
Offload Media – Cloud Storage Security & Risk Analysis
wordpress.org/plugins/offload-media-cloud-storageOffload Media moves your WordPress files to cloud storage (AWS S3, DigitalOcean, Cloudflare R2, Google Cloud) to improve site performance.
Is Offload Media – Cloud Storage Safe to Use in 2026?
Generally Safe
Score 100/100Offload Media – Cloud Storage has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "offload-media-cloud-storage" plugin v1.7.0 exhibits a generally strong security posture based on the provided static analysis. A significant positive is the complete absence of known CVEs, indicating a history of responsible development or lack of significant past vulnerabilities. The plugin also demonstrates good practices in its entry points, with only one AJAX handler identified and importantly, no unprotected entry points were found. Furthermore, a high percentage of output is properly escaped, and SQL queries predominantly use prepared statements, which are crucial for preventing common web vulnerabilities.
However, there are a few areas that warrant attention. The presence of 15 instances of the `unserialize` function is a notable concern. While not explicitly identified as a vulnerability in the taint analysis (which reported zero flows with unsanitized paths), `unserialize` can be a vector for remote code execution if the serialized data originates from an untrusted source and is not strictly validated. The limited number of capability checks (only 2) and a single nonce check on the single AJAX handler also suggest a potential area for improvement in access control, though the absence of unprotected entry points is reassuring.
Overall, the plugin appears to be developed with security in mind, particularly in its handling of entry points and data sanitization for outputs and SQL. The lack of past vulnerabilities and the current clean bill of health from taint analysis are positive indicators. The primary area for scrutiny is the use of `unserialize` and ensuring the data processed by it is always rigorously validated before deserialization. The minimal capability and nonce checks, while not a direct vulnerability in this version, represent a potential weakness that could be exploited if other security measures were to fail.
Key Concerns
- Use of unserialize function detected
- Limited capability checks
- Single nonce check on AJAX handler
Offload Media – Cloud Storage Security Vulnerabilities
Offload Media – Cloud Storage Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Offload Media – Cloud Storage Attack Surface
AJAX Handlers 1
WordPress Hooks 35
Maintenance & Trust
Offload Media – Cloud Storage Maintenance & Trust
Maintenance Signals
Community Trust
Offload Media – Cloud Storage Alternatives
Cloud Uploads Pro – Offload Media and Video to Cloud Storage
cloud-uploads-pro
Move, encode, and serve all your video and other media files from the cloud to boost performance and save on storage.
Swift Offload
swift-offload
Offload WordPress media to Amazon S3, Wasabi, DigitalOcean Spaces, or MinIO. Serve files via CloudFront CDN for faster delivery.
TP Media Offload & Edge CDN
tp-media-offload-edge-cdn
Offload WordPress media to Cloudflare R2 storage and serve via CDN with automatic image optimization.
Media Cloud for Bunny CDN, Amazon S3, Cloudflare R2, Google Cloud Storage, DigitalOcean and more
ilab-media-tools
Automatically store media on Amazon S3, Cloudflare R2, Google Cloud Storage, DigitalOcean Spaces + others. Serve CSS/JS assets through CDNs.
Advanced Media Offloader
advanced-media-offloader
Save server space & speed up your site by automatically offloading media to Amazon S3, Cloudflare R2 & more.
Offload Media – Cloud Storage Developer Profile
13 plugins · 74K total installs
How We Detect Offload Media – Cloud Storage
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/offload-media-cloud-storage/assets/css/backend.css/wp-content/plugins/offload-media-cloud-storage/assets/css/acoofm.css/wp-content/plugins/offload-media-cloud-storage/assets/js/backend.js/wp-content/plugins/offload-media-cloud-storage/assets/js/acoofm.js/wp-content/plugins/offload-media-cloud-storage/assets/js/backend.js/wp-content/plugins/offload-media-cloud-storage/assets/js/acoofm.jsoffload-media-cloud-storage/assets/css/backend.css?ver=offload-media-cloud-storage/assets/css/acoofm.css?ver=offload-media-cloud-storage/assets/js/backend.js?ver=offload-media-cloud-storage/assets/js/acoofm.js?ver=HTML / DOM Fingerprints
acoofm-backend-pageacoofm-admin-ui<!--Offload Media - Cloud Storage Options--><!-- ACOOFM activation survey--><!-- ACOOFM deactivation survey-->data-acoofm-upload-iddata-acoofm-urldata-acoofm-serviceACOOFMacoofm_params/wp-json/acoofmf/v1/media/upload