Bilder Alt Security & Risk Analysis

wordpress.org/plugins/bilder-alt

Generate SEO-optimized and accessible alt texts for your images using AI – directly in WordPress.

30 active installs v1.1.2 PHP 7.4+ WP 6.5+ Updated Feb 1, 2026
accessibilityaialt-textimageseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bilder Alt Safe to Use in 2026?

Generally Safe

Score 100/100

Bilder Alt has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "bilder-alt" v1.1.2 plugin exhibits a generally good security posture, with no critical vulnerabilities detected in static analysis or historical data. The absence of AJAX handlers, shortcodes, cron events, and the protected nature of its REST API routes significantly limit the potential attack surface. The code also demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage of output escaping.

However, there are a few areas for improvement. The plugin performs external HTTP requests, which, while not inherently problematic, can introduce risks if not handled securely and are an area where vulnerabilities have been found in other plugins. Furthermore, the absence of nonce checks is a notable concern, especially given the presence of REST API endpoints, as it could potentially lead to Cross-Site Request Forgery (CSRF) vulnerabilities if these endpoints are not properly secured against unauthorized actions.

The plugin's vulnerability history is clean, with no recorded CVEs. This indicates a history of secure development or a lack of significant historical scrutiny. While positive, it's important to remain vigilant. The strengths of this plugin lie in its limited attack surface and secure database interaction. The primary weaknesses are the potential for CSRF due to missing nonce checks and the general risk associated with external HTTP requests.

Key Concerns

  • No nonce checks on entry points
  • External HTTP requests present
  • 75% output escaping (not 100%)
Vulnerabilities
None known

Bilder Alt Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Bilder Alt Release Timeline

v1.1.2Current
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Bilder Alt Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
18 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

75% escaped24 total outputs
Attack Surface

Bilder Alt Attack Surface

Entry Points2
Unprotected0

REST API Routes 2

POST/wp-json/bilder-alt/v1/generateapi\bilder_alt_rest_api.php:6
GET/wp-json/bilder-alt/v1/creditsapi\bilder_alt_rest_api.php:14
WordPress Hooks 9
actionrest_api_initapi\bilder_alt_rest_api.php:5
actionadmin_noticesbilder-alt.php:23
actionhttp_api_curlhelper\bilder_alt_api_generate_alt_helper.php:30
actionadd_attachmenthooks\bilder_alt_add_attachment_hook.php:13
actioninithooks\bilder_alt_add_attachment_hook.php:17
filtermedia_row_actionsviews\bilder_alt_media_view.php:5
actionadmin_enqueue_scriptsviews\bilder_alt_media_view.php:27
actionadmin_menuviews\bilder_alt_settings_view.php:32
actionadmin_initviews\bilder_alt_settings_view.php:107
Maintenance & Trust

Bilder Alt Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 1, 2026
PHP min version7.4
Downloads535

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

Bilder Alt Developer Profile

Lukas Beck

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bilder Alt

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bilder-alt/assets/bilder-alt.js/wp-content/plugins/bilder-alt/assets/bilder-alt-media.js/wp-content/plugins/bilder-alt/assets/bilder-alt-media-bulk.js/wp-content/plugins/bilder-alt/assets/bilder-alt-list.js
Script Paths
/wp-content/plugins/bilder-alt/assets/bilder-alt.js/wp-content/plugins/bilder-alt/assets/bilder-alt-media.js/wp-content/plugins/bilder-alt/assets/bilder-alt-media-bulk.js/wp-content/plugins/bilder-alt/assets/bilder-alt-list.js
Version Parameters
bilder-alt/assets/bilder-alt.js?ver=bilder-alt/assets/bilder-alt-media.js?ver=bilder-alt/assets/bilder-alt-media-bulk.js?ver=bilder-alt/assets/bilder-alt-list.js?ver=

HTML / DOM Fingerprints

CSS Classes
altgen-button
Data Attributes
data-id
FAQ

Frequently Asked Questions about Bilder Alt