
WP-Stateless – Google Cloud Storage Security & Risk Analysis
wordpress.org/plugins/wp-statelessUpload and serve your WordPress media files from Google Cloud Storage.
Is WP-Stateless – Google Cloud Storage Safe to Use in 2026?
Generally Safe
Score 98/100WP-Stateless – Google Cloud Storage has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-stateless" plugin v4.4.1 presents a mixed security posture. On one hand, the static analysis reveals a commendably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no critical or high-severity taint flows detected, and dangerous functions are absent. This indicates a generally well-structured codebase with an emphasis on limiting direct entry points. However, several areas raise significant concerns. The plugin exhibits a very low rate of proper output escaping (5%), suggesting a high probability of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis shows no unsanitized paths, the lack of output escaping is a critical weakness that can easily be exploited. The plugin's vulnerability history, including a high-severity vulnerability from April 2024 and a medium one, coupled with common vulnerability types like Missing Authorization and XSS, reinforces these concerns. The absence of nonce checks and capability checks on its entry points (though currently zero) is also a potential future risk if the attack surface were to expand without proper security measures. The presence of bundled libraries like Guzzle and Select2 also warrants attention, as outdated versions of these can introduce vulnerabilities.
Key Concerns
- Low rate of proper output escaping (5%)
- High-severity vulnerability in history (2024-04-05)
- Medium-severity vulnerability in history
- Common vulnerability type: Missing Authorization
- Common vulnerability type: Cross-site Scripting
- No nonce checks
- No capability checks
- Bundled libraries (Guzzle, Select2) may be outdated
WP-Stateless – Google Cloud Storage Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP-Stateless – Google Cloud Storage <= 3.4.0 - Missing Authorization to Limited Arbitrary Options Update
WP-Stateless – Google Cloud Storage <= 3.1.1 - Authenticated (Admin+) Stored Cross-Site Scripting
WP-Stateless – Google Cloud Storage Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
WP-Stateless – Google Cloud Storage Attack Surface
WordPress Hooks 1
Maintenance & Trust
WP-Stateless – Google Cloud Storage Maintenance & Trust
Maintenance Signals
Community Trust
WP-Stateless – Google Cloud Storage Alternatives
Google Cloud Storage plugin
gcs
A plugin for uploading media files to Google Cloud Storage.
WP-Stateless – Gravity Forms Addon
wp-stateless-gravity-forms-addon
Provides compatibility between the Gravity Forms and the WP-Stateless plugins.
WP-Stateless – Elementor Website Builder Addon
wp-stateless-elementor-website-builder-addon
Provides compatibility between the Elementor Website Builder and the WP-Stateless plugins.
WP-Stateless – WooCommerce Addon
wp-stateless-woocommerce-addon
Provides compatibility between the WooCommerce and the WP-Stateless plugins.
WP-Stateless – LiteSpeed Cache Addon
wp-stateless-litespeed-cache-addon
Provides compatibility between the LiteSpeed Cache and the WP-Stateless plugins.
WP-Stateless – Google Cloud Storage Developer Profile
15 plugins · 5K total installs
How We Detect WP-Stateless – Google Cloud Storage
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-stateless/static/css/dashboard.css/wp-content/plugins/wp-stateless/static/js/dashboard.js/wp-content/plugins/wp-stateless/static/js/notice.js/wp-content/plugins/wp-stateless/static/js/scripts.jswp-stateless/static/css/dashboard.css?ver=wp-stateless/static/js/dashboard.js?ver=wp-stateless/static/js/notice.js?ver=wp-stateless/static/js/scripts.js?ver=HTML / DOM Fingerprints
stateless-media-notice<!-- wp-stateless: admin notices -->data-stateless-mediastateless_media_noticewpCloud/wp-json/stateless-media/v1/utilities/upload