Altinator Security & Risk Analysis

wordpress.org/plugins/altinator

Helps you optimize your image alternative texts and make your site more accessible.

0 active installs v1.0.0 PHP 8.2+ WP 6.8+ Updated Jun 27, 2025
a11yaccessibilityalternative-textsimagesmedia
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Altinator Safe to Use in 2026?

Generally Safe

Score 100/100

Altinator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The altinator v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. It demonstrates excellent practices by having no known vulnerabilities, no direct SQL queries without prepared statements, and a high percentage of properly escaped output. Furthermore, the absence of external HTTP requests and file operations reduces potential attack vectors. The plugin also incorporates nonces and capability checks, which are fundamental security mechanisms.

However, a significant concern arises from the presence of three 'assert' functions. While 'assert' can be used for debugging or internal checks, in a production environment, it can sometimes be exploited to cause denial-of-service or reveal internal state if not handled carefully. The static analysis did not reveal any critical or high severity taint flows, and the attack surface is reported as zero, which is highly positive. The lack of vulnerability history is also a good sign, suggesting the plugin has been developed with security in mind or has not yet been a target of significant exploit development.

In conclusion, altinator v1.0.0 appears to be a well-secured plugin with a minimal attack surface and good adherence to security best practices. The main area of caution lies with the use of 'assert' functions, which warrants further investigation in the context of the plugin's specific implementation to ensure they do not present an exploitable risk. The absence of known vulnerabilities and a clean taint analysis are strong indicators of its current security.

Key Concerns

  • Use of dangerous function (assert)
Vulnerabilities
None known

Altinator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Altinator Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
0 prepared
Unescaped Output
3
46 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

assertassert( ! empty( static::VERSION ), 'VERSION constant in Plugin class must be defined' );includes\classes\Plugin.php:24
assertassert( ! empty( static::SLUG ), 'SLUG constant in Plugin class must be defined' );includes\classes\Plugin.php:25
assertassert( ! empty( static::OPTION_GROUP ), 'Settings class must declare OPTION_GROUP const with optionincludes\classes\Settings\Settings.php:24

Output Escaping

94% escaped49 total outputs
Attack Surface

Altinator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionplugins_loadedaltinator.php:53
actionadmin_bar_menuincludes\classes\Modules\Frontend_Inspector\Frontend_Inspector_Module.php:47
actionwp_enqueue_scriptsincludes\classes\Modules\Frontend_Inspector\Frontend_Inspector_Module.php:48
filterwp_content_img_tagincludes\classes\Modules\Frontend_Inspector\Frontend_Inspector_Module.php:54
filterquery_varsincludes\classes\Modules\Media_Library\Filter.php:19
actionpre_get_postsincludes\classes\Modules\Media_Library\Filter.php:24
actionrestrict_manage_postsincludes\classes\Modules\Media_Library\Filter.php:29
filterajax_query_attachments_argsincludes\classes\Modules\Media_Library\Filter.php:36
actionadmin_enqueue_scriptsincludes\classes\Modules\Media_Library\Filter.php:41
actionload-upload.phpincludes\classes\Modules\Media_Library\Media_Library_Module.php:32
actionadmin_enqueue_scriptsincludes\classes\Modules\Media_Library\Media_Library_Module.php:41
actionadmin_enqueue_scriptsincludes\classes\Modules\Media_Library\Media_Library_Module.php:47
actionadmin_enqueue_scriptsincludes\classes\Modules\Media_Library\Quick_Edit.php:18
filtermanage_media_columnsincludes\classes\Modules\Media_Library\Quick_Edit.php:20
actionmanage_media_custom_columnincludes\classes\Modules\Media_Library\Quick_Edit.php:25
filteradmin_initincludes\classes\Plugin_Service_Provider.php:96
actionadmin_menuincludes\classes\Settings\Settings_Screen.php:34
actionadmin_enqueue_scriptsincludes\classes\Settings\Settings_Screen.php:62
Maintenance & Trust

Altinator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 27, 2025
PHP min version8.2
Downloads280

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Altinator Developer Profile

Fabian Todt

2 plugins · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
27 days
View full developer profile
Detection Fingerprints

How We Detect Altinator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/altinator/vendor/goodwp/common/build/css/admin.css/wp-content/plugins/altinator/vendor/goodwp/common/build/js/admin.js/wp-content/plugins/altinator/modules/frontend-inspector/build/css/frontend-inspector.css/wp-content/plugins/altinator/modules/frontend-inspector/build/js/frontend-inspector.js
Script Paths
/wp-content/plugins/altinator/vendor/goodwp/common/build/js/admin.js/wp-content/plugins/altinator/modules/frontend-inspector/build/js/frontend-inspector.js
Version Parameters
altinator/vendor/goodwp/common/build/css/admin.css?ver=altinator/vendor/goodwp/common/build/js/admin.js?ver=altinator/modules/frontend-inspector/build/css/frontend-inspector.css?ver=altinator/modules/frontend-inspector/build/js/frontend-inspector.js?ver=

HTML / DOM Fingerprints

CSS Classes
altinator-admin-bar-link
Data Attributes
data-altinator
JS Globals
window.__ALTINATOR__
FAQ

Frequently Asked Questions about Altinator