
Alternative WordPress Image Uploader Using Flickr Security & Risk Analysis
wordpress.org/plugins/akwpuploader-alternative-wordpress-image-uploaderThis plugin was created for those people who are unsatisfied with image resizing capabilites of wordpress uploader. It uses services from flickr.
Is Alternative WordPress Image Uploader Using Flickr Safe to Use in 2026?
Generally Safe
Score 85/100Alternative WordPress Image Uploader Using Flickr has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "akwpuploader-alternative-wordpress-image-uploader" plugin version 1.1.0 presents a significant security risk due to its unprotected AJAX handler. The presence of an AJAX entry point without any authentication or capability checks is a critical vulnerability, allowing any unauthenticated user to potentially interact with the plugin's backend functions.
Further concerns are raised by the static analysis, which indicates a lack of robust security practices. Specifically, the use of dangerous functions like `create_function` and `unserialize` opens the door to potential code injection and deserialization vulnerabilities, especially when combined with unsanitized input. The alarmingly low percentage of properly escaped output (8%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities. Additionally, the presence of multiple flows with unsanitized paths in the taint analysis, even without a critical severity flag, points to potential issues with file handling or directory traversal.
While the plugin has no recorded historical CVEs, this absence of past vulnerabilities does not negate the substantial risks identified in the current code. The plugin's static analysis and taint analysis reveal fundamental security weaknesses that could be exploited regardless of past history. The bundled outdated jQuery library is also a minor concern. Overall, this plugin exhibits a poor security posture due to critical vulnerabilities in its attack surface and a general lack of security hardening.
Key Concerns
- Unprotected AJAX handler
- Dangerous function: create_function
- Dangerous function: unserialize
- Low output escaping percentage
- Flows with unsanitized paths (High severity taint flow)
- Bundled outdated jQuery v1.2.3
- No nonce checks on AJAX
- Low capability checks coverage
Alternative WordPress Image Uploader Using Flickr Security Vulnerabilities
Alternative WordPress Image Uploader Using Flickr Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Alternative WordPress Image Uploader Using Flickr Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Alternative WordPress Image Uploader Using Flickr Maintenance & Trust
Maintenance Signals
Community Trust
Alternative WordPress Image Uploader Using Flickr Alternatives
AWSOM Pixgallery
awsom-pixgallery
AWSOM Pixgallery is an Image Gallery/Archive plugin for Wordpress designed to make it easier for Artists or Webcomic creators to set up a portfolio of …
real.PostImages
real-postimages
Дополнительное поле записей (постов) для изображений. | English read below
WPFlickr
wpflickr
Handles uploading, modifying images on Flickr, and insertion into posts.
Gallery View
gallery-view
View posts in a gallery layout in the admin.
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
Alternative WordPress Image Uploader Using Flickr Developer Profile
2 plugins · 20 total installs
How We Detect Alternative WordPress Image Uploader Using Flickr
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/akwpuploader-alternative-wordpress-image-uploader/js/jquery-1.2.3.min.js/wp-content/plugins/akwpuploader-alternative-wordpress-image-uploader/js/akuploader.js/wp-content/plugins/akwpuploader-alternative-wordpress-image-uploader/akloader.gif/wp-content/plugins/akwpuploader-alternative-wordpress-image-uploader/js/akuploader.jsakwpuploader-alternative-wordpress-image-uploader/js/jquery-1.2.3.min.js?ver=akwpuploader-alternative-wordpress-image-uploader/js/akuploader.js?ver=HTML / DOM Fingerprints
meta-box-sortablespostboxhandledivhndleinsidedbx-contentid="flickid"id="tag_sets"id="tags_button"onclick="getTagsAndSets(id="img_button"onclick="submitForm(+5 moreakuploader.jsgetTagsAndSetssubmitForm