Uptopromo Publisher Indonesia Security & Risk Analysis

wordpress.org/plugins/uptopromo-publisher-indonesia

Plugin UpToPromo untuk Publisher di Indonesia membantu menginstal kode PHP untuk slot iklan UpToPromo pada situs Wordpress hanya dengan 3 klik saja.

10 active installs v0.2 PHP + WP 4.3+ Updated Jan 21, 2016
automaticlinklinksseowidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Uptopromo Publisher Indonesia Safe to Use in 2026?

Generally Safe

Score 85/100

Uptopromo Publisher Indonesia has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'uptopromo-publisher-indonesia' v0.2 plugin presents a mixed security posture. On the positive side, the plugin demonstrates strong practices in its handling of database interactions, with 100% of SQL queries utilizing prepared statements. Furthermore, its limited attack surface, with no reported AJAX handlers, REST API routes, shortcodes, or cron events, reduces potential entry points for attackers. The lack of known CVEs and a clean vulnerability history also suggest a relatively stable codebase.

However, significant concerns arise from the static code analysis. The presence of the 'unserialize' function, a known security risk, is a primary area of worry, especially given the absence of any capability checks or nonce validations. While taint analysis did not report critical or high-severity issues, the identified flows with unsanitized paths are a concern, particularly when combined with the dangerous 'unserialize' function. The extremely low percentage of properly escaped output (5%) is another major red flag, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities.

Overall, while the plugin appears to have avoided publicly known vulnerabilities and employs secure database practices, the critical flaws in output escaping and the use of 'unserialize' without proper checks create substantial security risks that need immediate attention. The lack of basic security mechanisms like nonce and capability checks further exacerbates these risks.

Key Concerns

  • Dangerous function 'unserialize' used
  • Low percentage of properly escaped output
  • Flows with unsanitized paths
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Uptopromo Publisher Indonesia Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Uptopromo Publisher Indonesia Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
18
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
9
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

unserializeif (@unserialize($links) !== false) {promo.php:202
unserialize} else if (!$this->links = @unserialize($links)) {promo.php:264

Output Escaping

5% escaped19 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
options (uptopromo.php:246)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Uptopromo Publisher Indonesia Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwidgets_inituptopromo.php:36
actioninituptopromo.php:38
actioninituptopromo.php:39
actionadmin_menuuptopromo.php:41
actionwp_enqueue_scriptsuptopromo.php:43
actionwp_footeruptopromo.php:93
Maintenance & Trust

Uptopromo Publisher Indonesia Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJan 21, 2016
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Uptopromo Publisher Indonesia Developer Profile

ipnino

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Uptopromo Publisher Indonesia

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/uptopromo-publisher-indonesia/js/utp.js
Script Paths
/wp-content/plugins/uptopromo-publisher-indonesia/js/utp.js
Version Parameters
uptopromo-publisher-indonesia/js/utp.js?ver=

HTML / DOM Fingerprints

JS Globals
PromoClient
REST Endpoints
/wp-json/uptopromo-publisher-indonesia/v1/settings
FAQ

Frequently Asked Questions about Uptopromo Publisher Indonesia