
STN- SAVE TO NEXTCLOUD Security & Risk Analysis
wordpress.org/plugins/stn-save-to-nextcloudCe plugin est un outil simple et efficace pour sauvegarder votre site WordPress et sa base de données directement sur votre compte NextCloud.
Is STN- SAVE TO NEXTCLOUD Safe to Use in 2026?
Generally Safe
Score 92/100STN- SAVE TO NEXTCLOUD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The stn-save-to-nextcloud plugin exhibits significant security concerns primarily due to its unprotected entry points. The static analysis reveals two REST API routes that lack permission callbacks, meaning any authenticated user, regardless of their role or capabilities, could potentially interact with these endpoints. This presents a substantial attack surface that is not adequately secured. While the plugin appears to avoid dangerous functions and has a decent percentage of output escaping, the complete absence of nonce checks and capability checks across all identified entry points is a major weakness. The plugin also performs file operations and external HTTP requests, which, when combined with the unprotected entry points, could be exploited for various malicious activities if these operations are not properly validated and secured within the API routes.
The plugin's vulnerability history is currently clean, with no known CVEs or recorded vulnerabilities. This is a positive indicator, suggesting that developers may have a good understanding of secure coding practices or that the plugin has not been a target of significant past exploitation. However, the lack of historical vulnerabilities does not negate the immediate risks identified in the code analysis. The absence of taint analysis results could mean that either the tool was not run or no significant untrusted data flows were detected, but this doesn't provide strong assurance on its own. The current security posture is concerning due to the identified unprotected endpoints, despite the otherwise clean record.
Key Concerns
- REST API routes without permission callbacks
- No nonce checks on entry points
- No capability checks on entry points
- SQL queries with no prepared statements (44% prepared)
- Some output not properly escaped (87% escaped)
STN- SAVE TO NEXTCLOUD Security Vulnerabilities
STN- SAVE TO NEXTCLOUD Code Analysis
SQL Query Safety
Output Escaping
STN- SAVE TO NEXTCLOUD Attack Surface
REST API Routes 2
WordPress Hooks 22
Scheduled Events 9
Maintenance & Trust
STN- SAVE TO NEXTCLOUD Maintenance & Trust
Maintenance Signals
Community Trust
STN- SAVE TO NEXTCLOUD Alternatives
Luzid Backup to Nextcloud
luzid-backup-to-nextcloud
Upload WordPress backup files to Nextcloud via WebDAV, with optional rotation and retention management.
Imsanity
imsanity
Automatically resizes huge image uploads. Are contributors uploading huge photos? Tired of manually resizing your images? Imsanity to the rescue!
PNG to JPG
png-to-jpg
Convert PNG images to JPG, free up web space and speed up your webpage
DEPRECATED – Shipmondo – A complete shipping solution for WooCommerce
pakkelabels-for-woocommerce
Shipmondo for WooCommerce – Provide pick-up points in checkout and manage shipping easily
Toolbar Publish Button
toolbar-publish-button
Scroll less in WordPress admin area! A small UX improvement will keep Publish button within reach and retain the scrollbar position after saving.
STN- SAVE TO NEXTCLOUD Developer Profile
1 plugin · 70 total installs
How We Detect STN- SAVE TO NEXTCLOUD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stn-save-to-nextcloud/inc/stn-save-to-nextcloud.css/wp-content/plugins/stn-save-to-nextcloud/inc/stn-save-to-nextcloud.jsstn-save-to-nextcloud/inc/stn-save-to-nextcloud.css?ver=stn-save-to-nextcloud/inc/stn-save-to-nextcloud.js?ver=HTML / DOM Fingerprints
stn-save-to-nextcloud-status<!-- STN - Save To Nextcloud -->data-stn-actiondata-stn-targetdata-stn-filenamedata-stn-nextcloud-urlstn_save_to_nextcloud_params