
Add Media from URL Security & Risk Analysis
wordpress.org/plugins/add-media-from-urlLet you add media files into your media library without having to upload them.
Is Add Media from URL Safe to Use in 2026?
Generally Safe
Score 85/100Add Media from URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "add-media-from-url" plugin v1.0.2 exhibits a generally strong security posture based on the static analysis results. It demonstrates good practices by not exposing unprotected AJAX handlers, REST API routes, shortcodes, or cron events, thus minimizing its attack surface. Furthermore, the plugin exclusively uses prepared statements for SQL queries and includes nonce and capability checks, which are crucial for preventing common web vulnerabilities. The absence of any reported vulnerabilities, including critical or high-severity ones, in its history also suggests a commitment to security or a lack of discovery, which is a positive sign.
However, a notable area for improvement lies in output escaping. With 40% of its 25 output operations not being properly escaped, there is a potential risk of cross-site scripting (XSS) vulnerabilities. While the taint analysis did not reveal any unsanitized paths with critical or high severity, the presence of unescaped output remains a concerning weakness that could be exploited by attackers. The single file operation also warrants attention, although without further context, its specific risk is unknown.
In conclusion, the "add-media-from-url" plugin is built on a solid foundation of secure coding practices, particularly regarding its attack surface and data handling. The lack of historical vulnerabilities is encouraging. Nevertheless, the significant proportion of unescaped output presents a clear and present risk that should be addressed to further harden the plugin's security.
Key Concerns
- Unescaped output (40%)
Add Media from URL Security Vulnerabilities
Add Media from URL Code Analysis
Output Escaping
Data Flow Analysis
Add Media from URL Attack Surface
WordPress Hooks 6
Maintenance & Trust
Add Media from URL Maintenance & Trust
Maintenance Signals
Community Trust
Add Media from URL Alternatives
LH Add Media From Url
lh-add-media-from-url
Upload files from an url to wordpress media library, either enter file urls in an onsite input box or click a bookmarklet.
LH Browser Shots
lh-browser-shots
Add screenshots of remote wesbites directly to the wordpress media library, either enter the site url in an onsite input box or click a bookmarklet.
DX Delete Attached Media
dx-delete-attached-media
Automatically deletes attached media from posts and custom post types added via the Media button.
Autoremove Attachments
autoremove-attachments
Remove child attachments when parent post, page or custom post type is deleted.
Fix Media Library
wow-media-library-fix
Fix Media Library inconsistency between database and wp-content/uploads folder contents. Unused image files, broken media library entries, missing att …
Add Media from URL Developer Profile
8 plugins · 310 total installs
How We Detect Add Media from URL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-media-from-url/HTML / DOM Fingerprints
wrapform-tablename="AddMediaFromURL_Name"id="AddMediaFromURL_Name"name="AddMediaFromURL_Type"id="AddMediaFromURL_Type"name="AddMediaFromURL_Url"id="AddMediaFromURL_Url"+11 moreLP_AMFU_isImageFromURL