
Upload.am – File Hosting & VPN Security & Risk Analysis
wordpress.org/plugins/upload-am-file-hosting-vpnSeamlessly upload and manage files with Upload.am integration, supporting secure file sharing and shortcode embedding in WordPress.
Is Upload.am – File Hosting & VPN Safe to Use in 2026?
Generally Safe
Score 99/100Upload.am – File Hosting & VPN has a strong security track record. Known vulnerabilities have been patched promptly.
The "upload-am-file-hosting-vpn" plugin v1.0.1 presents a mixed security posture. While it demonstrates strong adherence to secure coding practices with 100% of SQL queries using prepared statements and all output properly escaped, several significant concerns remain. The plugin exposes a considerable attack surface through five AJAX handlers that lack authentication checks, making them vulnerable to unauthorized access and execution.
Taint analysis did not reveal any unsanitized path flows, which is a positive indicator. However, the plugin has a history of one known medium-severity vulnerability, specifically related to missing authorization, which was remediated. The fact that its last vulnerability was in September 2025 and is currently unpatched is a critical concern, suggesting a lack of ongoing maintenance or a potential delay in applying security updates.
In conclusion, the plugin's foundation in secure coding is commendable. Nevertheless, the numerous unprotected AJAX endpoints represent a substantial risk. The unpatched past vulnerability, even if older, highlights a recurring pattern of authorization issues and the potential for new vulnerabilities if not actively maintained and updated. Users should exercise caution and prioritize updating to a version that addresses these unprotected entry points and any outstanding security advisories.
Key Concerns
- Unprotected AJAX handlers
- Missing authorization on AJAX handlers
- Unpatched past vulnerability
- History of missing authorization vulnerabilities
Upload.am – File Hosting & VPN Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Upload.am File Hosting VPN <= 1.0.0 - Authenticated (Contributor+) Arbitrary Options Disclosure
Upload.am – File Hosting & VPN Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Upload.am – File Hosting & VPN Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Upload.am – File Hosting & VPN Maintenance & Trust
Maintenance Signals
Community Trust
Upload.am – File Hosting & VPN Alternatives
Shared Files – Frontend File Upload Form & Secure File Sharing
shared-files
File management plugin featuring frontend file upload form, download manager, statistics and download log.
Cloud Storage Manager for Fluent Forms – Google Drive, Dropbox, OneDrive, S3 Uploads
cloud-storage-manager
Upload Fluent Forms files to Google Drive, Dropbox, OneDrive, S3, and Cloudflare R2. Save server space with cloud storage.
Filestack WP Upload
filestack-upload
Upload files directly to the cloud with support for multiple sources including local, Facebook, Dropbox, Google Drive, and more.
Share5s – Upload, manage, sharing your file in free file hosting
share5s
Upload, share, track, manage your files in one simple to use file free host share5s.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
Upload.am – File Hosting & VPN Developer Profile
1 plugin · 0 total installs
How We Detect Upload.am – File Hosting & VPN
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/upload-am-file-hosting-vpn/assets/css/admin.css/wp-content/plugins/upload-am-file-hosting-vpn/assets/css/faq.css/wp-content/plugins/upload-am-file-hosting-vpn/assets/css/contacts.css/wp-content/plugins/upload-am-file-hosting-vpn/assets/css/vpn.css/wp-content/plugins/upload-am-file-hosting-vpn/assets/js/utils.js/wp-content/plugins/upload-am-file-hosting-vpn/assets/js/admin.js/wp-content/plugins/upload-am-file-hosting-vpn/assets/js/upload-modal.js/wp-content/plugins/upload-am-file-hosting-vpn/assets/js/faq.js/wp-content/plugins/upload-am-file-hosting-vpn/assets/js/utils.js/wp-content/plugins/upload-am-file-hosting-vpn/assets/js/admin.js/wp-content/plugins/upload-am-file-hosting-vpn/assets/js/upload-modal.js/wp-content/plugins/upload-am-file-hosting-vpn/assets/js/faq.jsupload-am-file-hosting-vpn/assets/css/admin.css?ver=upload-am-file-hosting-vpn/assets/css/faq.css?ver=upload-am-file-hosting-vpn/assets/css/contacts.css?ver=upload-am-file-hosting-vpn/assets/css/vpn.css?ver=upload-am-file-hosting-vpn/assets/js/utils.js?ver=upload-am-file-hosting-vpn/assets/js/admin.js?ver=upload-am-file-hosting-vpn/assets/js/upload-modal.js?ver=upload-am-file-hosting-vpn/assets/js/faq.js?ver=HTML / DOM Fingerprints
upload-modalupload-modal-contentprogressupload-am-filesupload-am-file-passwordupload-am-shortcode-textupload-am-modal-errorupload-am-results<!-- Enqueue inline script for media button click in classic editor --><!-- Enqueue inline script for file upload button click -->id="upload-am-media-button"id="upload-am-files"id="upload-am-file-password"id="upload-am-shortcode-text"id="upload-am-modal-error"id="upload-am-results"+1 moreuploadAmSettings/wp-json/upload-am/v1/upload/wp-json/upload-am/v1/files/wp-json/upload-am/v1/folders/wp-json/upload-am/v1/delete/wp-json/upload-am/v1/folders/create/wp-json/upload-am/v1/folders/rename/wp-json/upload-am/v1/folders/delete/wp-json/upload-am/v1/share/wp-json/upload-am/v1/users/login/wp-json/upload-am/v1/users/register/wp-json/upload-am/v1/users/logout/wp-json/upload-am/v1/users/profile/wp-json/upload-am/v1/vpn/settings/wp-json/upload-am/v1/vpn/connect/wp-json/upload-am/v1/vpn/disconnect/wp-json/upload-am/v1/contacts/add/wp-json/upload-am/v1/contacts/list/wp-json/upload-am/v1/contacts/delete[upload_am_file_uploader][upload_am_file_browser][upload_am_vpn_settings][upload_am_contacts_manager]