AOC Multiple Post Images Security & Risk Analysis

wordpress.org/plugins/aoc-multiple-post-images

AOC Multiple Post Images allows a user to upload multiple featured images to a post.

10 active installs v0.4 PHP 5.2.4+ WP 4.6+ Updated Sep 4, 2019
multiple-featured-imagespost-thumbnails
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AOC Multiple Post Images Safe to Use in 2026?

Generally Safe

Score 85/100

AOC Multiple Post Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "aoc-multiple-post-images" plugin version 0.4 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any entry points like AJAX handlers, REST API routes, or shortcodes significantly limits the plugin's attack surface. Furthermore, the code analysis reveals excellent security practices, including 100% proper output escaping and the use of prepared statements for all SQL queries, which is a critical defense against SQL injection. The presence of a nonce check is also a positive sign, indicating an attempt to prevent CSRF attacks. The lack of any recorded vulnerabilities, past or present, is highly encouraging and suggests a well-maintained and secure codebase.

While the analysis indicates a very secure plugin, the absence of any detected taint flows, while generally good, could also mean that the scope of the taint analysis was limited or that the plugin's functionality does not involve complex data handling that would typically trigger such flows. However, given the other positive indicators, this is a minor observation rather than a significant concern. The plugin appears to be a secure and reliable option for its intended functionality.

Vulnerabilities
None known

AOC Multiple Post Images Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AOC Multiple Post Images Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Attack Surface

AOC Multiple Post Images Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadd_meta_boxesaoc-multiple-post-images.php:16
actionsave_postaoc-multiple-post-images.php:53
actionadmin_enqueue_scriptsaoc-multiple-post-images.php:55
Maintenance & Trust

AOC Multiple Post Images Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedSep 4, 2019
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

AOC Multiple Post Images Developer Profile

ankittiwaari

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AOC Multiple Post Images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aoc-multiple-post-images/assets/js/admin.js/wp-content/plugins/aoc-multiple-post-images/assets/css/admin.css
Script Paths
/wp-content/plugins/aoc-multiple-post-images/assets/js/admin.js
Version Parameters
aoc-multiple-post-images/assets/js/admin.js?ver=aoc-multiple-post-images/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
aoc-img-containeraoc-img-wrapaoc-del-imgaoc_add_image_link
Data Attributes
name="aoc_save_img_nonce"data-img-id
FAQ

Frequently Asked Questions about AOC Multiple Post Images