
Publitio Offloading Security & Risk Analysis
wordpress.org/plugins/publitio-offloadingPublitio Offloading plugin automatically transfers and serves your images, videos, audios, documents, and archives from Publitio’s cloud storage and C …
Is Publitio Offloading Safe to Use in 2026?
Generally Safe
Score 100/100Publitio Offloading has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The publitio-offloading plugin version 1.2.9 exhibits a generally good security posture with several strengths. A significant positive is the complete absence of direct SQL injection vulnerabilities, with all queries utilizing prepared statements. Furthermore, the plugin demonstrates strong output escaping practices, with 94% of outputs properly escaped, and a good number of nonce and capability checks are implemented. The vulnerability history is also clean, with no recorded CVEs, indicating a potentially mature and well-maintained codebase.
However, there are notable concerns that detract from its overall security. The presence of 7 AJAX handlers, with 3 of them lacking authentication checks, presents a substantial attack surface. These unprotected entry points could potentially be exploited by unauthenticated users to trigger unintended actions within the plugin. While taint analysis did not reveal any critical or high-severity issues, the lack of explicit checks on these AJAX handlers leaves them vulnerable to various attacks if malicious data is passed through them.
In conclusion, while the plugin benefits from strong data handling practices and a clean vulnerability history, the exposed AJAX handlers represent a critical weakness that needs immediate attention. The absence of vulnerabilities in its history is positive, but the current static analysis highlights a clear area for improvement to mitigate potential risks.
Key Concerns
- Unprotected AJAX handlers
- Bundled outdated library (Guzzle may be outdated)
Publitio Offloading Security Vulnerabilities
Publitio Offloading Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Publitio Offloading Attack Surface
AJAX Handlers 7
WordPress Hooks 14
Maintenance & Trust
Publitio Offloading Maintenance & Trust
Maintenance Signals
Community Trust
Publitio Offloading Alternatives
Publitio
publitio
Publitio plugin integrates Publitio cloud media into WordPress with a simple block for effortless uploading, browsing, and embedding of image, video, …
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider
ml-slider
Slider, gallery, carousel plugin for WordPress. Build your image slider, video slider, post slider, YouTube slider, or WooCommerce product slider.
Prime Slider – Addons for Elementor
bdthemes-prime-slider-lite
Create responsive sliders using Elementor for hero sections, posts, logos, images, products, testimonials, and more.
Modula Image Gallery – Photo Grid & Video Gallery
modula-best-grid-gallery
Create responsive image galleries with drag-and-drop grid builder. Custom layouts, video support, AI optimization. Works with any theme.
Featured Image from URL (FIFU)
featured-image-from-url
Use remote media as the featured image and beyond.
Publitio Offloading Developer Profile
2 plugins · 600 total installs
How We Detect Publitio Offloading
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/publitio-offloading/admin/css/offloading-style.css/wp-content/plugins/publitio-offloading/admin/js/offloading-script.jshttps://cdn.jsdelivr.net/npm/toastify-js/src/toastify.min.csshttps://cdn.jsdelivr.net/npm/toastify-jsHTML / DOM Fingerprints
pwpo-text-greendata-folder-idPWPO_Admin_Params/wp-json/pwpo/v1/settings[publitio_media url="