WP-MultiTarget-Uploads-Sync-Tool Security & Risk Analysis

wordpress.org/plugins/wp-multitarget-uploads-sync-tool

A WordPress plugin which able to sync attachments to multiple FTP targets.

10 active installs v1.0.6 PHP + WP 3.4.0+ Updated Dec 30, 2012
attachmentsimagesimgbedsyncupload
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-MultiTarget-Uploads-Sync-Tool Safe to Use in 2026?

Generally Safe

Score 85/100

WP-MultiTarget-Uploads-Sync-Tool has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "wp-multitarget-uploads-sync-tool" v1.0.6 plugin presents a concerning security posture, despite a lack of documented historical vulnerabilities. The static analysis reveals significant issues related to data handling. Notably, 100% of SQL queries are not using prepared statements, indicating a high risk of SQL injection vulnerabilities. Furthermore, the lack of output escaping across all detected outputs suggests a high probability of cross-site scripting (XSS) vulnerabilities. The absence of nonce and capability checks on any entry points, coupled with the absence of any documented entry points like AJAX handlers, REST API routes, or shortcodes, is contradictory and raises questions about the thoroughness of the static analysis or the plugin's actual functionality. However, the identified external HTTP request warrants further investigation to ensure it is not being used in a malicious manner.

While the plugin has no recorded CVEs, this does not guarantee its security. The widespread lack of basic security practices like prepared statements and output escaping in the code itself is a major red flag. The plugin's potential attack surface is masked by the lack of documented entry points, but the underlying code quality issues are substantial. Without further context or a deeper analysis of the plugin's actual functionality and interaction points, it is difficult to definitively assess its overall risk. However, based solely on the provided static analysis, the plugin exhibits several critical security weaknesses.

Key Concerns

  • All SQL queries lack prepared statements
  • No output escaping detected
  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

WP-MultiTarget-Uploads-Sync-Tool Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP-MultiTarget-Uploads-Sync-Tool Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
0 prepared
Unescaped Output
29
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared6 total queries

Output Escaping

0% escaped29 total outputs
Attack Surface

WP-MultiTarget-Uploads-Sync-Tool Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuindex.php:105
filterthe_contentindex.php:109
actionsave_postindex.php:110
Maintenance & Trust

WP-MultiTarget-Uploads-Sync-Tool Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedDec 30, 2012
PHP min version
Downloads2K

Community Trust

Rating40/100
Number of ratings1
Active installs10
Developer Profile

WP-MultiTarget-Uploads-Sync-Tool Developer Profile

evlos

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP-MultiTarget-Uploads-Sync-Tool

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP-MultiTarget-Uploads-Sync-Tool