
Smart WeTransfer Security & Risk Analysis
wordpress.org/plugins/smart-wetransferUpload large files upto 2GB using this plugin. This plugin uses wetransfer API and all uploads are saved in wetransfer website for 7 days.
Is Smart WeTransfer Safe to Use in 2026?
Use With Caution
Score 63/100Smart WeTransfer has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "smart-wetransfer" v1.3 plugin exhibits several concerning security weaknesses despite some positive indicators. The presence of an unprotected AJAX handler significantly increases the attack surface, as this entry point lacks proper authentication checks, making it vulnerable to unauthorized access and potential exploitation. While the code analysis indicates a lack of dangerous functions and file operations, the fact that 100% of SQL queries are not using prepared statements is a major concern, as it opens the door to SQL injection vulnerabilities. Furthermore, the plugin has a history of known vulnerabilities, including a currently unpatched medium severity issue, which suggests a pattern of security oversight in its development and maintenance. While the plugin does perform some output escaping, the percentage is not high enough to fully mitigate cross-site scripting (XSS) risks in the remaining unescaped outputs.
Key Concerns
- Unprotected AJAX handler found
- 100% of SQL queries lack prepared statements
- Unpatched medium severity CVE found
- Missing nonce checks
- Only 58% of output properly escaped
Smart WeTransfer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Smart WeTransfer <= 1.3 - Missing Authorization
Smart WeTransfer Code Analysis
SQL Query Safety
Output Escaping
Smart WeTransfer Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Smart WeTransfer Maintenance & Trust
Maintenance Signals
Community Trust
Smart WeTransfer Alternatives
No alternatives data available yet.
Smart WeTransfer Developer Profile
2 plugins · 80 total installs
How We Detect Smart WeTransfer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smart-wetransfer/includes/style.css/wp-content/plugins/smart-wetransfer/includes/script.jshttps://prod-embed-cdn.wetransfer.net/v1/latest.jssmart-wetransfer/includes/style.css?ver=smart-wetransfer/includes/script.js?ver=HTML / DOM Fingerprints
form-controlbtnbtn-primarygrit-styletableerrorThe next input element will hold the transfer link. For testing purposes, you
could change the type attribute to "text", instead of "hidden".data-widget-hostwtEmbedKeywtEmbedOutputwtEmbedLanguageWETRANSFER_PLUGIN_PATH<h3 style='color:green'><span class="error"><input type='text' name='your_name' class='form-control' placeholder='Your Name'><input type='email' name='your_email' class='form-control' placeholder='Your Email' required>