
Attachment Slugs for WordPress Security & Risk Analysis
wordpress.org/plugins/attachment-slugEnables permalink support for media attachments making the URLs more friendly and great for SEO.
Is Attachment Slugs for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Attachment Slugs for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The attachment-slug plugin v2.0.0 exhibits a generally good security posture with no known vulnerabilities in its history and a commendable approach to SQL querying with 100% prepared statements. The absence of direct entry points like AJAX handlers, REST API routes, and shortcodes is a significant strength. However, the static analysis reveals two critical taint flows with unsanitized paths, indicating a potential risk of insecure handling of data that could lead to vulnerabilities if these paths are reachable and the data is user-controlled. While the plugin has a large number of output escapings, a portion of these are not properly escaped, which could present a risk for cross-site scripting (XSS) vulnerabilities, though the severity depends on the context of the unescaped output. The lack of capability checks on its functions is a concern, especially if any sensitive operations are performed without proper authorization checks, though the absence of direct entry points mitigates this to some extent. Overall, the plugin's clean vulnerability history and secure SQL practices are positives, but the identified taint flows and unescaped outputs warrant attention.
Key Concerns
- Taint flows with unsanitized paths (High severity)
- Unescaped output found (22%)
- No capability checks
Attachment Slugs for WordPress Security Vulnerabilities
Attachment Slugs for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Attachment Slugs for WordPress Attack Surface
WordPress Hooks 9
Maintenance & Trust
Attachment Slugs for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Attachment Slugs for WordPress Alternatives
Export media with selected content (by DKZR)
export-media-with-selected-content
Include all relevant attachments in your export.
File Upload Types by WPForms
file-upload-types
Easily allow WordPress to accept and upload any file type extension or MIME type, including custom file types.
Lightbox with PhotoSwipe
lightbox-photoswipe
Integration of PhotoSwipe (http://photoswipe.com) for WordPress.
Document Gallery
document-gallery
This plugin generates thumbnails for documents and displays them in a gallery-like format for easy sharing.
Download Attachments
download-attachments
Download Attachments is a new approach to managing downloads in WordPress. It allows you to easily add and display download links in any post or page.
Attachment Slugs for WordPress Developer Profile
15 plugins · 2K total installs
How We Detect Attachment Slugs for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/attachment-slug/admin/views/html-notice-requirement-wp.phpHTML / DOM Fingerprints
misc-pub-attachment-slugattachment_slugid="attachment_slug"