Auto Featured Image (Auto Post Thumbnail) Security & Risk Analysis

wordpress.org/plugins/auto-post-thumbnail

Automatically generate, assign, and manage featured images in bulk so every post on your site has a featured image.

50K active installs v5.0.2 PHP 7.4+ WP 5.6+ Updated Feb 25, 2026
auto-featured-imagefeatured-imagefeatured-image-from-titlepost-thumbnailsthumbnails
92
A · Safe
CVEs total6
Unpatched0
Last CVEDec 15, 2025
Safety Verdict

Is Auto Featured Image (Auto Post Thumbnail) Safe to Use in 2026?

Generally Safe

Score 92/100

Auto Featured Image (Auto Post Thumbnail) has a strong security track record. Known vulnerabilities have been patched promptly.

6 known CVEsLast CVE: Dec 15, 2025Updated 1mo ago
Risk Assessment

The auto-post-thumbnail plugin v5.0.2 exhibits a mixed security posture. While the static analysis shows a very limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events lacking authentication or permission checks, this is significantly undermined by its historical vulnerability record and certain code signals. The plugin has a history of six known CVEs, with one high and five medium severity vulnerabilities. This suggests a pattern of recurring security weaknesses, particularly in areas like missing authorization, SSRF, unrestricted file uploads, and XSS. The most recent vulnerability being in late 2025 is concerning, as it indicates potential for newly discovered or re-emerging issues.

Code analysis reveals some positive aspects such as a high percentage of properly escaped output and a reasonable use of prepared statements for SQL queries. However, the presence of one unsanitized path in taint analysis, while not critical or high severity in this specific run, is a red flag given the plugin's history. The complete absence of nonce checks and a low number of capability checks, especially in conjunction with file operations, raises concerns about how user inputs are handled and potentially lead to unintended actions or information disclosure. The external HTTP requests also present a potential avenue for SSRF if not handled with extreme care.

In conclusion, while the immediate static analysis for v5.0.2 doesn't present critical flaws in terms of entry points, the plugin's past vulnerabilities and specific code signals like unsanitized paths and weak input validation mechanisms warrant caution. Users should be aware of the plugin's history and ensure it's kept updated to the latest version to mitigate previously discovered risks. The lack of proactive security measures like nonce checks is a notable weakness.

Key Concerns

  • One unsanitized taint flow
  • History of 1 High severity CVE
  • History of 5 Medium severity CVEs
  • No nonce checks detected
  • Low number of capability checks (2)
  • File operations present (16)
  • External HTTP requests present (3)
Vulnerabilities
6

Auto Featured Image (Auto Post Thumbnail) Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
1 CVE in 2023
2023
3 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
5

6 total CVEs

CVE-2025-13794medium · 4.3Missing Authorization

Auto Featured Image <= 4.2.1 - Missing Authorization to Authenticated (Contributor+) Post Thumbnail Modification

Dec 15, 2025 Patched in 4.2.2 (58d)
CVE-2024-38719medium · 4.3Missing Authorization

Auto Featured Image (Auto Post Thumbnail) <= 4.1.2 - Missing Authorization

Jul 11, 2024 Patched in 4.1.3 (442d)
CVE-2023-7073medium · 6.4Server-Side Request Forgery (SSRF)

Auto Featured Image (Auto Post Thumbnail) <= 4.1.7 - Authenticated (Author+) Server-Side Request Forgery

May 30, 2024 Patched in 4.2.0 (597d)
CVE-2024-33629medium · 6.4Server-Side Request Forgery (SSRF)

Auto Featured Image (Auto Post Thumbnail) <= 4.1.3 - Authenticated (Author+) Server-Side Request Forgery

Apr 25, 2024 Patched in 4.1.4 (519d)
CVE-2023-0477high · 7.2Unrestricted Upload of File with Dangerous Type

Auto Featured Image (Auto Post Thumbnail) <= 3.9.15 - Authenticated (Author+) Arbitrary File Upload

