OBS HuaWeiCloud Security & Risk Analysis

wordpress.org/plugins/obs-huaweicloud

使用华为云对象存储服务 OBS 作为附件存储空间。(This is a plugin that uses HuaWei Cloud Object Storage Service for attachments remote saving.)

10 active installs v1.4.3 PHP 7.2+ WP 4.6+ Updated Dec 5, 2025
huaweiobs%e5%8d%8e%e4%b8%ba%e4%ba%91%e5%af%b9%e8%b1%a1%e5%ad%98%e5%82%a8
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OBS HuaWeiCloud Safe to Use in 2026?

Generally Safe

Score 100/100

OBS HuaWeiCloud has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "obs-huaweicloud" plugin v1.4.3 demonstrates a strong security posture based on the static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. Furthermore, the plugin utilizes prepared statements for all its SQL queries and includes a nonce check and capability check, which are good practices for preventing common web vulnerabilities. The fact that there are no recorded vulnerabilities (CVEs) further supports this positive assessment.

However, a notable concern arises from the output escaping analysis, where 32% of outputs are not properly escaped. While the taint analysis did not reveal any unsanitized paths, unescaped output can still lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly into the HTML without proper sanitization. The presence of the Guzzle library, while common for HTTP requests, also warrants attention; if this library is outdated or has known vulnerabilities, it could introduce risks, though external HTTP requests were not observed in the static analysis.

In conclusion, the "obs-huaweicloud" plugin v1.4.3 appears to be generally well-secured, with a commendable lack of critical code issues and a clean vulnerability history. The primary area for improvement lies in ensuring all output is consistently and correctly escaped to mitigate potential XSS risks. The bundled Guzzle library should also be monitored for any security advisories.

Key Concerns

  • Unescaped output found
Vulnerabilities
None known

OBS HuaWeiCloud Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

OBS HuaWeiCloud Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
10
21 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared4 total queries

Output Escaping

68% escaped31 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
obs_setting_page (huaweicloud-obs-wordpress.php:425)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

OBS HuaWeiCloud Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterwp_handle_uploadhuaweicloud-obs-wordpress.php:200
filterwp_generate_attachment_metadatahuaweicloud-obs-wordpress.php:201
actiondelete_attachmenthuaweicloud-obs-wordpress.php:307
filterwp_get_attachment_urlhuaweicloud-obs-wordpress.php:317
filtersanitize_file_namehuaweicloud-obs-wordpress.php:332
filterplugin_action_linkshuaweicloud-obs-wordpress.php:414
actionadmin_menuhuaweicloud-obs-wordpress.php:422
Maintenance & Trust

OBS HuaWeiCloud Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version7.2
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

OBS HuaWeiCloud Developer Profile

沈唁

13 plugins · 4K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
143 days
View full developer profile
Detection Fingerprints

How We Detect OBS HuaWeiCloud

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/obs-huaweicloud/sdk/vendor/composer/ClassLoader.php/wp-content/plugins/obs-huaweicloud/sdk/vendor/obs/obs-sdk-php/src/Obs/ObsClient.php/wp-content/plugins/obs-huaweicloud/sdk/vendor/obs/obs-sdk-php/src/Obs/ObsException.php
Version Parameters
obs-huaweicloud/style.css?ver=obs-huaweicloud/script.js?ver=

HTML / DOM Fingerprints

JS Globals
ObsClientObsExceptionobs_get_default_optionsobs_set_optionsobs_get_clientobs_get_bucket_endpoint+10 more
FAQ

Frequently Asked Questions about OBS HuaWeiCloud