PicGo avatar

PicGo

:rocket: The Ultimate Image Uploader for Efficient Creators. Supports Obsidian, Typora, VS Code etc. and 60+ image hosting services (S3, GitHub, Cloudflare R2, Imgur, Aliyun OSS...). Paste, upload, done.

PluginMediaDesktopDeveloperVisionFileStorageGitHub integration
Verification
L2 · Structured
Security
Low
Health
Active
Trust
Silver

What it doesAI

An image uploader for creators supporting many editors and 60+ hosting services.

  • Supports Obsidian, Typora, VS Code
  • 60+ image hosting services
  • Paste, upload, done

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:Molunerfinn/PicGo

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SO VETMEDIUMd7d2c2
Automated review · daily
MEDIUM

Vet verdict is suspicious: findings need human review (exfiltration endpoints, file deletion, etc.).

0 critical·1 high·0 medium·84 score
plugin version3.0.2
scanned commitd7d2c22994742026-08-22
latest commitd7d2c2299474
vet verdictsuspicious · gitscore 84

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

RiskRuleLocationDescription
high
R10
package.json
install 钩子:package.json scripts.postinstall(安装期任意代码执行面)
Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-22 · activity: Active

• Repo created: 2026-08-22

• Stars: ★ 27,007 · Forks: 2,325

• Health: Active — committed within last 30 days

Source

GitHub: github.com/Molunerfinn/PicGo

Was this page helpful?