
WP Copy Media URL Security & Risk Analysis
wordpress.org/plugins/wp-copy-media-urlThis WordPress plugin provides ability to copy media URL with just a single click.
Is WP Copy Media URL Safe to Use in 2026?
Use With Caution
Score 64/100WP Copy Media URL has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-copy-media-url v2.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, raw SQL queries, or file operations, and all SQL queries utilize prepared statements. There are also no identified flows with unsanitized paths in the taint analysis, indicating a generally clean code execution path. However, a significant concern arises from the vulnerability history, which shows one known unpatched medium severity vulnerability, specifically a Cross-Site Request Forgery (CSRF). This indicates a potential for an attacker to trick authenticated users into performing unintended actions. Furthermore, the low percentage of properly escaped output (17%) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, although no specific flows were identified in the provided taint analysis. The absence of nonce checks and the limited capability checks (2) on the plugin's entry points also contribute to a weaker defense against certain attack vectors, especially when coupled with the existing CSRF vulnerability. Overall, while the plugin shows good practices in handling data and avoiding direct code execution vulnerabilities, the unpatched CSRF and potential XSS risks due to insufficient output escaping, coupled with a limited defense on entry points, warrant caution.
Key Concerns
- Unpatched medium severity CVE
- Low output escaping percentage
- No nonce checks on entry points
WP Copy Media URL Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Copy Media URL <= 2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
WP Copy Media URL Code Analysis
Output Escaping
Data Flow Analysis
WP Copy Media URL Attack Surface
WordPress Hooks 10
Maintenance & Trust
WP Copy Media URL Maintenance & Trust
Maintenance Signals
Community Trust
WP Copy Media URL Alternatives
No alternatives data available yet.
WP Copy Media URL Developer Profile
4 plugins · 3K total installs
How We Detect WP Copy Media URL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-copy-media-url/css/wp-copy-media-url.css/wp-content/plugins/wp-copy-media-url/js/wp-copy-media-url.js/wp-content/plugins/wp-copy-media-url/js/wp-copy-media-url.jswp-copy-media-url/js/wp-copy-media-url.js?ver=wp-copy-media-url/css/wp-copy-media-url.css?ver=HTML / DOM Fingerprints
wp-cmu-copy-btnwp-cmu-copy-btn-listthumbnail-wp-cmu-copy-btn<!-- FOR THE RESTRICTION OF DIRECTLY ACCESS OF THE CLASS --><!-- Plugin Activation --><!-- Plugin deactivation --><!-- Stores the class instance. -->+10 moredata-copied-textwp_cmu_settings