
Add Custom Header Images Security & Risk Analysis
wordpress.org/plugins/add-custom-header-imagesRemove default header images and load custom header images from 'The Headers' page. Allows for easy selection of random header images in your theme.
Is Add Custom Header Images Safe to Use in 2026?
Generally Safe
Score 100/100Add Custom Header Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "add-custom-header-images" plugin, version 2.3.5, exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any detected dangerous functions, file operations, external HTTP requests, and the complete reliance on prepared statements for SQL queries are all positive indicators. Furthermore, the fact that all identified output points are properly escaped suggests a good understanding of secure coding practices in this regard. The plugin also boasts a clean vulnerability history with zero known CVEs, further reinforcing its current security standing.
However, a significant concern arises from the complete lack of nonce checks and capability checks across all identified entry points. While the current static analysis reports zero unprotected entry points, this absence of authorization checks means that if any new entry points were to be introduced or if the analysis missed any, they would be immediately exposed to unauthenticated or unauthorized access. The plugin's vulnerability history being completely clear is a positive sign, but it might also suggest a lack of rigorous security testing over time or a very limited attack surface that hasn't been thoroughly probed. Therefore, while the plugin appears secure in its current state due to good coding practices and a clean history, the missing authorization mechanisms represent a potential future risk that warrants attention.
Key Concerns
- Missing nonce checks
- Missing capability checks
Add Custom Header Images Security Vulnerabilities
Add Custom Header Images Code Analysis
Output Escaping
Add Custom Header Images Attack Surface
WordPress Hooks 7
Maintenance & Trust
Add Custom Header Images Maintenance & Trust
Maintenance Signals
Community Trust
Add Custom Header Images Alternatives
Unique Headers
unique-headers
Adds the ability to use unique custom header images on individual pages, posts or categories or tags.
Plugin Name: oQey Headers
oqey-headers
oQey Headers plugin is a Wordpress Plugin that allows to add and manage images for blog header easily.
Imagify Image Optimization – Optimize Images | Compress Images | Convert WebP | Convert AVIF
imagify
Optimize images in 1-click: compress images, convert to WebP & AVIF, resize, and boost your site with the easiest WordPress image optimization plugin!
Smush Image Optimization – Optimize Images | Compress & Lazy Load Images | Convert WebP & AVIF | Image CDN
wp-smushit
Optimize and compress images with lossless and lossy compression, lazy load, WebP & AVIF conversion, and global image CDN.
Autoptimize
autoptimize
Autoptimize speeds up your website by optimizing JS, CSS, images (incl. lazy-load), HTML and Google Fonts, asyncing JS, removing emoji cruft and more.
Add Custom Header Images Developer Profile
12 plugins · 43K total installs
How We Detect Add Custom Header Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-custom-header-images/add-custom-header-images.phpHTML / DOM Fingerprints
error