
Automatic Alternative Text Security & Risk Analysis
wordpress.org/plugins/automatic-alternative-textAutomatically generate alt text for images with Microsoft's Cognitive Services Computer Vision API.
Is Automatic Alternative Text Safe to Use in 2026?
Generally Safe
Score 85/100Automatic Alternative Text has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "automatic-alternative-text" plugin v1.1.4 exhibits a generally good security posture with several positive indicators. The absence of known vulnerabilities in its history, coupled with the use of prepared statements for all SQL queries and proper output escaping, suggests a commitment to secure coding practices. The plugin also avoids dangerous functions and file operations, further reducing its attack surface. However, a significant concern arises from the presence of an unprotected AJAX handler. This single unprotected entry point represents a direct risk, as it can be triggered by unauthenticated users, potentially leading to unintended actions or information disclosure depending on the handler's functionality. While taint analysis found no issues, the lack of nonce checks on the AJAX handler is a direct omission that leaves it vulnerable to Cross-Site Request Forgery (CSRF) attacks.
The plugin's vulnerability history is clean, which is a strong positive. This indicates a low likelihood of previously exploited weaknesses. The limited attack surface, with only one AJAX handler identified, is also beneficial. However, the fact that this single entry point lacks authentication is a notable weakness. The presence of an external HTTP request is not inherently a security risk, but its context would be important for a deeper analysis. Ultimately, the plugin is well-coded in many respects, but the unprotected AJAX handler is a critical oversight that needs immediate attention to mitigate potential security risks.
Key Concerns
- Unprotected AJAX handler
- AJAX handler missing nonce check
Automatic Alternative Text Security Vulnerabilities
Automatic Alternative Text Code Analysis
Output Escaping
Automatic Alternative Text Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Automatic Alternative Text Maintenance & Trust
Maintenance Signals
Community Trust
Automatic Alternative Text Alternatives
ACF Galerie 4
acf-galerie-4
Enhance your WordPress website with ACF Galerie 4, a powerful and customizable gallery plugin.
Polaroid Gallery
polaroid-gallery
Polaroid Gallery is a CSS3 & jQuery Image Gallery plugin for WordPress Media Library.
Scissors and Watermark
scissors-watermark
Scissors and Watermark enhances WordPress' handling of images by introducing cropping, resizing, rotating, and watermarking functionality.
Bubuku Media Library
bubuku-media-library
Manage image file size and alt text in your WordPress Media Library to improve performance, accessibility and SEO.
Full Screen Galleries
full-screen-galleries
Full Screen Galleries creates an automatic full-screen slideshow mode for image galleries in your content. Posts and pages with galleries are automati …
Automatic Alternative Text Developer Profile
1 plugin · 100 total installs
How We Detect Automatic Alternative Text
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/automatic-alternative-text/js/aat-admin.jsautomatic-alternative-text/js/aat-admin.js?ver=HTML / DOM Fingerprints
aat-api-noticeid="aat_endpoint"id="aat_api_key"id="aat_confidence"