Profile

沈唁

13 plugins · 4K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
143 days
View full developer profile
Detection Fingerprints

How We Detect KODO Qiniu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
data-kodo-options
JS Globals
kodo_options
FAQ

Frequently Asked Questions about KODO Qiniu