404 Image Redirection (Replace Broken Images) Security & Risk Analysis

wordpress.org/plugins/broken-images-redirection

This plugin will help to replace broken images in posts and pages with a default image. Powerful & easy to use :)

600 active installs v1.4 PHP + WP 4.5+ Updated Jun 15, 2025
404-imagebroken-imagesdefault-imagereplace-404-images
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 4, 2025
Download
Safety Verdict

Is 404 Image Redirection (Replace Broken Images) Safe to Use in 2026?

Mostly Safe

Score 78/100

404 Image Redirection (Replace Broken Images) is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 4, 2025Updated 9mo ago
Risk Assessment

The "broken-images-redirection" plugin version 1.4 exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points indicates a minimal attack surface. Furthermore, the code demonstrates strong practices regarding dangerous function usage, output escaping, and a high percentage of SQL queries utilizing prepared statements. The taint analysis also reveals no critical or high-severity unsanitized flows, suggesting a low risk of common injection vulnerabilities.

However, a significant concern arises from the vulnerability history. The presence of one unpatched medium-severity CVE, last reported in April 2025, indicates a known security flaw that has not yet been addressed. While the plugin's code shows good internal security practices, this unaddressed vulnerability presents a direct and exploitable risk to users. The common vulnerability type of Cross-Site Request Forgery (CSRF) in its history, though not directly highlighted in the current static analysis, suggests a potential weakness in how user actions are handled and authenticated, which could be exacerbated if the unpatched CVE is related to this.

In conclusion, "broken-images-redirection" v1.4 demonstrates a commendable effort in secure coding practices, particularly in preventing common code-level vulnerabilities. The low attack surface and robust output escaping are positive indicators. Nevertheless, the sole unpatched medium-severity CVE is a critical point of concern that significantly lowers its overall security rating. Addressing this known vulnerability should be the top priority for users of this plugin.

Key Concerns

  • Unpatched medium severity CVE
  • 0 Nonce checks on entry points
Vulnerabilities
1

404 Image Redirection (Replace Broken Images) Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32266medium · 4.3Cross-Site Request Forgery (CSRF)

404 Image Redirection (Replace Broken Images) <= 1.4 - Cross-Site Request Forgery

Apr 4, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

404 Image Redirection (Replace Broken Images) Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
2
45 escaped
Nonce Checks
0
Capability Checks
2
File Operations
9
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

67% prepared3 total queries

Output Escaping

96% escaped47 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
broken_image_domain_options_page_html (admin\change.php:55)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

404 Image Redirection (Replace Broken Images) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menuadmin\change.php:6
actionadmin_enqueue_scriptsadmin\change.php:7
actionadmin_print_stylesadmin\change.php:313
actionadmin_menuadmin\setting.php:6
actionadmin_initadmin\setting.php:7
actionadmin_enqueue_scriptsadmin\setting.php:8
actionupdate_option_broken_img_optionsadmin\setting.php:9
actionadmin_print_stylesadmin\setting.php:231
actioninitbroken-images-redirection.php:19
Maintenance & Trust

404 Image Redirection (Replace Broken Images) Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 15, 2025
PHP min version
Downloads9K

Community Trust

Rating70/100
Number of ratings2
Active installs600
Developer Profile

404 Image Redirection (Replace Broken Images) Developer Profile

wp-buy

13 plugins · 355K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
926 days
View full developer profile
Detection Fingerprints

How We Detect 404 Image Redirection (Replace Broken Images)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/broken-images-redirection/admin/js/admin.js/wp-content/plugins/broken-images-redirection/admin/css/admin.css
Script Paths
admin/js/admin.js
Version Parameters
broken-images-redirection/admin/js/admin.js?ver=broken-images-redirection/admin/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
h2_broken_tabs_headerbroken_tabs_header
HTML Comments
# BEGIN All_404_marker_comment_link_# END All_404_marker_comment_link_
Data Attributes
data-id
FAQ

Frequently Asked Questions about 404 Image Redirection (Replace Broken Images)