
Uptopromo Publisher Indonesia Security & Risk Analysis
wordpress.org/plugins/uptopromo-publisher-indonesiaPlugin UpToPromo untuk Publisher di Indonesia membantu menginstal kode PHP untuk slot iklan UpToPromo pada situs Wordpress hanya dengan 3 klik saja.
Is Uptopromo Publisher Indonesia Safe to Use in 2026?
Generally Safe
Score 85/100Uptopromo Publisher Indonesia has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'uptopromo-publisher-indonesia' v0.2 plugin presents a mixed security posture. On the positive side, the plugin demonstrates strong practices in its handling of database interactions, with 100% of SQL queries utilizing prepared statements. Furthermore, its limited attack surface, with no reported AJAX handlers, REST API routes, shortcodes, or cron events, reduces potential entry points for attackers. The lack of known CVEs and a clean vulnerability history also suggest a relatively stable codebase.
However, significant concerns arise from the static code analysis. The presence of the 'unserialize' function, a known security risk, is a primary area of worry, especially given the absence of any capability checks or nonce validations. While taint analysis did not report critical or high-severity issues, the identified flows with unsanitized paths are a concern, particularly when combined with the dangerous 'unserialize' function. The extremely low percentage of properly escaped output (5%) is another major red flag, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities.
Overall, while the plugin appears to have avoided publicly known vulnerabilities and employs secure database practices, the critical flaws in output escaping and the use of 'unserialize' without proper checks create substantial security risks that need immediate attention. The lack of basic security mechanisms like nonce and capability checks further exacerbates these risks.
Key Concerns
- Dangerous function 'unserialize' used
- Low percentage of properly escaped output
- Flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
Uptopromo Publisher Indonesia Security Vulnerabilities
Uptopromo Publisher Indonesia Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Uptopromo Publisher Indonesia Attack Surface
WordPress Hooks 6
Maintenance & Trust
Uptopromo Publisher Indonesia Maintenance & Trust
Maintenance Signals
Community Trust
Uptopromo Publisher Indonesia Alternatives
iMoney
imoney
Plugin iMoney is meant for monetize your blog using Adsense, sape.ru, tnx.net and other systems.
iSape
isape
en
Internal Link Juicer: SEO Auto Linker for WordPress
internal-links
Improve your SEO and your user experience through internal linkbuilding. Automated links between your posts based on a smart keyword configuration.
Autolinks Manager – SEO Auto Linker
daext-autolinks-manager
Automate your affiliate links, increase product page visits, link glossary keywords, and more with this advanced SEO auto-linker plugin.
Automatic Internal Links for SEO by Pagup
automatic-internal-links-for-seo
This fully automated plugin creates and boosts your internal linking in 2 clicks, using Yoast / Rank Math Focus keywords as anchor text for internal l …
Uptopromo Publisher Indonesia Developer Profile
1 plugin · 10 total installs
How We Detect Uptopromo Publisher Indonesia
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/uptopromo-publisher-indonesia/js/utp.js/wp-content/plugins/uptopromo-publisher-indonesia/js/utp.jsuptopromo-publisher-indonesia/js/utp.js?ver=HTML / DOM Fingerprints
PromoClient/wp-json/uptopromo-publisher-indonesia/v1/settings