优刻得UCloud对象存储插件 Security & Risk Analysis

wordpress.org/plugins/wpufile-ucloud

优刻得UCloud对象存储插件(WPUFile),基于UCloud UFile与WordPress实现静态资源到对象存储中。提高网站项目的访问速度,以及静态资源的安全存储功能。目前UCLOUD对象存储提供每月20GB流量,适合入门用户使用。公众号: 老蒋朋友圈。

10 active installs v3.0 PHP 7.4+ WP 5.3+ Updated Feb 9, 2026
ufilewordpress-ucloud%e5%af%b9%e8%b1%a1%e5%ad%98%e5%82%a8wordpress%e5%8a%a0%e9%80%9fwordpress%e5%af%b9%e8%b1%a1%e5%ad%98%e5%82%a8
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 优刻得UCloud对象存储插件 Safe to Use in 2026?

Generally Safe

Score 100/100

优刻得UCloud对象存储插件 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The wpufile-ucloud v3.0 plugin exhibits a strong security posture with no publicly disclosed vulnerabilities and a clean record. The static analysis reveals a commendable lack of critical security weaknesses. Notably, there are no identified dangerous functions, all SQL queries utilize prepared statements, and the taint analysis shows no unsanitized path flows. The plugin also demonstrates good practices by including nonce and capability checks, and its attack surface is effectively zero due to the absence of unprotected entry points like unprotected AJAX handlers, REST API routes, shortcodes, and cron events. However, there are minor areas for improvement. A significant portion of output (27%) is not properly escaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped data originates from user input. While the number of file operations and external HTTP requests is manageable, their context and the data processed during these operations would require deeper inspection to rule out potential risks.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

优刻得UCloud对象存储插件 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

优刻得UCloud对象存储插件 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
16 escaped
Nonce Checks
1
Capability Checks
1
File Operations
6
External Requests
1
Bundled Libraries
0

Output Escaping

73% escaped22 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
setting_page (index.php:423)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

优刻得UCloud对象存储插件 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_noticesindex.php:27
filterwp_handle_uploadindex.php:61
filterwp_update_attachment_metadataindex.php:63
filterwp_generate_attachment_metadataindex.php:65
filterwp_save_image_editor_fileindex.php:66
filterwp_unique_filenameindex.php:71
actiondelete_attachmentindex.php:74
actionadmin_menuindex.php:77
filterplugin_action_linksindex.php:78
filtersanitize_file_nameindex.php:80
filterwp_update_attachment_metadataindex.php:321
Maintenance & Trust

优刻得UCloud对象存储插件 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

优刻得UCloud对象存储插件 Developer Profile

老蒋和他的小伙伴

12 plugins · 4K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 优刻得UCloud对象存储插件

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpufile-ucloud/css/admin.css/wp-content/plugins/wpufile-ucloud/js/admin.js
Script Paths
/wp-content/plugins/wpufile-ucloud/js/admin.js
Version Parameters
wpufile-ucloud/css/admin.css?ver=wpufile-ucloud/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpufile-ucloud-settings
HTML Comments
<!-- 优刻得UCloud对象存储插件设置 --><!-- 优刻得UCloud对象存储插件 -->
Data Attributes
data-ucloud-settings
JS Globals
wpufile_ucloud_admin_object
FAQ

Frequently Asked Questions about 优刻得UCloud对象存储插件