Auto Image Tags Security & Risk Analysis

wordpress.org/plugins/auto-image-tags

Automatically add ALT, TITLE, Caption and Description tags to WordPress media library images.

20 active installs v2.1.0 PHP 7.2+ WP 5.0+ Updated Nov 5, 2025
altimagemediaseotitle
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Auto Image Tags Safe to Use in 2026?

Generally Safe

Score 100/100

Auto Image Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The auto-image-tags v2.1.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. All identified entry points, including 22 AJAX handlers, are protected with nonce and capability checks, indicating a good understanding of WordPress security best practices. The code also demonstrates excellent data handling with 100% of outputs being properly escaped and 89% of SQL queries utilizing prepared statements, which significantly mitigates the risk of common web vulnerabilities like XSS and SQL injection. The absence of dangerous functions, file operations, and critical or high-severity taint flows further reinforces this positive assessment.

While the plugin's internal code hygiene is commendable, a minor area of consideration is the 10 external HTTP requests. Although not inherently a vulnerability, each external request represents a potential dependency on external services, which could introduce risks if those services are compromised or unavailable. The plugin's complete lack of historical vulnerabilities is a significant strength, suggesting a well-maintained and secure development process. The absence of any recorded vulnerabilities over time is a strong indicator of the plugin's current stability and the diligence of its developers.

In conclusion, auto-image-tags v2.1.0 appears to be a very secure plugin. Its robust implementation of authentication and output escaping, combined with a spotless vulnerability history, makes it a low-risk option. The only minor point for awareness is the reliance on external HTTP requests, which is a standard practice but warrants occasional review in a broader security context.

Vulnerabilities
None known

Auto Image Tags Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Auto Image Tags Release Timeline

v2.1.0Current
v2.0.0
Code Analysis
Analyzed Mar 16, 2026

Auto Image Tags Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
16 prepared
Unescaped Output
0
214 escaped
Nonce Checks
22
Capability Checks
22
File Operations
0
External Requests
10
Bundled Libraries
0

SQL Query Safety

89% prepared18 total queries

Output Escaping

100% escaped214 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
ajax_import_settings (auto-image-tags.php:2166)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Auto Image Tags Attack Surface

Entry Points22
Unprotected0

AJAX Handlers 22

authwp_ajax_autoimta_process_existing_imagesauto-image-tags.php:77
authwp_ajax_autoimta_get_images_countauto-image-tags.php:78
authwp_ajax_autoimta_preview_changesauto-image-tags.php:79
authwp_ajax_autoimta_get_filter_optionsauto-image-tags.php:80
authwp_ajax_autoimta_get_remove_statsauto-image-tags.php:81
authwp_ajax_autoimta_remove_tagsauto-image-tags.php:82
authwp_ajax_autoimta_export_settingsauto-image-tags.php:83
authwp_ajax_autoimta_import_settingsauto-image-tags.php:84
authwp_ajax_autoimta_test_translationauto-image-tags.php:85
authwp_ajax_autoimta_get_translation_statsauto-image-tags.php:86
authwp_ajax_autoimta_translate_batchauto-image-tags.php:87
authwp_ajax_autoimta_process_existing_imagestrunk\auto-image-tags.php:77
authwp_ajax_autoimta_get_images_counttrunk\auto-image-tags.php:78
authwp_ajax_autoimta_preview_changestrunk\auto-image-tags.php:79
authwp_ajax_autoimta_get_filter_optionstrunk\auto-image-tags.php:80
authwp_ajax_autoimta_get_remove_statstrunk\auto-image-tags.php:81
authwp_ajax_autoimta_remove_tagstrunk\auto-image-tags.php:82
authwp_ajax_autoimta_export_settingstrunk\auto-image-tags.php:83
authwp_ajax_autoimta_import_settingstrunk\auto-image-tags.php:84
authwp_ajax_autoimta_test_translationtrunk\auto-image-tags.php:85
authwp_ajax_autoimta_get_translation_statstrunk\auto-image-tags.php:86
authwp_ajax_autoimta_translate_batchtrunk\auto-image-tags.php:87
WordPress Hooks 18
actioninitauto-image-tags.php:71
actionadmin_menuauto-image-tags.php:72
actionadmin_initauto-image-tags.php:73
filteradd_attachmentauto-image-tags.php:74
actionadmin_enqueue_scriptsauto-image-tags.php:75
actionwp_enqueue_scriptsauto-image-tags.php:76
actionwoocommerce_new_productauto-image-tags.php:90
actionwoocommerce_update_productauto-image-tags.php:91
filterdetermine_localeauto-image-tags.php:189
actioninittrunk\auto-image-tags.php:71
actionadmin_menutrunk\auto-image-tags.php:72
actionadmin_inittrunk\auto-image-tags.php:73
filteradd_attachmenttrunk\auto-image-tags.php:74
actionadmin_enqueue_scriptstrunk\auto-image-tags.php:75
actionwp_enqueue_scriptstrunk\auto-image-tags.php:76
actionwoocommerce_new_producttrunk\auto-image-tags.php:90
actionwoocommerce_update_producttrunk\auto-image-tags.php:91
filterdetermine_localetrunk\auto-image-tags.php:189
Maintenance & Trust

Auto Image Tags Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 5, 2025
PHP min version7.2
Downloads321

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Auto Image Tags Developer Profile

Bogdan Shapovalov

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Auto Image Tags

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-image-tags/assets/css/admin.css/wp-content/plugins/auto-image-tags/assets/js/admin.js/wp-content/plugins/auto-image-tags/assets/js/build/admin.js/wp-content/plugins/auto-image-tags/assets/js/build/app.js
Script Paths
/wp-content/plugins/auto-image-tags/assets/js/admin.js/wp-content/plugins/auto-image-tags/assets/js/build/admin.js/wp-content/plugins/auto-image-tags/assets/js/build/app.js
Version Parameters
auto-image-tags/assets/css/admin.css?ver=auto-image-tags/assets/js/admin.js?ver=auto-image-tags/assets/js/build/admin.js?ver=auto-image-tags/assets/js/build/app.js?ver=

HTML / DOM Fingerprints

CSS Classes
auto-image-tags-settings
HTML Comments
<!-- Main Image Tags Settings Page --><!-- Process Existing Images Section --><!-- Bulk Actions Section --><!-- Remove Tags Section -->+2 more
Data Attributes
data-autoimta-targetdata-autoimta-action
JS Globals
autoimta_admin_params
REST Endpoints
/wp-json/auto-image-tags/v1/process/wp-json/auto-image-tags/v1/settings
FAQ

Frequently Asked Questions about Auto Image Tags