WPQiNiu七牛云对象存储 Security & Risk Analysis

wordpress.org/plugins/wpqiniu

WordPress 七牛云对象存储(简称:WPQiNiu),基于七牛云对象存储与WordPress实现静态资源到对象存储中,让静态资源包括图片、附件分离WordPress根目录,提高网站打开速度。

400 active installs v5.0 PHP 7.4+ WP 5.3+ Updated Feb 9, 2026
wordpress%e5%af%b9%e8%b1%a1%e5%ad%98%e5%82%a8%e4%b8%83%e7%89%9bwordpress%e4%b8%83%e7%89%9b%e5%8a%a0%e9%80%9fwordpress%e4%b8%83%e7%89%9b%e5%af%b9%e8%b1%a1%e5%ad%98%e5%82%a8%e4%b8%83%e7%89%9b%e4%ba%91%e5%ad%98%e5%82%a8wordpress
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPQiNiu七牛云对象存储 Safe to Use in 2026?

Generally Safe

Score 100/100

WPQiNiu七牛云对象存储 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The wpqiniu plugin v5.0 exhibits a strong security posture based on the provided static analysis. The absence of any identifiable AJAX handlers, REST API routes, shortcodes, or cron events with exposed entry points suggests a minimal attack surface. The code also demonstrates good practices by utilizing prepared statements for all SQL queries, indicating a defense against SQL injection vulnerabilities. Furthermore, the presence of nonce and capability checks, along with a single external HTTP request, are generally well-managed aspects. The taint analysis revealing zero unsanitized paths further strengthens this positive outlook.

However, a notable concern lies in the output escaping. With only 43% of outputs properly escaped, there's a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that data displayed to users might not be sufficiently sanitized, allowing malicious scripts to be injected and executed. The plugin's history of zero known CVEs is a positive indicator, suggesting a track record of good security, but it doesn't negate the immediate risk posed by the poor output escaping practices in the current version. In conclusion, while the plugin has a fundamentally secure design with a small attack surface and robust data handling for SQL, the significant lack of output escaping represents a critical weakness that requires immediate attention.

Key Concerns

  • Insufficient output escaping (43%)
Vulnerabilities
None known

WPQiNiu七牛云对象存储 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPQiNiu七牛云对象存储 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
22 escaped
Nonce Checks
1
Capability Checks
1
File Operations
14
External Requests
1
Bundled Libraries
0

Output Escaping

43% escaped51 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
setting_page (index.php:390)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WPQiNiu七牛云对象存储 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_noticesindex.php:14
filterwp_handle_uploadindex.php:49
filterwp_update_attachment_metadataindex.php:51
filterwp_generate_attachment_metadataindex.php:53
filterwp_save_image_editor_fileindex.php:54
filterwp_unique_filenameindex.php:59
actiondelete_attachmentindex.php:62
actionadmin_menuindex.php:65
filterplugin_action_linksindex.php:66
filtersanitize_file_nameindex.php:68
filterwp_update_attachment_metadataindex.php:288
Maintenance & Trust

WPQiNiu七牛云对象存储 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version7.4
Downloads22K

Community Trust

Rating100/100
Number of ratings2
Active installs400
Developer Profile

WPQiNiu七牛云对象存储 Developer Profile

老蒋和他的小伙伴

12 plugins · 4K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPQiNiu七牛云对象存储

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpqiniu/css/qiniu.css/wp-content/plugins/wpqiniu/js/qiniu.js
Script Paths
/wp-content/plugins/wpqiniu/js/qiniu.js
Version Parameters
wpqiniu/css/qiniu.css?ver=wpqiniu/js/qiniu.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpqiniu-notice
Data Attributes
data-qiniu-config
JS Globals
wpqiniu_config
FAQ

Frequently Asked Questions about WPQiNiu七牛云对象存储