
Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Security & Risk Analysis
wordpress.org/plugins/bulk-image-title-attributeAuto-optimize (bulk) your Image title attributes (Image title tags, title text) from page/post/product titles &/or site name or with custom instru …
Is Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Safe to Use in 2026?
Mostly Safe
Score 78/100Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) is generally safe to use. 1 past CVE were resolved. Keep it updated.
The 'bulk-image-title-attribute' plugin v2.0.1 presents a mixed security posture. While it shows strengths in avoiding dangerous functions, SQL injection vulnerabilities (as evidenced by the high percentage of prepared statements), and file operations, significant concerns arise from its attack surface. Two AJAX handlers are present, and critically, both lack authentication checks. This creates an open door for unauthenticated users to potentially trigger plugin functionality, which could be exploited if vulnerabilities exist within these handlers.
The vulnerability history, specifically a known medium-severity CVE for Cross-Site Scripting (XSS) that is currently unpatched, is a substantial red flag. The fact that the last vulnerability was in 2025 suggests a recent or ongoing issue that has not been addressed. While taint analysis shows no critical or high severity flows, the presence of an unpatched XSS vulnerability, combined with unprotected AJAX endpoints, significantly elevates the risk. This indicates that while some secure coding practices are followed, there are critical blind spots in securing entry points and a failure to address disclosed vulnerabilities.
In conclusion, the plugin has positive aspects like minimal external dependencies and a good approach to SQL querying. However, the unprotected AJAX handlers and the unpatched XSS vulnerability are serious issues that could lead to malicious exploitation. Users should exercise extreme caution and ideally await a patch for the known CVE before relying on this plugin.
Key Concerns
- Unpatched CVE (Medium severity)
- Unprotected AJAX handler
- Unprotected AJAX handler
- Low output escaping percentage (44%)
- Bundled outdated library (Freemius v1.0)
Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Bulk Auto Image Title Attribute <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Attack Surface
AJAX Handlers 2
WordPress Hooks 14
Maintenance & Trust
Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Maintenance & Trust
Maintenance Signals
Community Trust
Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Alternatives
Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)
auto-image-attributes-from-filename-with-bulk-updater
Automatically add Image Alt Text, Title, Caption and Description from Filename. Bulk update existing images. Great for Image SEO and Accessibility.
Bulk Auto Image Alt Text (Alt tag, Alt attribute) optimizer (image SEO)
bulk-image-alt-text-with-yoast
Auto optimize all image alt text (+ Woocommerce ), per page & product, from Yoast SEO / Rank Math optimization settings (keywords).
Rel Nofollow Checkbox
rel-nofollow-checkbox
Adds a checkbox in the insert/edit link popup for including rel="nofollow".
Browser Tab Title Reminder
change-browser-tab-title-when-tab-is-not-active
Change the browser tab Title when the tab is not active as a reminder or to get the attention back from the user.
ImageComply – Alt Text Generator
imagecomply
ImageComply can generate alt text for your entire media gallery of images in the click of a button. Time saved, money saved.
Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Developer Profile
17 plugins · 33K total installs
How We Detect Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bulk-image-title-attribute/assets/css/style.css/wp-content/plugins/bulk-image-title-attribute/assets/js/script.js/wp-content/plugins/bulk-image-title-attribute/assets/js/script.jsbulk-image-title-attribute/assets/css/style.css?ver=bulk-image-title-attribute/assets/js/script.js?ver=HTML / DOM Fingerprints
bigta-containerdata-bigta-overridebigta_plugin_mode