
Add External Media Security & Risk Analysis
wordpress.org/plugins/add-external-mediaAdd external media to the media library
Is Add External Media Safe to Use in 2026?
Generally Safe
Score 85/100Add External Media has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'add-external-media' plugin version 1.0.5 demonstrates a strong security posture based on the provided static analysis. The code exhibits excellent practices with all identified outputs being properly escaped, SQL queries exclusively using prepared statements, and a single AJAX handler protected by both nonce and capability checks. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. Taint analysis revealing no unsanitized paths or critical/high severity flows is a significant positive indicator.
The vulnerability history is completely clean, with no recorded CVEs across any severity level and no common vulnerability types. This lack of historical issues suggests either a well-developed and scrutinized plugin or a relatively new plugin that has not yet been targeted or found to have flaws. The minimal attack surface, comprising only a single AJAX handler, is also a strength, especially given it is properly secured.
Overall, this plugin appears to be very secure. The analysis shows adherence to best security practices, and the absence of any historical vulnerabilities further bolsters confidence. While no direct security concerns are evident from the provided data, vigilance for future updates and continued good security practices from the developer are always recommended for any plugin.
Add External Media Security Vulnerabilities
Add External Media Code Analysis
Output Escaping
Add External Media Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
Add External Media Maintenance & Trust
Maintenance Signals
Community Trust
Add External Media Alternatives
Media Deduper
media-deduper
Save disk space and bring some order to the chaos of your media library by removing and preventing duplicate files.
WP Attachment Export
wp-attachment-export
Exports only posts of type 'attachment', i.e. your media library
Default Media Uploader View
default-media-uploader-view
Sets "Uploaded to this post" instead of "All media items" as the default view in the media uploader.
Tumble
tumble
Tumble is simple-to-use and allows you to manually send Posts, Images, Audio, and Video to Tumblr from within your Dashboard/Media Library
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
Add External Media Developer Profile
3 plugins · 700 total installs
How We Detect Add External Media
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-external-media/add-external-media.js/wp-content/plugins/add-external-media/add-external-media.jsHTML / DOM Fingerprints
embed-containerembed-previewsettingwidthheightalignmentdata-setting="width"data-setting="height"window.AddExternalMediavar AddExternalMedia/wp-json/add-external-media/v1/add-oembed