Feb 7, 2023 Patched in 3.9.16 (350d)
CVE-2021-24932medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Auto Featured Image <= 3.9.2 - Reflected Cross-Site Scripting

Nov 15, 2021 Patched in 3.9.3 (799d)
Code Analysis
Analyzed Mar 16, 2026

Auto Featured Image (Auto Post Thumbnail) Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
3 prepared
Unescaped Output
3
37 escaped
Nonce Checks
0
Capability Checks
2
File Operations
16
External Requests
3
Bundled Libraries
0

SQL Query Safety

60% prepared5 total queries

Output Escaping

93% escaped40 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
add_filter_dropdown (src\Modules\Admin\Posts_List_Table.php:125)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Auto Featured Image (Auto Post Thumbnail) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 25
actionadmin_noticesauto-post-thumbnail.php:96
actionnetwork_admin_noticesauto-post-thumbnail.php:97
actionadmin_noticesauto-post-thumbnail.php:109
filterthemeisle_sdk_productssrc\Loader.php:70
actionadmin_initsrc\Loader.php:72
actionadmin_noticessrc\Loader.php:116
actionshutdownsrc\Logger.php:174
actionadmin_menusrc\Modules\Admin\Main.php:30
actionadmin_enqueue_scriptssrc\Modules\Admin\Main.php:31
actionadmin_noticessrc\Modules\Admin\Main.php:32
filtermanage_post_posts_columnssrc\Modules\Admin\Posts_List_Table.php:41
actionmanage_post_posts_custom_columnsrc\Modules\Admin\Posts_List_Table.php:42
actionrestrict_manage_postssrc\Modules\Admin\Posts_List_Table.php:45
actionpre_get_postssrc\Modules\Admin\Posts_List_Table.php:46
filterviews_edit-postsrc\Modules\Admin\Posts_List_Table.php:47
filterbulk_actions-edit-postsrc\Modules\Admin\Posts_List_Table.php:50
filterhandle_bulk_actions-edit-postsrc\Modules\Admin\Posts_List_Table.php:51
actionadmin_noticessrc\Modules\Admin\Posts_List_Table.php:52
actionadmin_enqueue_scriptssrc\Modules\Admin\Posts_List_Table.php:55
actionrest_api_initsrc\Modules\Api.php:55
actionsave_postsrc\Modules\Auto_Generate.php:50
actiontransition_post_statussrc\Modules\Auto_Generate.php:51
actionadmin_initsrc\Modules\Options.php:27
filtermime_typessrc\Modules\Options.php:28
filterwapt/image_generator_defaultssrc\Routes\Settings.php:190
Maintenance & Trust

Auto Featured Image (Auto Post Thumbnail) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 25, 2026
PHP min version7.4
Downloads1.8M

Community Trust

Rating76/100
Number of ratings117
Active installs50K
Developer Profile

Auto Featured Image (Auto Post Thumbnail) Developer Profile

Themeisle

37 plugins · 2.2M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
420 days
View full developer profile
Detection Fingerprints

How We Detect Auto Featured Image (Auto Post Thumbnail)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-post-thumbnail/assets/build/runtime.js/wp-content/plugins/auto-post-thumbnail/assets/build/dashboard.js/wp-content/plugins/auto-post-thumbnail/assets/build/dashboard.css
Script Paths
/wp-content/plugins/auto-post-thumbnail/assets/build/runtime.js/wp-content/plugins/auto-post-thumbnail/assets/build/dashboard.js
Version Parameters
/wp-content/plugins/auto-post-thumbnail/assets/build/runtime.js?ver=/wp-content/plugins/auto-post-thumbnail/assets/build/dashboard.js?ver=/wp-content/plugins/auto-post-thumbnail/assets/build/dashboard.css?ver=

HTML / DOM Fingerprints

CSS Classes
wapt-dashboard-settings
Data Attributes
data-plugin-slug="auto-post-thumbnail"
JS Globals
window.APTData
FAQ

Frequently Asked Questions about Auto Featured Image (Auto Post Thumbnail)