USS Upyun Security & Risk Analysis

wordpress.org/plugins/uss-upyun

使用又拍云云存储USS作为附件存储空间。(This is a plugin that uses UPYUN Storage Service for attachments remote saving.)

30 active installs v1.5.1 PHP 7.0.0+ WP 4.6+ Updated Dec 5, 2025
upyunuss%e5%8f%88%e6%8b%8d%e4%ba%91%e5%af%b9%e8%b1%a1%e5%ad%98%e5%82%a8%e4%ba%91%e5%ad%98%e5%82%a8
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 16, 2025
Safety Verdict

Is USS Upyun Safe to Use in 2026?

Generally Safe

Score 99/100

USS Upyun has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 16, 2025Updated 4mo ago
Risk Assessment

The "uss-upyun" v1.5.1 plugin exhibits a generally good security posture based on the static analysis. The absence of any entry points like AJAX handlers, REST API routes, or shortcodes significantly limits the potential attack surface. Furthermore, the code demonstrates strong secure coding practices with 100% of SQL queries using prepared statements, and the presence of nonce and capability checks is reassuring. The taint analysis shows no unsanitized flows, indicating a low risk of direct code injection or data leakage through the analyzed paths.

However, there are minor areas for improvement. The output escaping is only at 70%, meaning a portion of the output could potentially be vulnerable to Cross-Site Scripting (XSS) if the data being outputted is not properly sanitized beforehand by the source. The presence of a single medium-severity CVE in its vulnerability history, although currently patched, suggests that past vulnerabilities have existed and required attention. The plugin also bundles Guzzle, which could be a potential point of concern if it's an outdated version, though this is not specified.

Overall, the plugin appears to be reasonably secure due to its limited attack surface and use of prepared statements. The main area of concern is the incomplete output escaping, which warrants further investigation into the specific outputs that are not properly handled. The past CVE, while patched, should serve as a reminder for continued vigilance and timely updates.

Key Concerns

  • Output escaping not fully implemented
  • Bundled library (Guzzle) presence without version info
  • Past medium CVE in vulnerability history
Vulnerabilities
1

USS Upyun Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-9629medium · 4.3Cross-Site Request Forgery (CSRF)

USS Upyun <= 1.5.0 - Cross-Site Request Forgery

Sep 16, 2025 Patched in 1.5.1 (1d)
Code Analysis
Analyzed Mar 16, 2026

USS Upyun Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
12
28 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared4 total queries

Output Escaping

70% escaped40 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
uss_setting_page (upyun-uss-wordpress.php:493)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

USS Upyun Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
filtersanitize_file_nameupyun-uss-wordpress.php:98
filterwp_update_attachment_metadataupyun-uss-wordpress.php:271
filterwp_handle_uploadupyun-uss-wordpress.php:286
filterwp_generate_attachment_metadataupyun-uss-wordpress.php:287
filterwp_save_image_editor_fileupyun-uss-wordpress.php:288
actiondelete_attachmentupyun-uss-wordpress.php:355
filterwp_get_attachment_urlupyun-uss-wordpress.php:365
filterthe_contentupyun-uss-wordpress.php:406
filterpost_thumbnail_htmlupyun-uss-wordpress.php:407
filterwp_calculate_image_srcsetupyun-uss-wordpress.php:408
filterplugin_action_linksupyun-uss-wordpress.php:482
actionadmin_menuupyun-uss-wordpress.php:490
Maintenance & Trust

USS Upyun Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version7.0.0
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

USS Upyun Developer Profile

沈唁

13 plugins · 4K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
143 days
View full developer profile
Detection Fingerprints

How We Detect USS Upyun

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/uss-upyun/

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about USS Upyun