
Offload Videos – Bunny.net, AWS S3 Security & Risk Analysis
wordpress.org/plugins/offload-videos-bunny-netaws-s3Upload videos to Bunny.net and AWS S3 storage via using bunny streaming API's and AWS SDK services
Is Offload Videos – Bunny.net, AWS S3 Safe to Use in 2026?
Generally Safe
Score 91/100Offload Videos – Bunny.net, AWS S3 has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'offload-videos-bunny-netaws-s3' plugin v1.0.2 presents a generally good security posture, with no critical or high severity issues identified in static and taint analysis. The plugin demonstrates strong adherence to secure coding practices by using prepared statements for all SQL queries and a high percentage of proper output escaping. The absence of unsanitized paths in taint flows is also a positive indicator. The plugin's attack surface is well-protected, with all identified entry points (AJAX handlers, REST API routes, shortcodes) appearing to have authentication checks in place.
However, there are a few areas for improvement. The presence of two dangerous functions, 'shell_exec' and 'move_uploaded_file', warrants careful scrutiny, especially in how they are implemented and if user input can influence their behavior. While the taint analysis did not reveal vulnerabilities related to these functions, their mere presence increases the potential risk profile. The plugin's vulnerability history, while currently showing no unpatched vulnerabilities, does include one medium severity CVE. The common type of this past vulnerability being Cross-Site Request Forgery (CSRF) suggests a need for robust nonce checking on all relevant actions, even if the current analysis shows a moderate number of nonce checks.
In conclusion, the plugin has a solid foundation of secure coding. The primary concerns stem from the potential misuse of dangerous functions and the historical presence of CSRF vulnerabilities, which requires ongoing vigilance. The plugin's strengths lie in its SQL handling and output escaping. The plugin is relatively secure but could benefit from a deeper review of the usage of 'shell_exec' and 'move_uploaded_file' and reinforcing CSRF protections.
Key Concerns
- Presence of dangerous function: shell_exec
- Presence of dangerous function: move_uploaded_file
- Past medium severity CVE (CSRF)
- Moderate number of nonce checks
Offload Videos – Bunny.net, AWS S3 Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Offload Videos – Bunny.net, AWS S3 <= 1.0.0 - Cross-Site Request Forgery
Offload Videos – Bunny.net, AWS S3 Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Offload Videos – Bunny.net, AWS S3 Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Offload Videos – Bunny.net, AWS S3 Maintenance & Trust
Maintenance Signals
Community Trust
Offload Videos – Bunny.net, AWS S3 Alternatives
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
Media Cloud for Bunny CDN, Amazon S3, Cloudflare R2, Google Cloud Storage, DigitalOcean and more
ilab-media-tools
Automatically store media on Amazon S3, Cloudflare R2, Google Cloud Storage, DigitalOcean Spaces + others. Serve CSS/JS assets through CDNs.
C3 Cloudfront Cache Controller
c3-cloudfront-clear-cache
This is simple plugin that clear all cloudfront cache if you publish posts.
SMTP for Amazon SES – YaySMTP
smtp-amazon-ses
Send WordPress emails through Amazon SES server using YaySMTP
Replace Google Fonts with Bunny Fonts
replace-google-fonts-with-bunny-fonts
Replace Google Fonts with Bunny Fonts in the HTML Markup of your WordPress site.
Offload Videos – Bunny.net, AWS S3 Developer Profile
2 plugins · 20 total installs
How We Detect Offload Videos – Bunny.net, AWS S3
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/offload-videos-bunny-netaws-s3/admin/css/offload-video-admin.css/wp-content/plugins/offload-videos-bunny-netaws-s3/admin/js/offload-video-admin.js/wp-content/plugins/offload-videos-bunny-netaws-s3/admin/js/offload-video-admin.jsoffload-videos-bunny-netaws-s3/admin/css/offload-video-admin.css?ver=offload-videos-bunny-netaws-s3/admin/js/offload-video-admin.js?ver=HTML / DOM Fingerprints
<!-- Admin settings page content --><!-- Update & save Api settings -->window.offloadvideos