MaxUpload – Upload Larger Files Easily Security & Risk Analysis

wordpress.org/plugins/maxupload-upload-larger-files-easily

Upload large files easily with chunked uploads and server limit customization.

50 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Oct 14, 2025
chunked-uploadfile-uploadlarge-filesmedia-libraryserver-limits
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MaxUpload – Upload Larger Files Easily Safe to Use in 2026?

Generally Safe

Score 100/100

MaxUpload – Upload Larger Files Easily has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

This plugin, maxupload-upload-larger-files-easily v1.0.0, exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and the absence of critical or high-severity taint flows are positive indicators. The plugin also demonstrates good practices by exclusively using prepared statements for SQL queries and implementing nonce and capability checks on its entry points. However, there are areas that warrant caution. A significant concern is the relatively low percentage of properly escaped output (61%). This suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, particularly if user-supplied data is being displayed without adequate sanitization or escaping. While the attack surface is small and appears to be protected, the reliance on escaping for output sanitization presents a potential weakness that could be exploited if not meticulously implemented across all output locations. The limited history and zero known vulnerabilities might be due to the plugin's simplicity or a lack of deep security review. Therefore, while the plugin shows promise, the unescaped output is the primary area of concern that necessitates careful review and remediation.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

MaxUpload – Upload Larger Files Easily Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MaxUpload – Upload Larger Files Easily Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
50
79 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

61% escaped129 total outputs
Attack Surface

MaxUpload – Upload Larger Files Easily Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_maxu82up_upload_fileincludes\uploader.php:18
noprivwp_ajax_maxu82up_upload_fileincludes\uploader.php:19

Shortcodes 1

[maxu82up_big_upload] maxupload-wp.php:26
WordPress Hooks 5
actionadmin_menuincludes\settings.php:6
actionadmin_initincludes\settings.php:18
actionmaxu82up_cleanup_chunksincludes\uploader.php:20
actioninitmaxupload-wp.php:25
actionadmin_enqueue_scriptsmaxupload-wp.php:29

Scheduled Events 1

maxu82up_cleanup_chunks
Maintenance & Trust

MaxUpload – Upload Larger Files Easily Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 14, 2025
PHP min version7.4
Downloads569

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

MaxUpload – Upload Larger Files Easily Developer Profile

Sadat Himel

4 plugins · 250 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MaxUpload – Upload Larger Files Easily

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/maxupload-upload-larger-files-easily/assets/css/bootstrap.min.css/wp-content/plugins/maxupload-upload-larger-files-easily/assets/css/all.min.css/wp-content/plugins/maxupload-upload-larger-files-easily/assets/style.css/wp-content/plugins/maxupload-upload-larger-files-easily/assets/resumable.min.js/wp-content/plugins/maxupload-upload-larger-files-easily/assets/script.js/wp-content/plugins/maxupload-upload-larger-files-easily/assets/media-replace.js/wp-content/plugins/maxupload-upload-larger-files-easily/assets/js/bootstrap.bundle.min.js/wp-content/plugins/maxupload-upload-larger-files-easily/assets/settings.js
Script Paths
/wp-content/plugins/maxupload-upload-larger-files-easily/assets/resumable.min.js/wp-content/plugins/maxupload-upload-larger-files-easily/assets/script.js/wp-content/plugins/maxupload-upload-larger-files-easily/assets/media-replace.js/wp-content/plugins/maxupload-upload-larger-files-easily/assets/js/bootstrap.bundle.min.js/wp-content/plugins/maxupload-upload-larger-files-easily/assets/settings.js
Version Parameters
/wp-content/plugins/maxupload-upload-larger-files-easily/assets/css/bootstrap.min.css?ver=/wp-content/plugins/maxupload-upload-larger-files-easily/assets/css/all.min.css?ver=/wp-content/plugins/maxupload-upload-larger-files-easily/assets/style.css?ver=/wp-content/plugins/maxupload-upload-larger-files-easily/assets/resumable.min.js?ver=/wp-content/plugins/maxupload-upload-larger-files-easily/assets/script.js?ver=/wp-content/plugins/maxupload-upload-larger-files-easily/assets/media-replace.js?ver=/wp-content/plugins/maxupload-upload-larger-files-easily/assets/js/bootstrap.bundle.min.js?ver=/wp-content/plugins/maxupload-upload-larger-files-easily/assets/settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
maxu82up_shortcode-uploadermaxu82up_error
Data Attributes
data-max-sizedata-allowed-types
JS Globals
maxu82up_ajaxmaxu82up_settings
Shortcode Output
<div class="maxu82up_shortcode-uploader"
FAQ

Frequently Asked Questions about MaxUpload – Upload Larger Files Easily