
Plugin Name: oQey Pdfs Security & Risk Analysis
wordpress.org/plugins/oqey-pdfsoQey Pdfs plugin is a Wordpress Plugin that allows to add and manage protected pdf files.
Is Plugin Name: oQey Pdfs Safe to Use in 2026?
Generally Safe
Score 85/100Plugin Name: oQey Pdfs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'oqey-pdfs' plugin, version 0.1, exhibits a concerning security posture despite having a seemingly small attack surface and no known historical vulnerabilities. The static analysis reveals significant weaknesses, particularly in how the plugin handles data. All SQL queries are executed without prepared statements, indicating a high risk of SQL injection vulnerabilities. Furthermore, none of the observed output operations are properly escaped, presenting a strong likelihood of cross-site scripting (XSS) flaws. The taint analysis highlights critical issues with three data flows containing unsanitized paths, with two classified as high severity. This suggests that user-supplied data could potentially be manipulated to execute malicious code or access sensitive information.
While the absence of known CVEs and a minimal attack surface are positive indicators, the fundamental lack of secure coding practices in data handling overshadows these strengths. The complete absence of nonce and capability checks, coupled with the unescaped output and raw SQL queries, makes this plugin highly vulnerable to common web attacks. The presence of unsanitized paths in taint flows, even without critical severity, is a serious concern that directly impacts the integrity and security of the WordPress installation. This plugin requires immediate attention to address these critical security flaws.
Key Concerns
- SQL queries without prepared statements
- Unescaped output operations
- High severity taint flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
- Taint flows with unsanitized paths
Plugin Name: oQey Pdfs Security Vulnerabilities
Plugin Name: oQey Pdfs Release Timeline
Plugin Name: oQey Pdfs Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Plugin Name: oQey Pdfs Attack Surface
WordPress Hooks 3
Maintenance & Trust
Plugin Name: oQey Pdfs Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Name: oQey Pdfs Alternatives
AAM Protected Media Files
aam-protected-media-files
Add-on to the free Advanced Access Manager plugin that protects media files from direct access for visitors, roles or users
Get Filesize Shortcode
get-filesize-shortcode
"Get Filesize Shortcode" is a simple shortcode to get filesize of a file( eg. PDF, JPG, PNG ... ).
ACF My Media Cluster
acf-my-media-cluster
ACF My Media Cluster is an extension for the Advance Custom Fields plugin, which adds the ability to create groups of media files for download on a pa …
Zodan Authorized Downloads
z-authorized-downloads
Protect documents from unauthorized download.
PDF Embedder
pdf-embedder
Seamlessly embed PDFs into your content, with customizations and intelligent responsive resizing, and no third-party services or iframes.
Plugin Name: oQey Pdfs Developer Profile
5 plugins · 60 total installs
How We Detect Plugin Name: oQey Pdfs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oqey-pdfs/pdfd.css/wp-content/plugins/oqey-pdfs/pdfd.css?ver=HTML / DOM Fingerprints
pdfdname="downloadFormid="parolapdf<form name="downloadForm<input type="password" name="parolapdf<a href="#" onclick="document.downloadForm