WPUPYUN又拍云云存储 Security & Risk Analysis

wordpress.org/plugins/wpupyun

WordPress又拍云云存储插件(简称:WPUPYUN),基于又拍云云存储与WordPress实现静态资源到又拍云对象存储中。提高网站项目的访问速度,以及静态资源的安全存储功能。 公众号: 老蒋朋友圈。

100 active installs v4.0 PHP 7.4+ WP 5.3+ Updated Feb 9, 2026
wordpress-%e5%8f%88%e6%8b%8d%e4%ba%91%e5%ad%98%e5%82%a8wordpress%e5%8a%a0%e9%80%9fwordpress%e5%af%b9%e8%b1%a1%e5%ad%98%e5%82%a8%e5%8f%88%e6%8b%8d%e4%ba%91wordpress%e5%8f%88%e6%8b%8d%e4%ba%91%e5%af%b9%e8%b1%a1%e5%ad%98%e5%82%a8
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPUPYUN又拍云云存储 Safe to Use in 2026?

Generally Safe

Score 100/100

WPUPYUN又拍云云存储 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the static analysis and vulnerability history, the 'wpupyun' plugin v4.0 exhibits a very strong security posture. The absence of any discovered CVEs, coupled with the static analysis revealing zero unprotected entry points, dangerous functions, or unsanitized taint flows, suggests a highly secure codebase. The plugin also demonstrates excellent secure coding practices, with all SQL queries utilizing prepared statements, all output properly escaped, and a healthy use of nonce and capability checks. The presence of Guzzle as a bundled library is noted, but without further information regarding its version or known vulnerabilities, it's difficult to assign a specific risk. The plugin's attack surface is zero, which is an exceptionally positive sign for security.

Vulnerabilities
None known

WPUPYUN又拍云云存储 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPUPYUN又拍云云存储 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
21 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped21 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
wpupyun_setting_page (setting_page.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WPUPYUN又拍云云存储 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionupgrader_process_completeindex.php:19
filtersanitize_file_nameindex.php:22
filterwp_handle_uploadindex.php:26
filterwp_update_attachment_metadataindex.php:28
filterwp_generate_attachment_metadataindex.php:30
filterwp_save_image_editor_fileindex.php:31
filterwp_unique_filenameindex.php:36
actiondelete_attachmentindex.php:39
actionadmin_menuindex.php:42
filterplugin_action_linksindex.php:43
filterwp_update_attachment_metadataindex.php:49
Maintenance & Trust

WPUPYUN又拍云云存储 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version7.4
Downloads11K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

WPUPYUN又拍云云存储 Developer Profile

老蒋和他的小伙伴

12 plugins · 4K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPUPYUN又拍云云存储

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpupyun/css/wpupyun.css/wp-content/plugins/wpupyun/js/wpupyun.js
Script Paths
/wp-content/plugins/wpupyun/js/wpupyun.js
Version Parameters
wpupyun/css/wpupyun.css?ver=wpupyun/js/wpupyun.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-upyun-path
JS Globals
window.wpupyun_options
FAQ

Frequently Asked Questions about WPUPYUN又拍云云存储