Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Security & Risk Analysis

wordpress.org/plugins/bulk-image-title-attribute

Auto-optimize (bulk) your Image title attributes (Image title tags, title text) from page/post/product titles &/or site name or with custom instru …

1K active installs v2.0.1 PHP 5.6+ WP 4.1+ Updated Jan 18, 2026
google-imagesimage-titletitle-attributetitle-tag
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEOct 4, 2025
Download
Safety Verdict

Is Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Safe to Use in 2026?

Mostly Safe

Score 78/100

Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Oct 4, 2025Updated 2mo ago
Risk Assessment

The 'bulk-image-title-attribute' plugin v2.0.1 presents a mixed security posture. While it shows strengths in avoiding dangerous functions, SQL injection vulnerabilities (as evidenced by the high percentage of prepared statements), and file operations, significant concerns arise from its attack surface. Two AJAX handlers are present, and critically, both lack authentication checks. This creates an open door for unauthenticated users to potentially trigger plugin functionality, which could be exploited if vulnerabilities exist within these handlers.

The vulnerability history, specifically a known medium-severity CVE for Cross-Site Scripting (XSS) that is currently unpatched, is a substantial red flag. The fact that the last vulnerability was in 2025 suggests a recent or ongoing issue that has not been addressed. While taint analysis shows no critical or high severity flows, the presence of an unpatched XSS vulnerability, combined with unprotected AJAX endpoints, significantly elevates the risk. This indicates that while some secure coding practices are followed, there are critical blind spots in securing entry points and a failure to address disclosed vulnerabilities.

In conclusion, the plugin has positive aspects like minimal external dependencies and a good approach to SQL querying. However, the unprotected AJAX handlers and the unpatched XSS vulnerability are serious issues that could lead to malicious exploitation. Users should exercise extreme caution and ideally await a patch for the known CVE before relying on this plugin.

Key Concerns

  • Unpatched CVE (Medium severity)
  • Unprotected AJAX handler
  • Unprotected AJAX handler
  • Low output escaping percentage (44%)
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
1

Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62921medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Bulk Auto Image Title Attribute <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 4, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
5 prepared
Unescaped Output
10
8 escaped
Nonce Checks
2
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

83% prepared6 total queries

Output Escaping

44% escaped18 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
save_options (admin\controllers\SettingsController.php:78)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_bigta__optionsadmin\Settings.php:16
authwp_ajax_bigta__onboardingadmin\Settings.php:17
WordPress Hooks 14
filterthe_contentadmin\controllers\DomController.php:12
filterwoocommerce_single_product_image_thumbnail_htmladmin\controllers\DomController.php:13
filterpost_thumbnail_htmladmin\controllers\DomController.php:14
actionsave_postadmin\controllers\MetaboxController.php:10
actionadmin_menuadmin\Settings.php:15
actionadmin_enqueue_scriptsadmin\Settings.php:18
actionadd_meta_boxesadmin\Settings.php:19
filterscript_loader_tagadmin\Settings.php:20
filterconnect_urlbulk-image-title-attribute.php:65
filterafter_skip_urlbulk-image-title-attribute.php:66
filterafter_connect_urlbulk-image-title-attribute.php:67
filterafter_pending_connect_urlbulk-image-title-attribute.php:68
filterconnect_messagebulk-image-title-attribute.php:83
actioninitbulk-image-title-attribute.php:94
Maintenance & Trust

Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 18, 2026
PHP min version5.6
Downloads31K

Community Trust

Rating72/100
Number of ratings5
Active installs1K
Developer Profile

Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) Developer Profile

Pagup

17 plugins · 33K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
439 days
View full developer profile
Detection Fingerprints

How We Detect Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bulk-image-title-attribute/assets/css/style.css/wp-content/plugins/bulk-image-title-attribute/assets/js/script.js
Script Paths
/wp-content/plugins/bulk-image-title-attribute/assets/js/script.js
Version Parameters
bulk-image-title-attribute/assets/css/style.css?ver=bulk-image-title-attribute/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
bigta-container
Data Attributes
data-bigta-override
JS Globals
bigta_plugin_mode
FAQ

Frequently Asked Questions about Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO)