
Category Featured Images Extended Security & Risk Analysis
wordpress.org/plugins/category-featured-images-extendedSet images for categories and tags, especially for fallback post thumbnails or featured images.
Is Category Featured Images Extended Safe to Use in 2026?
Use With Caution
Score 63/100Category Featured Images Extended has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'category-featured-images-extended' plugin version 1.52 presents a mixed security posture. While it demonstrates good practices in using prepared statements for SQL queries and has a limited attack surface with no unprotected entry points, several concerns warrant attention. The static analysis reveals a low percentage of properly escaped output, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities, particularly given the plugin's history. Furthermore, the presence of a flow with an unsanitized path in the taint analysis, though not currently rated critical or high, suggests a potential for unexpected behavior or further exploitability when combined with other factors. The plugin's vulnerability history shows a past medium-severity XSS vulnerability, and critically, there is a currently unpatched medium-severity vulnerability. This pattern of past XSS issues combined with an existing unpatched vulnerability in the same vein is a significant concern, suggesting a recurring weakness in input sanitization for output. Overall, while the plugin has some strengths, the unpatched vulnerability and output escaping issues necessitate caution.
Key Concerns
- Currently unpatched medium severity CVE
- Low percentage of properly escaped output
- Flow with unsanitized path (taint analysis)
- Past XSS vulnerability history
Category Featured Images Extended Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Category Featured Images Extended <= 1.52 - Authenticated (Author+) Stored Cross-Site Scripting
Category Featured Images Extended Code Analysis
Output Escaping
Data Flow Analysis
Category Featured Images Extended Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Category Featured Images Extended Maintenance & Trust
Maintenance Signals
Community Trust
Category Featured Images Extended Alternatives
Freundschaft Default Featured Images
freundschaft-default-featured-images
Set a global default featured image and category-specific fallbacks with priority ordering.
Auto Featured Image (Auto Post Thumbnail)
auto-post-thumbnail
Automatically generate, assign, and manage featured images in bulk so every post on your site has a featured image.
Quick Featured Images
quick-featured-images
The time-saving solution for managing tons of featured images within minutes: Set, replace and delete in bulk and set default images for future posts.
Conditionally display featured image on singular posts and pages
conditionally-display-featured-image-on-singular-pages
Easily control whether the featured image appears in the single post or page view (doesn't hide it in archive/list view).
XO Featured Image Tools
xo-featured-image-tools
Automatically generate the featured image from the image of the post.
Category Featured Images Extended Developer Profile
4 plugins · 540 total installs
How We Detect Category Featured Images Extended
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/category-featured-images-extended/settings.php/wp-content/plugins/category-featured-images-extended/js/cfix-media-upload.js/wp-content/plugins/category-featured-images-extended/js/cfix-select-cat-image.jsjs/cfix-media-upload.jsjs/cfix-select-cat-image.jscategory-featured-images-extended/js/cfix-media-upload.js?ver=category-featured-images-extended/js/cfix-select-cat-image.js?ver=HTML / DOM Fingerprints
button_textselect_cat_strings[cfix_featured_image]