
Yatterukun Security & Risk Analysis
wordpress.org/plugins/yatterukunFast and easy photo/video media changer plugin.
Is Yatterukun Safe to Use in 2026?
Generally Safe
Score 85/100Yatterukun has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The yatterukun plugin v1.0.0 exhibits a mixed security posture. On the positive side, it has a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, no unprotected entry points. Furthermore, all SQL queries are properly prepared, and there are no known past vulnerabilities or CVEs. This suggests a careful approach to common web vulnerabilities.
However, there are significant concerns. The presence of two instances of the `move_uploaded_file` function, which can be risky if not handled with extreme care, is a red flag. Compounding this, the taint analysis reveals one flow with unsanitized paths, indicating a potential for directory traversal or insecure file handling, even though it's not categorized as critical or high severity in this analysis. The low percentage of properly escaped output (16%) is a major weakness, significantly increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of capability checks and only one nonce check for all entry points further expose the plugin to potential unauthorized actions or CSRF attacks.
In conclusion, while the plugin benefits from a limited attack surface and good SQL practices, the high risk of XSS due to poor output escaping and the potential for insecure file operations highlighted by taint analysis and the use of `move_uploaded_file` are critical weaknesses that need immediate attention. The absence of past vulnerabilities is positive but does not negate the current code-level risks.
Key Concerns
- Unsanitized path in taint flow
- Low percentage of properly escaped output
- Use of dangerous function: move_uploaded_file
- No capability checks
- Limited nonce checks
Yatterukun Security Vulnerabilities
Yatterukun Release Timeline
Yatterukun Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Yatterukun Attack Surface
WordPress Hooks 4
Maintenance & Trust
Yatterukun Maintenance & Trust
Maintenance Signals
Community Trust
Yatterukun Alternatives
Enable Media Replace
enable-media-replace
Easily replace any attached image/file by simply uploading a new file in the Media Library edit view - a real time saver!
Devenia Replace Media
devenia-replace-media
Replace media files while keeping the same URL. Works in Media Library, Elementor, and more.
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager
folders
Create unlimited folders with the Folders WordPress plugin, organize & manage your Media Library files, Pages & Posts in folders 📁
Easy Media Replace
easy-media-replace
Replace Images and Media Files in WordPress Easily and Quickly.
Image Editor by Pixo
image-editor-by-pixo
Replaces the default image editor in wp-admin with more powerful one - Pixo. It can also be used in the front-end.
Yatterukun Developer Profile
1 plugin · 0 total installs
How We Detect Yatterukun
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yatterukun/images/yatterukun.jpg/wp-content/plugins/yatterukun/images/yatterukun.mp4HTML / DOM Fingerprints
<!-- jpg place holder file --><!-- mp4 place holder file -->data-id="yatterukun"data-url="yatterukun_url"window.yatterukun_data