
JSM Adobe XMP / IPTC for WordPress Security & Risk Analysis
wordpress.org/plugins/adobe-xmp-for-wpProvides Adobe XMP / IPTC information from Media Library or NextGEN Gallery images using a shortcode or PHP class method.
Is JSM Adobe XMP / IPTC for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100JSM Adobe XMP / IPTC for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "adobe-xmp-for-wp" v1.6.0 plugin exhibits a strong security posture. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events, especially without authentication checks, significantly limits the plugin's attack surface. The code also demonstrates good practices by not utilizing dangerous functions, performing all SQL queries with prepared statements, and properly escaping all output. The lack of external HTTP requests further reduces potential attack vectors.
However, there are a few areas that warrant attention. The presence of six file operations, while not inherently problematic, could become a risk if not handled with extreme care, especially in the absence of explicit nonce or capability checks for these operations. The complete lack of nonce and capability checks across all entry points is a notable weakness. While the current analysis found no exploitable flows, this oversight could allow for privilege escalation or unauthorized actions if a vulnerability were introduced or discovered in the future.
The plugin's vulnerability history is entirely clean, with no recorded CVEs. This, combined with the absence of known common vulnerability types and recent vulnerabilities, indicates a well-maintained and secure history. Nevertheless, the lack of checks in critical areas remains a potential concern for future development or unforeseen interactions. Overall, the plugin is secure due to its limited attack surface and good coding practices, but the missing authorization checks represent a potential area for improvement.
Key Concerns
- Missing capability checks on entry points
- Missing nonce checks on entry points
- File operations without explicit checks
JSM Adobe XMP / IPTC for WordPress Security Vulnerabilities
JSM Adobe XMP / IPTC for WordPress Release Timeline
JSM Adobe XMP / IPTC for WordPress Code Analysis
JSM Adobe XMP / IPTC for WordPress Attack Surface
WordPress Hooks 2
Maintenance & Trust
JSM Adobe XMP / IPTC for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
JSM Adobe XMP / IPTC for WordPress Alternatives
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
XML Sitemap Generator for Google
google-sitemap-generator
Generate multiple types of sitemaps to improve SEO and get your website indexed quickly.
SiteSEO – SEO Simplified
siteseo
SiteSEO is an easy, fast and powerful SEO plugin for WordPress. Unlock your Website's potential and Maximize your online visibility with our SiteSEO!
SureRank SEO – Smart Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
surerank
SureRank – SEO Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
JSM Adobe XMP / IPTC for WordPress Developer Profile
31 plugins · 32K total installs
How We Detect JSM Adobe XMP / IPTC for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/adobe-xmp-for-wp/assets/js/adobe-xmp-for-wp.js/wp-content/plugins/adobe-xmp-for-wp/assets/css/adobe-xmp-for-wp.css/wp-content/plugins/adobe-xmp-for-wp/assets/js/adobe-xmp-for-wp.jsadobe-xmp-for-wp/assets/js/adobe-xmp-for-wp.js?ver=adobe-xmp-for-wp/assets/css/adobe-xmp-for-wp.css?ver=HTML / DOM Fingerprints
<!--
* Plugin Name: JSM Adobe XMP / IPTC for WordPress
* Text Domain: adobe-xmp-for-wp
* Domain Path: /languages
* Plugin URI: https://surniaulula.com/extend/plugins/adobe-xmp-for-wp/
* Assets URI: https://jsmoriss.github.io/adobe-xmp-for-wp/assets/
* Author: JS Morisset
* Author URI: https://surniaulula.com/
* License: GPLv3
* License URI: https://www.gnu.org/licenses/gpl.txt
* Description: Provides Adobe XMP / IPTC information from Media Library or NextGEN Gallery images using a shortcode or PHP class method.
* Requires PHP: 7.4.33
* Requires At Least: 6.0
* Tested Up To: 6.9.4
* Version: 1.6.0
*
* Version Numbering: {major}.{minor}.{bugfix}[-{stage}.{level}]
*
* {major} Major structural code changes and/or incompatible API changes (ie. breaking changes).
* {minor} New functionality was added or improved in a backwards-compatible manner.
* {bugfix} Backwards-compatible bug fixes or small improvements.
* {stage}.{level} Pre-production release: dev < a (alpha) < b (beta) < rc (release candidate).
*
* Copyright 2012-2025 Jean-Sebastien Morisset (https://surniaulula.com/)
-->adobeXMP