SmartSync Lite – Offload media cloud storage using AWS S3, Digital Ocean Spaces Security & Risk Analysis

wordpress.org/plugins/smartsync-lite-media-offloader-and-assets-cdn

SmartSync Lite makes it incredibly easy to offload your WordPress media library to Amazon S3 or DigitalOcean Spaces—no technical expertise required! T …

10 active installs v1.4 PHP 7.4+ WP 5.0+ Updated Nov 12, 2025
awsmediaoffloads3sync
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SmartSync Lite – Offload media cloud storage using AWS S3, Digital Ocean Spaces Safe to Use in 2026?

Generally Safe

Score 100/100

SmartSync Lite – Offload media cloud storage using AWS S3, Digital Ocean Spaces has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "smartsync-lite-media-offloader-and-assets-cdn" plugin v1.4 exhibits a generally strong security posture with notable good practices. The absence of any recorded vulnerabilities and the high percentage of properly escaped outputs are positive indicators. Furthermore, the plugin effectively utilizes prepared statements for all SQL queries, mitigating the risk of SQL injection. The static analysis also reveals a good number of nonce checks and no critical or high severity taint flows, suggesting careful coding in these areas.

However, there are specific concerns that warrant attention. The plugin exposes 15 AJAX handlers, with two of them lacking authentication checks. This represents a direct entry point for potential attackers to interact with the plugin's functionality without proper authorization. While there are no recorded CVEs, indicating a clean history, this does not negate the risks identified in the current static analysis. The limited number of capability checks is also a potential area for improvement, as robust capability checks are crucial for fine-grained access control.

In conclusion, while the plugin demonstrates several strengths in secure coding practices, the unprotected AJAX handlers are a significant risk that needs to be addressed. The absence of historical vulnerabilities is encouraging, but proactive security measures, particularly in securing all entry points, are essential for maintaining a secure application. Addressing the unauthenticated AJAX handlers should be the priority to improve the plugin's overall security.

Key Concerns

  • Unprotected AJAX handlers
  • Lack of capability checks
Vulnerabilities
None known

SmartSync Lite – Offload media cloud storage using AWS S3, Digital Ocean Spaces Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SmartSync Lite – Offload media cloud storage using AWS S3, Digital Ocean Spaces Release Timeline

v1.4Current
Code Analysis
Analyzed Apr 16, 2026

SmartSync Lite – Offload media cloud storage using AWS S3, Digital Ocean Spaces Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
4
278 escaped
Nonce Checks
13
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared3 total queries

Output Escaping

99% escaped282 total outputs
Attack Surface
2 unprotected

SmartSync Lite – Offload media cloud storage using AWS S3, Digital Ocean Spaces Attack Surface

Entry Points15
Unprotected2

AJAX Handlers 15

authwp_ajax_clear_cloudfront_cachesrc/Ajax/SMARL_AjaxHandler.php:67
authwp_ajax_toggle_cdnsrc/Ajax/SMARL_AjaxHandler.php:68
authwp_ajax_toggle_media_auto_deletesrc/Ajax/SMARL_AjaxHandler.php:69
authwp_ajax_sync_local_to_awssrc/Ajax/SMARL_AjaxHandler.php:70
authwp_ajax_stop_all_processessrc/Ajax/SMARL_AjaxHandler.php:71
authwp_ajax_sync_aws_to_localsrc/Ajax/SMARL_AjaxHandler.php:73
authwp_ajax_set_sync_statesrc/Ajax/SMARL_AjaxHandler.php:74
authwp_ajax_get_sync_statesrc/Ajax/SMARL_AjaxHandler.php:75
authwp_ajax_check_sync_statussrc/Ajax/SMARL_AjaxHandler.php:76
authwp_ajax_fetch_aws_analyticssrc/Ajax/SMARL_AjaxHandler.php:77
authwp_ajax_check_dns_recordsrc/Ajax/SMARL_AwsConfigAjax.php:116
authwp_ajax_generate_ssl_certificatesrc/Ajax/SMARL_AwsConfigAjax.php:117
authwp_ajax_list_s3_bucketssrc/Ajax/SMARL_AwsConfigAjax.php:118
authwp_ajax_configure_awssrc/Ajax/SMARL_AwsConfigAjax.php:119
authwp_ajax_attach_to_cloudfrontsrc/Ajax/SMARL_AwsConfigAjax.php:120
WordPress Hooks 14
filterupload_mimesaws-s3-smartsync-wp.php:42
actionprocess_s3_sync_batchsrc/Ajax/SMARL_AjaxHandler.php:72
filterscript_loader_srcsrc/SMARL_SmartSync.php:101
filterstyle_loader_srcsrc/SMARL_SmartSync.php:102
filterwp_get_attachment_urlsrc/SMARL_SmartSync.php:104
filterwp_delete_filesrc/SMARL_SmartSync.php:105
actionactivated_pluginsrc/SMARL_SmartSync.php:112
actionadd_attachmentsrc/SMARL_SmartSync.php:113
actionadmin_enqueue_scriptssrc/SMARL_SmartSync.php:116
actionplugins_loadedsrc/SMARL_SmartSync.php:124
filterwp_generate_attachment_metadatasrc/SMARL_SmartSync.php:453
actionadmin_menusrc/Views/SMARL_AWSWizard.php:19
actionadmin_menusrc/Views/SMARL_CustomUrl.php:19
actionadmin_menusrc/Views/SMARL_SettingsPage.php:19
Maintenance & Trust

SmartSync Lite – Offload media cloud storage using AWS S3, Digital Ocean Spaces Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 12, 2025
PHP min version7.4
Downloads661

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

SmartSync Lite – Offload media cloud storage using AWS S3, Digital Ocean Spaces Developer Profile

Infinitie Technologies

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SmartSync Lite – Offload media cloud storage using AWS S3, Digital Ocean Spaces

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smartsync-lite-media-offloader-and-assets-cdn/assets/css/smartsync.css/wp-content/plugins/smartsync-lite-media-offloader-and-assets-cdn/assets/js/smartsync.js/wp-content/plugins/smartsync-lite-media-offloader-and-assets-cdn/assets/js/vue.js/wp-content/plugins/smartsync-lite-media-offloader-and-assets-cdn/assets/js/app.js/wp-content/plugins/smartsync-lite-media-offloader-and-assets-cdn/assets/js/pages/SettingsPage.js
Script Paths
/wp-content/plugins/smartsync-lite-media-offloader-and-assets-cdn/assets/js/smartsync.js/wp-content/plugins/smartsync-lite-media-offloader-and-assets-cdn/assets/js/vue.js/wp-content/plugins/smartsync-lite-media-offloader-and-assets-cdn/assets/js/app.js/wp-content/plugins/smartsync-lite-media-offloader-and-assets-cdn/assets/js/pages/SettingsPage.js
Version Parameters
smartsync-lite-media-offloader-and-assets-cdn/assets/css/smartsync.css?ver=smartsync-lite-media-offloader-and-assets-cdn/assets/js/smartsync.js?ver=smartsync-lite-media-offloader-and-assets-cdn/assets/js/vue.js?ver=smartsync-lite-media-offloader-and-assets-cdn/assets/js/app.js?ver=smartsync-lite-media-offloader-and-assets-cdn/assets/js/pages/SettingsPage.js?ver=

HTML / DOM Fingerprints

CSS Classes
smartsync-settings-pagesmartsync-wizard-pagesmartsync-wizard-step
Data Attributes
data-smartsync-config
JS Globals
smartsync_ajax_object
FAQ

Frequently Asked Questions about SmartSync Lite – Offload media cloud storage using AWS S3, Digital Ocean Spaces