
Kumori (曇) Security & Risk Analysis
wordpress.org/plugins/kumoriIt's a plugin that lets the users upload video files and transcode them on-the-cloud!
Is Kumori (曇) Safe to Use in 2026?
Generally Safe
Score 85/100Kumori (曇) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kumori" plugin v0.23 presents a mixed security posture. On the positive side, the static analysis reveals no known CVEs, a complete absence of dangerous functions, and a commendable 100% usage of prepared statements for its SQL queries. Furthermore, there are no external HTTP requests or cron events, and the attack surface is reported as zero. This suggests a deliberate effort to avoid common web application vulnerabilities.
However, significant concerns arise from the output escaping and taint analysis. With 0% of outputs properly escaped, the plugin is highly vulnerable to cross-site scripting (XSS) attacks. Any data displayed to users without proper sanitization could be exploited. The taint analysis also identified two flows with unsanitized paths, although these are not categorized as critical or high severity. The absence of nonce checks and capability checks, coupled with two file operations that might be susceptible if inputs are not carefully validated, warrants attention. The lack of any recorded vulnerability history could indicate either a very secure plugin or a lack of historical scrutiny.
In conclusion, while "kumori" v0.23 demonstrates good practices in areas like SQL handling and attack surface minimization, its severe deficiency in output escaping creates a significant risk of XSS vulnerabilities. The identified unsanitized paths in taint analysis, along with the absence of nonce and capability checks for its file operations, should be addressed to improve its overall security.
Key Concerns
- 0% of outputs properly escaped
- 2 flows with unsanitized paths
- No nonce checks
- No capability checks
- 2 file operations
Kumori (曇) Security Vulnerabilities
Kumori (曇) Code Analysis
Output Escaping
Data Flow Analysis
Kumori (曇) Attack Surface
WordPress Hooks 2
Maintenance & Trust
Kumori (曇) Maintenance & Trust
Maintenance Signals
Community Trust
Kumori (曇) Alternatives
WPAdmin AWS CDN
aws-cdn-by-wpadmin
Setup Amazon Cloudfront CDN for your website. Now with intuitive layout and more flexibility.
CloudSearch
cloud-search
CloudSearch is a flexible plugin that allows you to leverage the search index power of Amazon CloudSearch in your WordPress site.
Ultimate Media On The Cloud Lite
ultimate-media-on-the-cloud-lite
With Ultimate Media On The Cloud plugin, you can easy migrate/ move and mange wordpress medias on the Cloud Storage Platforms like Amazon S3, Google C …
WP2Cloud
wp2cloud-wordpress-to-cloud
Now WordPress site can store all its content (pages and media) in cloud. This makes site powered by enormous scale and reliability of cloud storage.
FrontPup
frontpup
Your AWS CloudFront companion. Clear cache and optimize your CloudFront distribution for your WordPress website
Kumori (曇) Developer Profile
1 plugin · 10 total installs
How We Detect Kumori (曇)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kumori/kumori/kumori_logo2_png24.pngHTML / DOM Fingerprints
id="gv_kumori_aws_access_id"id="gv_kumori_aws_secret_key"id="gv_kumori_aws_region"id="gv_kumori_debug_mode"