Acme Fix Images – Regenerate Thumbnails Security & Risk Analysis

wordpress.org/plugins/acme-fix-images

Fix image sizes after you have changed image sizes from Media Settings. Ensure your images display consistently across your website.

4K active installs v2.0.4 PHP + WP 5.0+ Updated Apr 18, 2025
featured-imagesimage-croppost-thumbnailsregenerate-thumbnails
100
A · Safe
CVEs total1
Unpatched0
Last CVENov 15, 2023
Download
Safety Verdict

Is Acme Fix Images – Regenerate Thumbnails Safe to Use in 2026?

Generally Safe

Score 100/100

Acme Fix Images – Regenerate Thumbnails has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 15, 2023Updated 11mo ago
Risk Assessment

The "acme-fix-images" v2.0.4 plugin demonstrates a generally good security posture based on the static analysis. It exhibits no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The absence of file operations and external HTTP requests further reduces the potential attack surface. Furthermore, the plugin shows a commitment to security by implementing capability checks, although the absence of nonces on its zero identified entry points is noteworthy.

The vulnerability history, however, reveals a past critical medium severity vulnerability related to missing authorization, last patched on 2023-11-15. While there are no currently unpatched vulnerabilities, this history indicates a potential recurring weakness in authorization checks. The lack of taint analysis results is neutral as there were no flows analyzed, but the clean code signals are positive.

In conclusion, the plugin has strong internal coding practices. The main concern stems from the historical vulnerability, suggesting that while improvements have been made, vigilance regarding authorization logic remains crucial. The plugin's strengths lie in its secure coding of database operations and output handling. Its weakness, hinted at by past CVEs, is the potential for authorization bypasses if not rigorously implemented across all functionalities.

Key Concerns

  • Past medium severity vulnerability (Missing Authorization)
  • Lack of nonce checks on entry points
Vulnerabilities
1

Acme Fix Images – Regenerate Thumbnails Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-47793medium · 5.3Missing Authorization

Acme Fix Images <= 1.0.0 - Missing Authorization via acme_fix_images_ajax_callback

Nov 15, 2023 Patched in 2.0.0 (139d)
Code Analysis
Analyzed Mar 17, 2026

Acme Fix Images – Regenerate Thumbnails Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
19 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped19 total outputs
Attack Surface

Acme Fix Images – Regenerate Thumbnails Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionrest_api_initincludes\api\class-api-settings.php:54
actionrest_api_initincludes\api\class-api.php:75
actionplugins_loadedincludes\main.php:117
actioninitincludes\main.php:132
actionadmin_menuincludes\main.php:146
filteradmin_body_classincludes\main.php:147
actionadmin_enqueue_scriptsincludes\main.php:148
filterattachment_fields_to_editincludes\main.php:149
filterplugin_action_links_acme-fix-images/acme-fix-images.phpincludes\main.php:152
Maintenance & Trust

Acme Fix Images – Regenerate Thumbnails Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 18, 2025
PHP min version
Downloads98K

Community Trust

Rating50/100
Number of ratings2
Active installs4K
Developer Profile

Acme Fix Images – Regenerate Thumbnails Developer Profile

Acme Themes

26 plugins · 34K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
139 days
View full developer profile
Detection Fingerprints

How We Detect Acme Fix Images – Regenerate Thumbnails

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acme-fix-images/build/admin/admin.css/wp-content/plugins/acme-fix-images/assets/library/fonts/open-sans.css
Script Paths
/wp-content/plugins/acme-fix-images/build/admin/admin.js
Version Parameters
acme-fix-images/build/admin/admin.css?ver=acme-fix-images/assets/library/fonts/open-sans.css?ver=

HTML / DOM Fingerprints

CSS Classes
at-has-hdr-stky
Data Attributes
id="acme-fix-images"
JS Globals
acmeFixImagesLocalize
FAQ

Frequently Asked Questions about Acme Fix Images – Regenerate Thumbnails