
Category Featured Images Security & Risk Analysis
wordpress.org/plugins/category-featured-imagesSet a featured image for all the posts of a category.
Is Category Featured Images Safe to Use in 2026?
Use With Caution
Score 63/100Category Featured Images has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "category-featured-images" plugin version 1.1.8 presents a mixed security posture. On the positive side, the static analysis shows no dangerous functions, no file operations, no external HTTP requests, and all SQL queries utilize prepared statements, which are excellent security practices. The total attack surface is minimal, consisting of a single shortcode, and importantly, it appears to have no unprotected entry points. Taint analysis also revealed no vulnerabilities.
However, significant concerns arise from the vulnerability history. The plugin has one known medium-severity CVE, which is currently unpatched. This indicates a past issue related to Cross-Site Scripting (XSS), a common and impactful vulnerability type. The fact that this CVE is recent (September 2025) and unpatched is a major red flag, suggesting a lack of active maintenance or a delayed response to security advisories. Furthermore, the static analysis shows that not all output is properly escaped (63% proper escaping), which, combined with the XSS history, increases the risk of latent XSS vulnerabilities even if not immediately apparent in the taint analysis.
In conclusion, while the code itself demonstrates some good security fundamentals like prepared statements and a limited attack surface, the presence of an unpatched medium-severity CVE and incomplete output escaping significantly detract from its overall security. Users should be cautious, and developers should prioritize patching the known vulnerability and improving output escaping.
Key Concerns
- Unpatched medium severity CVE
- Incomplete output escaping
Category Featured Images Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Category Featured Images <= 1.1.8 - Authenticated (Author+) Stored Cross-Site Scripting
Category Featured Images Code Analysis
Output Escaping
Category Featured Images Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Category Featured Images Maintenance & Trust
Maintenance Signals
Community Trust
Category Featured Images Alternatives
New Recent Posts Select Categories By Thao Marky
new-recent-posts-select-categories-by-thao-marky
Display Recent Posts in your Website with images thumbnail of the Contents.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
List category posts
list-category-posts
Very customizable plugin to list posts by category (or tag, author and more) in a post, page or widget. Uses the [catlist] shortcode to select posts.
Category Posts Widget
category-posts
Adds a widget that shows the most recent posts from a single category.
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Category Featured Images Developer Profile
3 plugins · 910 total installs
How We Detect Category Featured Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/category-featured-images/cfi-styles.css/wp-content/plugins/category-featured-images/category-featured-images.js/wp-content/plugins/category-featured-images/category-featured-images.jscategory-featured-images/cfi-styles.css?ver=category-featured-images/category-featured-images.js?ver=HTML / DOM Fingerprints
cfi-featured-imageid="cfi-featured-image"id="cfi-remove-image"id="cfi-change-image"id="cfi-thumbnail"<span class="cfi-featured-image">