
WPOSS阿里云对象存储 Security & Risk Analysis
wordpress.org/plugins/wpossWordPress阿里云对象存储插件(简称:WPOSS),基于阿里云OSS对象存储与WordPress实现静态资源到OSS存储。支持阿里云OSS图片编辑,水印、裁剪、压缩等。
Is WPOSS阿里云对象存储 Safe to Use in 2026?
Generally Safe
Score 100/100WPOSS阿里云对象存储 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wposs plugin v5.0 demonstrates a strong security posture based on the provided static analysis. The complete absence of unprotected AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the plugin utilizes prepared statements for all SQL queries, employs nonces and capability checks, and properly escapes a high percentage of its output, indicating good development practices for mitigating common web vulnerabilities.
The taint analysis shows no flows with unsanitized paths, and the vulnerability history is clean, with no recorded CVEs. This suggests that the plugin has either been developed with security in mind from the outset or has a history of being well-maintained and patched. The presence of file operations and external HTTP requests are standard for many plugins and, without further context or taint analysis indicating malicious intent, are not immediate causes for concern.
Overall, wposs v5.0 appears to be a secure plugin. The lack of identified vulnerabilities and a well-mitigated attack surface are significant strengths. The plugin's adherence to secure coding practices like prepared statements and output escaping is commendable. While there are no specific critical issues identified, the general diligence in secure coding practices is the primary indicator of its strong security.
Key Concerns
- Output escaping is not 100%
- File operations present
- External HTTP requests present
WPOSS阿里云对象存储 Security Vulnerabilities
WPOSS阿里云对象存储 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPOSS阿里云对象存储 Attack Surface
WordPress Hooks 13
Maintenance & Trust
WPOSS阿里云对象存储 Maintenance & Trust
Maintenance Signals
Community Trust
WPOSS阿里云对象存储 Alternatives
OSS Aliyun
oss-aliyun
使用阿里云对象存储 OSS 作为附件存储空间。(This is a plugin that uses Aliyun Object Storage Service for attachments remote saving.)
[凹凸曼]自动同步阿里云对象存储OSS
apoyl-aliyunoss
设计理念,这是绿色无任何污染,可以随时关闭插件,实现手动同步和自动同步,让网站图片和附件自动同步到阿里云对象存储OSS,实现图片附件和网站代码分离,流量分流让网站打开速度更快.
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution
shopengine
WooCommerce builder for Elementor and Gutenberg. It offers product templates, product sliders, shopping cart, quick view, Woo wishlist, product filter …
Blog2Social: Social Media Auto Post & Scheduler
blog2social
Automatically share and schedule your WordPress content on top social platforms like Facebook, Instagram, LinkedIn, TikTok, and more.
zipaddr-jp
zipaddr-jp
zipaddr-jp is a collaborative tool that automatically inputs addresses from postal codes.
WPOSS阿里云对象存储 Developer Profile
12 plugins · 4K total installs
How We Detect WPOSS阿里云对象存储
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wposs//wp-content/plugins/wposs/api.phpwposs/style.css?ver=wposs/script.js?ver=HTML / DOM Fingerprints
wposs-setting-noticewposs-setting-wrapwposs_updated<!-- WPOSS: 阿里云对象存储同步插件 -->data-wposs-sync-statuswposs_ajax_object/wp-json/wposs/v1/settings[wposs_sync_status]