
404 Image Redirection (Replace Broken Images) Security & Risk Analysis
wordpress.org/plugins/broken-images-redirectionThis plugin will help to replace broken images in posts and pages with a default image. Powerful & easy to use :)
Is 404 Image Redirection (Replace Broken Images) Safe to Use in 2026?
Mostly Safe
Score 78/100404 Image Redirection (Replace Broken Images) is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "broken-images-redirection" plugin version 1.4 exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points indicates a minimal attack surface. Furthermore, the code demonstrates strong practices regarding dangerous function usage, output escaping, and a high percentage of SQL queries utilizing prepared statements. The taint analysis also reveals no critical or high-severity unsanitized flows, suggesting a low risk of common injection vulnerabilities.
However, a significant concern arises from the vulnerability history. The presence of one unpatched medium-severity CVE, last reported in April 2025, indicates a known security flaw that has not yet been addressed. While the plugin's code shows good internal security practices, this unaddressed vulnerability presents a direct and exploitable risk to users. The common vulnerability type of Cross-Site Request Forgery (CSRF) in its history, though not directly highlighted in the current static analysis, suggests a potential weakness in how user actions are handled and authenticated, which could be exacerbated if the unpatched CVE is related to this.
In conclusion, "broken-images-redirection" v1.4 demonstrates a commendable effort in secure coding practices, particularly in preventing common code-level vulnerabilities. The low attack surface and robust output escaping are positive indicators. Nevertheless, the sole unpatched medium-severity CVE is a critical point of concern that significantly lowers its overall security rating. Addressing this known vulnerability should be the top priority for users of this plugin.
Key Concerns
- Unpatched medium severity CVE
- 0 Nonce checks on entry points
404 Image Redirection (Replace Broken Images) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
404 Image Redirection (Replace Broken Images) <= 1.4 - Cross-Site Request Forgery
404 Image Redirection (Replace Broken Images) Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
404 Image Redirection (Replace Broken Images) Attack Surface
WordPress Hooks 9
Maintenance & Trust
404 Image Redirection (Replace Broken Images) Maintenance & Trust
Maintenance Signals
Community Trust
404 Image Redirection (Replace Broken Images) Alternatives
Broken Link Checker
broken-link-checker
Broken Link Checker helps you catch broken links & images fast, before they hurt your SEO or UX. Scan and bulk-fix issues from one easy dashboard.
All 404 Redirect to Homepage
all-404-redirect-to-homepage
Using this plugin, you can fix all 404 error links by redirecting them to homepage using the SEO 301 redirection. Improve your SEO rank & pages speed
Remove Broken Images
remove-broken-images
Very simply, uses JavaScript to remove broken images from page display.
Schema Default Image
schema-default-image
Add ability to set a default Featured image for schema.org markup, an extension for the Schema plugin.
Default Image Settings
default-image-settings
Change default settings for image size, link to and align for images inserted into posts. Allows you to remove the link on images by default.
404 Image Redirection (Replace Broken Images) Developer Profile
13 plugins · 355K total installs
How We Detect 404 Image Redirection (Replace Broken Images)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/broken-images-redirection/admin/js/admin.js/wp-content/plugins/broken-images-redirection/admin/css/admin.cssadmin/js/admin.jsbroken-images-redirection/admin/js/admin.js?ver=broken-images-redirection/admin/css/admin.css?ver=HTML / DOM Fingerprints
h2_broken_tabs_headerbroken_tabs_header# BEGIN All_404_marker_comment_link_# END All_404_marker_comment_link_data-id