Archive Remote Images Security & Risk Analysis

wordpress.org/plugins/archive-remote-images

Archive Remote Images allows you to scan a post to fetch remote images; then updates its content automatically.

50 active installs v1.0.7 PHP + WP 3.0+ Updated Feb 27, 2015
archive-remote-imagesauto-save-imagescache-imagesgrab-imagesimage-archive
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Archive Remote Images Safe to Use in 2026?

Generally Safe

Score 85/100

Archive Remote Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'archive-remote-images' plugin v1.0.7 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the analysis shows no dangerous functions, all SQL queries using prepared statements, no file operations, and a good use of nonces and capability checks. This indicates diligent development practices focused on preventing common WordPress vulnerabilities.

The plugin does perform one external HTTP request, which is a potential, albeit minor, concern. While not explicitly detailed, the escaping of output is only 67% complete, leaving a small window for potential cross-site scripting (XSS) vulnerabilities if the unescaped data is user-controllable or displayed in a sensitive context.

With zero known CVEs and no recorded vulnerability history, the plugin has a clean track record. This, combined with the robust static analysis findings, suggests a low overall risk. However, the incomplete output escaping warrants a slight deduction to reflect this area of potential, though likely minor, concern.

Key Concerns

  • Output escaping is not fully implemented
Vulnerabilities
None known

Archive Remote Images Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Archive Remote Images Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
1
Capability Checks
6
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

Archive Remote Images Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actioninitarchive-remote-images.php:109
actionadmin_enqueue_scriptsarchive-remote-images.php:112
actionadd_meta_boxesarchive-remote-images.php:115
actionsave_postarchive-remote-images.php:118
actionsave_postarchive-remote-images.php:119
filterari_get_remote_image_urlarchive-remote-images.php:121
filterari_get_image_attributesarchive-remote-images.php:122
filterwp_revisions_to_keeparchive-remote-images.php:319
filterwp_get_attachment_image_attributesarchive-remote-images.php:320
actionsave_postarchive-remote-images.php:332
actionsave_postarchive-remote-images.php:333
actionpre_post_updatearchive-remote-images.php:334
actionadd_attachmentarchive-remote-images.php:561
actionadmin_menuari-settings.php:19
actionadmin_initari-settings.php:20
actionplugins_loadedari-settings.php:21
actionadmin_enqueue_scriptsari-settings.php:22
Maintenance & Trust

Archive Remote Images Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedFeb 27, 2015
PHP min version
Downloads9K

Community Trust

Rating86/100
Number of ratings3
Active installs50
Developer Profile

Archive Remote Images Developer Profile

kasonzhao

2 plugins · 120 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Archive Remote Images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/archive-remote-images/_inc/css/ari-admin.css
Version Parameters
archive-remote-images?ver=_inc/css/ari-admin.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-ari-enabled
JS Globals
ari_metabox_options
FAQ

Frequently Asked Questions about Archive Remote Images