
Auto Generated Images Remover Security & Risk Analysis
wordpress.org/plugins/auto-generated-images-removerShort Description: Scan and remove auto-generated WordPress image thumbnails safely.
Is Auto Generated Images Remover Safe to Use in 2026?
Generally Safe
Score 100/100Auto Generated Images Remover has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "auto-generated-images-remover" plugin version 1.1.2 exhibits a generally good security posture, with no critical or high-severity vulnerabilities identified in its vulnerability history. The static analysis reveals a clean slate regarding dangerous functions, SQL injection risks (all queries use prepared statements), and taint analysis flows. The presence of nonce checks on all AJAX handlers further strengthens its security. However, a concerning weakness is the complete lack of capability checks, meaning any authenticated user, regardless of their role, can interact with the plugin's AJAX endpoints. Additionally, the output escaping is only at 42%, leaving a significant portion of output potentially vulnerable to cross-site scripting (XSS) attacks if the data being output is not inherently safe.
While the plugin boasts a clean vulnerability history and has no known CVEs, the identified weaknesses in capability checks and output escaping represent potential attack vectors. The lack of capability checks is a significant oversight that could allow lower-privileged users to trigger plugin functionality unexpectedly. The insufficient output escaping is a common source of XSS vulnerabilities. Therefore, despite its strengths in other areas, these specific concerns warrant attention for a truly robust security implementation.
Key Concerns
- Lack of capability checks on AJAX handlers
- Low percentage of properly escaped output
Auto Generated Images Remover Security Vulnerabilities
Auto Generated Images Remover Code Analysis
Output Escaping
Auto Generated Images Remover Attack Surface
AJAX Handlers 5
WordPress Hooks 2
Maintenance & Trust
Auto Generated Images Remover Maintenance & Trust
Maintenance Signals
Community Trust
Auto Generated Images Remover Alternatives
Thumbnail Manager
thumbnail-manager
Clean up unused thumbnails with progress; find orphan -WxH files; disable sizes for future uploads.
Thumbs
thumbs
Ein einfaches Tool zur Verwaltung von Thumbnail-Dateien in WordPress. Zählt, listet und löscht generierte Thumbnails und entfernt leere Upload-Ordner, …
Crop-Thumbnails
crop-thumbnails
"Crop Thumbnails" made it easy to get exacly that specific image-detail you want to show in your featured image or gallery image.
iOS images fixer
ios-images-fixer
Automatically fix iOS-taken images' orientation using ImageMagic/PHP GD upon upload.
Optimize Images Resizing
optimize-images-resizing
Plugin optimizes the process of generating custom image sizes in WordPress and offers a cleanup functionality for preexisting images.
Auto Generated Images Remover Developer Profile
2 plugins · 40 total installs
How We Detect Auto Generated Images Remover
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-generated-images-remover/admin.css/wp-content/plugins/auto-generated-images-remover/admin.js/wp-content/plugins/auto-generated-images-remover/admin.jsauto-generated-images-remover/admin.css?ver=auto-generated-images-remover/admin.js?ver=HTML / DOM Fingerprints
mzkgir_vars