upword. Connect Security & Risk Analysis

wordpress.org/plugins/upword-connect

Publish SEO-ready articles from upword. to WordPress automatically. No logins, no copy-paste, no extra work.

0 active installs v1.0.1 PHP 7.4+ WP 6.0+ Updated Apr 4, 2026
ai-contentcontent-marketinglocal-seopublishingseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is upword. Connect Safe to Use in 2026?

Generally Safe

Score 100/100

upword. Connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The upword-connect plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the complete proper escaping of all output are significant strengths. Furthermore, the lack of critical or high-severity taint flows indicates that user-supplied data is being handled securely. The plugin also demonstrates good practice by incorporating capability checks, though the absence of nonce checks on its single shortcode is a potential area of concern.

The plugin's vulnerability history is a major positive indicator, showing no recorded CVEs of any severity. This suggests a mature development process and a consistent track record of security. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, further contributes to its overall security.

While the plugin is generally well-secured, the lack of nonce checks on its shortcode represents a minor risk. However, given the absence of other vulnerabilities and the overall robust code signals, the overall risk is low. The plugin is well-developed from a security perspective, with room for minor improvement in input validation on its shortcode.

Key Concerns

  • Missing nonce check on shortcode
Vulnerabilities
None known

upword. Connect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

upword. Connect Release Timeline

v1.0.1Current
Code Analysis
Analyzed Apr 16, 2026

upword. Connect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
64 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped64 total outputs
Attack Surface

upword. Connect Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[upword_json_ld] includes/class-upword-connect.php:16
WordPress Hooks 4
actionadmin_menuincludes/class-upword-admin.php:9
actionadmin_enqueue_scriptsincludes/class-upword-admin.php:10
actionrest_api_initincludes/class-upword-rest.php:16
actionplugins_loadedupword-connect.php:29
Maintenance & Trust

upword. Connect Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 4, 2026
PHP min version7.4
Downloads84

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

upword. Connect Developer Profile

goupword

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect upword. Connect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/upword-connect/assets/css/admin.css/wp-content/plugins/upword-connect/assets/js/admin.js
Script Paths
/wp-content/plugins/upword-connect/assets/js/admin.js
Version Parameters
upword-connect/assets/css/admin.css?ver=upword-connect/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
upword-connectupword-connect__heroupword-connect__logoupword-connect__hero-textupword-connect__titleupword-connect__subtitleupword-connect__cardupword-connect__row+9 more
Data Attributes
data-current
JS Globals
UpwordConnect
REST Endpoints
/wp-json/upword/v1
FAQ

Frequently Asked Questions about upword. Connect