
Automatic File Renamer Security & Risk Analysis
wordpress.org/plugins/automatic-file-renamerAutomatic File Renamer let you rename with prefix or suffix media's name, and redirect attachment pages where you want (3 options).
Is Automatic File Renamer Safe to Use in 2026?
Generally Safe
Score 92/100Automatic File Renamer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'automatic-file-renamer' plugin v0.2.81 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and having no recorded vulnerabilities or CVEs in its history. This suggests a generally well-maintained and secure codebase, with no obvious external threats identified through its vulnerability history.
However, there are notable concerns arising from the static analysis. The presence of a single flow with an unsanitized path is a significant risk, as it could potentially lead to path traversal vulnerabilities if not handled carefully. Additionally, the low percentage of properly escaped output (21%) indicates a high risk of cross-site scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks for its entry points, though the attack surface is currently zero, means that if any entry points were to be introduced in the future without proper authentication, they would be inherently insecure.
While the lack of known vulnerabilities is a good sign, the identified code signals, particularly the unsanitized path flow and the extensive unescaped output, present immediate risks that require attention. Future development should prioritize addressing these areas to improve the plugin's overall security.
Key Concerns
- Unsanitized path flow
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Automatic File Renamer Security Vulnerabilities
Automatic File Renamer Release Timeline
Automatic File Renamer Code Analysis
Output Escaping
Data Flow Analysis
Automatic File Renamer Attack Surface
WordPress Hooks 7
Maintenance & Trust
Automatic File Renamer Maintenance & Trust
Maintenance Signals
Community Trust
Automatic File Renamer Alternatives
Rename Featured Image
rename-featured-image
This plugin uses WordPress hooks and updates the featured image title and file name.
MediaHue – Media Rename & Auto Alt Text
mediahue-media-rename-auto-alt-text
Automatically rename media files and generate alt text, titles, and captions to improve image SEO and accessibility.
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
Phoenix Media Rename
phoenix-media-rename
The Phoenix Media Rename plugin allows you to easily rename (and retitle) your media files, once uploaded.
Export media with selected content (by DKZR)
export-media-with-selected-content
Include all relevant attachments in your export.
Automatic File Renamer Developer Profile
1 plugin · 40 total installs
How We Detect Automatic File Renamer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.