Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI Security & Risk Analysis

wordpress.org/plugins/alt-manager

Automatically bulk change images alt text to dynamic alt tags values related to content or media and also generate empty values.

7K active installs v1.8.3 PHP 5.2.4+ WP 2.8.0+ Updated Mar 10, 2026
aialt-textimage-altimage-alt-textimages-seo
98
A · Safe
CVEs total2
Unpatched0
Last CVEMar 20, 2026
Safety Verdict

Is Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI Safe to Use in 2026?

Generally Safe

Score 98/100

Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Mar 20, 2026Updated 2mo ago
Risk Assessment

The "alt-manager" plugin v1.8.3 presents a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. The plugin also demonstrates good practices in its SQL query handling, with 100% of queries using prepared statements, and a high percentage (93%) of output being properly escaped, mitigating common injection and XSS risks. The presence of nonce checks further adds to its defensive measures.

However, concerns arise from the taint analysis, which indicates two flows with unsanitized paths. While these are not classified as critical or high severity, they represent potential avenues for attackers to exploit if properly triggered. The vulnerability history shows a past medium-severity vulnerability related to missing authorization. Although there are no currently unpatched vulnerabilities, this past incident suggests a potential weakness in authorization handling that could re-emerge or manifest in different ways.

In conclusion, "alt-manager" v1.8.3 has several strong security features, particularly in its limited attack surface and sanitized SQL queries. The primary areas of concern are the identified unsanitized paths in the taint analysis and the historical pattern of missing authorization vulnerabilities. The plugin's overall security is decent, but diligent attention should be paid to the taint analysis findings and historical vulnerability types to ensure ongoing security.

Key Concerns

  • Unsanitized paths found in taint analysis
  • Past medium vulnerability (Missing Authorization)
  • Low percentage of properly escaped output (93%)
  • Bundled Freemius v1.0 library (potential for outdated)
Vulnerabilities
2 published

Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-3350medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Image Alt Text Manager <= 1.8.2 - Authenticated (Author+) Stored Cross-Site Scripting via Post Title

Mar 20, 2026 Patched in 1.8.3 (1d)
CVE-2023-50373medium · 5.3Missing Authorization

Alt Manager <= 1.6.1 - Missing Authorization

Dec 7, 2023 Patched in 1.6.2 (110d)
Version History

Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI Release Timeline

v1.8.3Current
v1.8.21 CVE
v1.8.11 CVE
v1.8.01 CVE
v1.7.91 CVE
v1.7.81 CVE
v1.7.71 CVE
v1.7.61 CVE
v1.7.51 CVE
v1.7.41 CVE
v1.7.31 CVE
v1.7.21 CVE
v1.7.11 CVE
v1.7.01 CVE
v1.6.91 CVE
v1.6.81 CVE
v1.6.71 CVE
v1.6.61 CVE
v1.6.51 CVE
v1.6.41 CVE
Code Analysis
Analyzed Mar 16, 2026

Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
10
141 escaped
Nonce Checks
3
Capability Checks
0
File Operations
3
External Requests
1
Bundled Libraries
2

Bundled Libraries

Select2Freemius1.0

SQL Query Safety

100% prepared1 total queries

Output Escaping

93% escaped151 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
alm_settings_admin (inc\alm-admin.php:23)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_enqueue_scriptsalt-manager.php:60
actioninitalt-manager.php:120
actionadmin_initalt-manager.php:144
actionadmin_menuinc\alm-admin.php:4
actionnetwork_admin_menuinc\alm-admin.php:13
actiontemplate_redirectinc\alm-empty-generator.php:5
filteralm_outputinc\alm-empty-generator.php:6
actionwp_enqueue_scriptsinc\alm-empty-generator.php:394
filterwp_get_attachment_image_attributesinc\alm-functions.php:12
Maintenance & Trust

Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 10, 2026
PHP min version5.2.4
Downloads101K

Community Trust

Rating86/100
Number of ratings12
Active installs7K
Developer Profile

Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI Developer Profile

WPSAAD

7 plugins · 7K total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
56 days
View full developer profile
Detection Fingerprints

How We Detect Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI