UCM Files Manager Addon (UCM FM) Security & Risk Analysis

wordpress.org/plugins/ucm-files-manager-ucm-fm

UCM Files Manager (UCM FM) is an addon for Ultimate Media On The Cloud Plugin! https://wordpress.org/plugins/ultimate-media-on-the-cloud-lite/ With UC …

0 active installs v1.1 PHP 5.5+ WP 4.0.0+ Updated Oct 21, 2019
elfinder-file-managerfiles-managerinline-file-managerwp-file-manager
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is UCM Files Manager Addon (UCM FM) Safe to Use in 2026?

Generally Safe

Score 85/100

UCM Files Manager Addon (UCM FM) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of ucm-files-manager-ucm-fm v1.1 reveals a concerning security posture despite a seemingly small attack surface. While there are no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed, the presence of the `unserialize` function five times is a significant red flag. The complete lack of output escaping on all identified outputs further exacerbates this risk, as it creates a high probability of cross-site scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on any potential entry points is also a serious oversight, leaving the plugin vulnerable to unauthorized actions.

Key Concerns

  • Dangerous function 'unserialize' used 5 times
  • 100% of outputs not properly escaped
  • 0 Nonce checks found
  • 0 Capability checks found
Vulnerabilities
None known

UCM Files Manager Addon (UCM FM) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

UCM Files Manager Addon (UCM FM) Code Analysis

Dangerous Functions
5
Raw SQL Queries
0
0 prepared
Unescaped Output
17
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

unserialize$account_data = unserialize($account['value']);includes\classes\PhpRockets_UCM_FileManager_AddOn.php:147
unserialize$account_data = unserialize($account['value']);includes\classes\PhpRockets_UCM_FileManager_AddOn.php:1300
unserialize$account_data = unserialize($args['account']['value']);includes\classes\PhpRockets_UCM_FileManager_AddOn.php:1564
unserialize$account_data = unserialize($account['value']);includes\classes\PhpRockets_UCM_FileManager_AddOn.php:1612
unserialize$account_data = unserialize($account['value']);includes\tpl\fm_main.php:5

Bundled Libraries

TinyMCE

Output Escaping

0% escaped17 total outputs
Attack Surface

UCM Files Manager Addon (UCM FM) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
filteralter_register_ucm_assetincludes\classes\PhpRockets_UCM_FileManager_AddOn.php:64
filterucm_fm_general_formincludes\classes\PhpRockets_UCM_FileManager_AddOn.php:120
filterucm_fm_roles_formincludes\classes\PhpRockets_UCM_FileManager_AddOn.php:121
filterucm_fm_ui_formincludes\classes\PhpRockets_UCM_FileManager_AddOn.php:122
filterucm_fm_file_type_formincludes\classes\PhpRockets_UCM_FileManager_AddOn.php:123
filterucm_fm_image_editors_formincludes\classes\PhpRockets_UCM_FileManager_AddOn.php:124
filterucm_fm_code_editors_formincludes\classes\PhpRockets_UCM_FileManager_AddOn.php:125
filterucm_fm_advanced_formincludes\classes\PhpRockets_UCM_FileManager_AddOn.php:126
filterucm_fm_initincludes\classes\PhpRockets_UCM_FileManager_AddOn.php:152
filterucm_fm_styleincludes\classes\PhpRockets_UCM_FileManager_AddOn.php:176
filterucm_fm_requireincludes\classes\PhpRockets_UCM_FileManager_AddOn.php:177
filterucm_fm_other_placesincludes\classes\PhpRockets_UCM_FileManager_AddOn.php:1276
Maintenance & Trust

UCM Files Manager Addon (UCM FM) Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedOct 21, 2019
PHP min version5.5
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

UCM Files Manager Addon (UCM FM) Developer Profile

PhpRockets Team

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect UCM Files Manager Addon (UCM FM)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ucm-files-manager-ucm-fm/assets/css/fm.css/wp-content/plugins/ucm-files-manager-ucm-fm/assets/js/fm.js
Script Paths
/wp-content/plugins/ucm-files-manager-ucm-fm/assets/js/fm.js
Version Parameters
ucm-files-manager-ucm-fm/assets/css/fm.css?ver=ucm-files-manager-ucm-fm/assets/js/fm.js?ver=

HTML / DOM Fingerprints

CSS Classes
php-rockets-fm
HTML Comments
<!-- php-rockets-fm --><!-- UCM File Manager Add-on -->
Data Attributes
data-ucm-fm-id
JS Globals
ucm_fm_params
REST Endpoints
/wp-json/ucm-fm/v1/clientConnect/wp-json/ucm-fm/v1/reload-buckets/wp-json/ucm-fm/v1/fm-save-general/wp-json/ucm-fm/v1/fm-save-roles/wp-json/ucm-fm/v1/fm-save-ui/wp-json/ucm-fm/v1/fm-save-file-types/wp-json/ucm-fm/v1/fm-save-image-editors/wp-json/ucm-fm/v1/fm-save-code-editors/wp-json/ucm-fm/v1/fm-save-advanced/wp-json/ucm-fm/v1/update-file-acl/wp-json/ucm-fm/v1/import-media
FAQ

Frequently Asked Questions about UCM Files Manager Addon (UCM FM)