
Uploadcare File Uploader and Adaptive Delivery (beta) Security & Risk Analysis
wordpress.org/plugins/uploadcareUploadcare, an all-round media upload, storage, management, and delivery solution, breaks many WordPress Media Library limitations.
Is Uploadcare File Uploader and Adaptive Delivery (beta) Safe to Use in 2026?
Generally Safe
Score 91/100Uploadcare File Uploader and Adaptive Delivery (beta) has a strong security track record. Known vulnerabilities have been patched promptly.
The Uploadcare plugin v3.1.0 exhibits a concerning security posture primarily due to a significant number of unprotected entry points. While the plugin demonstrates good practices like 100% use of prepared statements for SQL queries and a high percentage of properly escaped output, the presence of 5 AJAX handlers, all lacking authentication checks, creates a substantial attack surface. Furthermore, taint analysis reveals 2 high-severity flows with unsanitized paths, indicating potential risks for data manipulation or injection if these flows are triggered by malicious input. The use of the `unserialize` function, though only present twice, is a known risk vector if not handled with extreme care, especially with user-supplied data. The vulnerability history shows one medium-severity CVE recently, which, although patched, highlights a pattern of past vulnerabilities. The plugin's strengths lie in its secure database interactions and output handling, but these are overshadowed by the critical weaknesses in its entry point security and data sanitization for specific flows.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Use of unserialize function
- Medium severity CVE history
Uploadcare File Uploader and Adaptive Delivery (beta) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Uploadcare File Uploader and Adaptive Delivery (beta) <= 3.0.11 - Cross-Site Request Forgery
Uploadcare File Uploader and Adaptive Delivery (beta) Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Uploadcare File Uploader and Adaptive Delivery (beta) Attack Surface
AJAX Handlers 5
WordPress Hooks 25
Maintenance & Trust
Uploadcare File Uploader and Adaptive Delivery (beta) Maintenance & Trust
Maintenance Signals
Community Trust
Uploadcare File Uploader and Adaptive Delivery (beta) Alternatives
Filestack WP Upload
filestack-upload
Upload files directly to the cloud with support for multiple sources including local, Facebook, Dropbox, Google Drive, and more.
WP-Stateless – Google Cloud Storage
wp-stateless
Upload and serve your WordPress media files from Google Cloud Storage.
Microsoft Azure Storage for WordPress
windows-azure-storage
Use the Microsoft Azure Storage service to host your website's media files.
Max Upload File Size Manager
max-upload-file-size-manager
Max Upload File Size Manager empowers you to effortlessly overcome your hosting provider's file size limits (up to 2 GB) by allowing seamless upl …
Cloud Storage Manager for Fluent Forms – Google Drive, Dropbox, OneDrive, S3 Uploads
cloud-storage-manager
Upload Fluent Forms files to Google Drive, Dropbox, OneDrive, S3, and Cloudflare R2. Save server space with cloud storage.
Uploadcare File Uploader and Adaptive Delivery (beta) Developer Profile
1 plugin · 90 total installs
How We Detect Uploadcare File Uploader and Adaptive Delivery (beta)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/uploadcare/css/uploadcare.css/wp-content/plugins/uploadcare/compiled-js/blocks.css/wp-content/plugins/uploadcare/css/custom.css/wp-content/plugins/uploadcare/compiled-js/admin.css/wp-content/plugins/uploadcare/js/config.js/wp-content/plugins/uploadcare/compiled-js/blocks.js/wp-content/plugins/uploadcare/compiled-js/admin.jsuploadcare.css?ver=blocks.css?ver=custom.css?ver=admin.css?ver=HTML / DOM Fingerprints
uploadcare-widget-formuploadcare-widget-file-uploaderdata-uploadcare-public-keyWP_UC_PARAMS