
Add Watermarks Security & Risk Analysis
wordpress.org/plugins/add-watermarkAdds watermarks to selected images without changing the original image.
Is Add Watermarks Safe to Use in 2026?
Generally Safe
Score 85/100Add Watermarks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'add-watermark' plugin v2.0.2 exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, using prepared statements for SQL queries, and having no known historical vulnerabilities, significant concerns arise from its attack surface. The plugin exposes two AJAX handlers, both of which lack proper authentication checks. This creates a direct pathway for unauthenticated users to interact with potentially sensitive functionality, significantly increasing the risk of exploitation. The lack of capability checks and the low percentage of properly escaped output further exacerbate these risks, suggesting potential for cross-site scripting (XSS) vulnerabilities if the exposed AJAX actions handle user-supplied data without sufficient sanitization and escaping.
The taint analysis showing zero flows with unsanitized paths is a positive indicator, suggesting that at least in the analyzed flows, sensitive data is handled with some degree of caution. However, this does not fully mitigate the risks posed by the unprotected AJAX endpoints. The complete absence of recorded CVEs is a strength, implying a history of stable and likely secure development. Overall, the plugin's strength lies in its lack of historical issues and its safe SQL handling. Its primary weakness, and the most pressing concern, is the direct exposure of AJAX endpoints without any authentication or permission checks, which represents a substantial security vulnerability.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping percentage
- No capability checks
- Single nonce check on two entry points
Add Watermarks Security Vulnerabilities
Add Watermarks Release Timeline
Add Watermarks Code Analysis
Output Escaping
Add Watermarks Attack Surface
AJAX Handlers 2
WordPress Hooks 16
Maintenance & Trust
Add Watermarks Maintenance & Trust
Maintenance Signals
Community Trust
Add Watermarks Alternatives
Easy Watermark
easy-watermark
Allows to add watermark to images automatically on upload or manually.
Htaccess Secure Files
htaccess-secure-files
Allows securing files in WP's media library to be only accessible to users with specific roles, capabilities, or IP addresses.
htaccess Watermark
ips-watermark
This plugin allows to add a watermark on your images uploaded.
AquaMark
aquamark
Add a custom watermark to your images in the WordPress media library with powerful controls and blending modes.
Guest Video Protection – Copy Protect PDF & Video
guest-video-protection
The most secure copy protection for images, video and PDF. Prevent save, screenshots, screen capture and screen recording.
Add Watermarks Developer Profile
2 plugins · 2K total installs
How We Detect Add Watermarks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-watermark/assets/settings.js/wp-content/plugins/add-watermark/assets/settings.css/wp-content/plugins/add-watermark/assets/settings.jsadd-watermark/assets/settings.js?ver=add-watermark/assets/settings.css?ver=HTML / DOM Fingerprints
id="wpp-add-watermark"window.addEventListener('load',