Auto Generated Images Remover Security & Risk Analysis

wordpress.org/plugins/auto-generated-images-remover

Short Description: Scan and remove auto-generated WordPress image thumbnails safely.

40 active installs v1.1.2 PHP + WP 5.0+ Updated Sep 30, 2025
cleanupimagesmediaremoverthumbnails
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Auto Generated Images Remover Safe to Use in 2026?

Generally Safe

Score 100/100

Auto Generated Images Remover has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "auto-generated-images-remover" plugin version 1.1.2 exhibits a generally good security posture, with no critical or high-severity vulnerabilities identified in its vulnerability history. The static analysis reveals a clean slate regarding dangerous functions, SQL injection risks (all queries use prepared statements), and taint analysis flows. The presence of nonce checks on all AJAX handlers further strengthens its security. However, a concerning weakness is the complete lack of capability checks, meaning any authenticated user, regardless of their role, can interact with the plugin's AJAX endpoints. Additionally, the output escaping is only at 42%, leaving a significant portion of output potentially vulnerable to cross-site scripting (XSS) attacks if the data being output is not inherently safe.

While the plugin boasts a clean vulnerability history and has no known CVEs, the identified weaknesses in capability checks and output escaping represent potential attack vectors. The lack of capability checks is a significant oversight that could allow lower-privileged users to trigger plugin functionality unexpectedly. The insufficient output escaping is a common source of XSS vulnerabilities. Therefore, despite its strengths in other areas, these specific concerns warrant attention for a truly robust security implementation.

Key Concerns

  • Lack of capability checks on AJAX handlers
  • Low percentage of properly escaped output
Vulnerabilities
None known

Auto Generated Images Remover Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Auto Generated Images Remover Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
11 escaped
Nonce Checks
5
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

42% escaped26 total outputs
Attack Surface

Auto Generated Images Remover Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_mzkgir_scan_imagesauto-generated-images-remover.php:32
authwp_ajax_mzkgir_delete_imagesauto-generated-images-remover.php:33
authwp_ajax_mzkgir_empty_trashauto-generated-images-remover.php:34
authwp_ajax_mzkgir_get_trash_imagesauto-generated-images-remover.php:36
authwp_ajax_mzkgir_restore_imagesauto-generated-images-remover.php:37
WordPress Hooks 2
actionadmin_menuauto-generated-images-remover.php:29
actionadmin_enqueue_scriptsauto-generated-images-remover.php:30
Maintenance & Trust

Auto Generated Images Remover Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 30, 2025
PHP min version
Downloads528

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Auto Generated Images Remover Developer Profile

socialeum

2 plugins · 40 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Auto Generated Images Remover

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-generated-images-remover/admin.css/wp-content/plugins/auto-generated-images-remover/admin.js
Script Paths
/wp-content/plugins/auto-generated-images-remover/admin.js
Version Parameters
auto-generated-images-remover/admin.css?ver=auto-generated-images-remover/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
mzkgir_vars
FAQ

Frequently Asked Questions about Auto Generated Images Remover