
Broken Image Checker Security & Risk Analysis
wordpress.org/plugins/broken-image-checkerChecks the featured image of any of the post types if they are broken or not.
Is Broken Image Checker Safe to Use in 2026?
Generally Safe
Score 85/100Broken Image Checker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'broken-image-checker' plugin version 2.0 demonstrates a generally good security posture with no known vulnerabilities in its history and a clean record regarding dangerous functions, SQL queries, file operations, and external HTTP requests. The static analysis also shows no identified attack surface through AJAX, REST API, shortcodes, or cron events, and no critical or high-severity taint flows. This indicates that the plugin developers have implemented several key security best practices.
However, there are significant concerns. The extremely low percentage of properly escaped output (14%) is a major red flag. This suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, where user-supplied data could be injected into the web page without proper sanitization, leading to potential unauthorized actions or data theft. Furthermore, the absence of any nonce checks or capability checks on the identified entry points, even though the attack surface is reported as zero, suggests a potential oversight. If any entry points were to be discovered or introduced in future versions, they might be left unprotected. The taint analysis, while not reporting critical or high severity, did reveal unsanitized paths in all analyzed flows, which warrants further investigation.
In conclusion, while the plugin avoids common pitfalls like raw SQL and known CVEs, the severe lack of output escaping presents a substantial risk. The absence of explicit authentication checks on entry points, coupled with the presence of unsanitized paths in taint flows, indicates areas for improvement. The plugin's strength lies in its lack of historical vulnerabilities and its avoidance of direct code execution risks, but the output sanitization issue significantly lowers its overall security score.
Key Concerns
- Low output escaping percentage
- Unsanitized paths in taint flows
- No nonce checks on entry points
- No capability checks on entry points
Broken Image Checker Security Vulnerabilities
Broken Image Checker Code Analysis
Output Escaping
Data Flow Analysis
Broken Image Checker Attack Surface
WordPress Hooks 3
Maintenance & Trust
Broken Image Checker Maintenance & Trust
Maintenance Signals
Community Trust
Broken Image Checker Alternatives
No alternatives data available yet.
Broken Image Checker Developer Profile
4 plugins · 90 total installs
How We Detect Broken Image Checker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/broken-image-checker/assets/bic-style.css/wp-content/plugins/broken-image-checker/assets/bic-custom.js/wp-content/plugins/broken-image-checker/assets/bic-custom.jsbroken-image-checker/assets/bic-style.css?ver=broken-image-checker/assets/bic-custom.js?ver=HTML / DOM Fingerprints
bic-plugin-headerbic-tableid="foo"name="myselect"onchange="self.location=self.location+'&idx='+this.value"