Auto Featured Image from Title Security & Risk Analysis

wordpress.org/plugins/auto-featured-image-from-title

Automatically generates an image from the post title of a new or updated post and sets it as the featured image.

1K active installs v2.4 PHP + WP 3.5+ Updated Nov 27, 2024
automatic-featured-imagefeatured-imagefeatured-imagesgenerate-thumbnailgenerate-thumbnails
91
A · Safe
CVEs total1
Unpatched0
Last CVESep 30, 2024
Safety Verdict

Is Auto Featured Image from Title Safe to Use in 2026?

Generally Safe

Score 91/100

Auto Featured Image from Title has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Sep 30, 2024Updated 1yr ago
Risk Assessment

The plugin 'auto-featured-image-from-title' v2.4 demonstrates a generally good security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, or external HTTP requests is highly commendable. Furthermore, the presence of nonce and capability checks indicates an awareness of basic WordPress security principles. However, the historical vulnerability data reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, last patched on September 30, 2024. While currently unpatched, this indicates a potential recurring weakness if not thoroughly addressed and monitored.

The static analysis shows a clean bill of health with zero identified critical or high severity taint flows, and a zero attack surface from common entry points like AJAX handlers, REST API routes, shortcodes, and cron events. This suggests that in its current state, the plugin has minimal direct exposure to common web attack vectors. The plugin's strengths lie in its careful coding practices regarding SQL and output escaping, and its minimal attack surface. The primary concern stems from its vulnerability history, which, despite being addressed, highlights a past susceptibility that warrants vigilance.

Key Concerns

  • Past medium severity XSS vulnerability
Vulnerabilities
1 published

Auto Featured Image from Title Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-8786medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Auto Featured Image from Title <= 2.3 - Reflected Cross-Site Scripting

Sep 30, 2024 Patched in 2.4 (64d)
Version History

Auto Featured Image from Title Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Auto Featured Image from Title Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
33 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped33 total outputs
Attack Surface

Auto Featured Image from Title Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionwp_insert_postauto-featured-image-from-title.php:401
actionadd_meta_boxesauto-featured-image-from-title.php:443
actionsave_postauto-featured-image-from-title.php:473
actionwp_insert_postauto-featured-image-from-title.php:610
actionadmin_enqueue_scriptsauto-featured-image-from-title.php:619
filterplugin_action_linksauto-featured-image-from-title.php:626
actionadmin_initauto-featured-image-from-title.php:628
actionadmin_menuauto-featured-image-from-title.php:662
actionadmin_headauto-featured-image-from-title.php:686
actionadmin_noticesauto-featured-image-from-title.php:838
actionadmin_initauto-featured-image-from-title.php:849
Maintenance & Trust

Auto Featured Image from Title Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 27, 2024
PHP min version
Downloads51K

Community Trust

Rating90/100
Number of ratings11
Active installs1K
Developer Profile

Auto Featured Image from Title Developer Profile

Chris Huff

1 plugin · 1K total installs

82
trust score
Avg Security Score
91/100
Avg Patch Time
64 days
View full developer profile
Detection Fingerprints

How We Detect Auto Featured Image from Title

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-featured-image-from-title/images/wp-content/plugins/auto-featured-image-from-title/fonts

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Auto Featured Image from Title