Auto Product After Upload Image Security & Risk Analysis

wordpress.org/plugins/auto-product-after-upload-image

Upload image and create product automatically. Saves lots of time. This plugin will provide you the facility to create product after uploading each me …

10 active installs v2025.06.25 PHP 5.6+ WP 4.0+ Updated Jun 26, 2025
auto-image-uploadauto-productcreate-product-from-imageimage-productimage-upload
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Auto Product After Upload Image Safe to Use in 2026?

Generally Safe

Score 100/100

Auto Product After Upload Image has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The security posture of the "auto-product-after-upload-image" plugin version 2025.06.25 appears strong based on the provided static analysis. The complete absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and a clean slate in taint analysis for critical and high severity issues are all positive indicators. The plugin also demonstrates good practices by not exposing sensitive functionality through AJAX, REST API, shortcodes, or cron events without proper authentication or authorization, as evidenced by zero unprotected entry points.

However, a significant concern arises from the low percentage of properly escaped output (22%). This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied or dynamic data, if not properly sanitized before being displayed to users, could be exploited to inject malicious scripts. The lack of any recorded vulnerability history is a positive sign, suggesting a history of secure development, but it does not mitigate the identified output escaping issue.

In conclusion, while the plugin exhibits strong architectural security with no apparent critical code execution or data manipulation vulnerabilities identified in the static analysis, the poor output escaping practices present a notable weakness. This needs to be addressed to prevent potential XSS attacks.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

Auto Product After Upload Image Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Auto Product After Upload Image Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

22% escaped9 total outputs
Attack Surface

Auto Product After Upload Image Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptsauto-product-after-upload-image.php:35
actionadmin_menuauto-product-after-upload-image.php:40
actionadd_attachmentauto-product-after-upload-image.php:41
actionadmin_initauto-product-after-upload-image.php:920
actionplugins_loadedauto-product-after-upload-image.php:925
Maintenance & Trust

Auto Product After Upload Image Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedJun 26, 2025
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Auto Product After Upload Image Developer Profile

Quý Lê 91

2 plugins · 410 total installs

62
trust score
Avg Security Score
75/100
Avg Patch Time
154 days
View full developer profile
Detection Fingerprints

How We Detect Auto Product After Upload Image

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-product-after-upload-image/css/main.css/wp-content/plugins/auto-product-after-upload-image/js/main.js
Script Paths
/wp-content/plugins/auto-product-after-upload-image/js/main.js

HTML / DOM Fingerprints

HTML Comments
<!-- 0/8/12/2020 13h:50pm -->
FAQ

Frequently Asked Questions about Auto Product After Upload Image