Category Featured Images Extended Security & Risk Analysis

wordpress.org/plugins/category-featured-images-extended

Set images for categories and tags, especially for fallback post thumbnails or featured images.

500 active installs v1.52 PHP 5.6+ WP 3.5.0+ Updated Sep 7, 2017
categoriescategory-featured-imageck-macleodfeatured-imagethumbnail
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Category Featured Images Extended Safe to Use in 2026?

Use With Caution

Score 63/100

Category Featured Images Extended has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 8yr ago
Risk Assessment

The 'category-featured-images-extended' plugin version 1.52 presents a mixed security posture. While it demonstrates good practices in using prepared statements for SQL queries and has a limited attack surface with no unprotected entry points, several concerns warrant attention. The static analysis reveals a low percentage of properly escaped output, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities, particularly given the plugin's history. Furthermore, the presence of a flow with an unsanitized path in the taint analysis, though not currently rated critical or high, suggests a potential for unexpected behavior or further exploitability when combined with other factors. The plugin's vulnerability history shows a past medium-severity XSS vulnerability, and critically, there is a currently unpatched medium-severity vulnerability. This pattern of past XSS issues combined with an existing unpatched vulnerability in the same vein is a significant concern, suggesting a recurring weakness in input sanitization for output. Overall, while the plugin has some strengths, the unpatched vulnerability and output escaping issues necessitate caution.

Key Concerns

  • Currently unpatched medium severity CVE
  • Low percentage of properly escaped output
  • Flow with unsanitized path (taint analysis)
  • Past XSS vulnerability history
Vulnerabilities
1

Category Featured Images Extended Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-57920medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Category Featured Images Extended <= 1.52 - Authenticated (Author+) Stored Cross-Site Scripting

Sep 22, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Category Featured Images Extended Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
9 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped31 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
category_edit_form (category-featured-images-extended.php:264)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Category Featured Images Extended Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[cfix_featured_image] category-featured-images-extended.php:53
WordPress Hooks 13
actionadmin_print_scriptscategory-featured-images-extended.php:28
actionadmin_print_stylescategory-featured-images-extended.php:31
actioncategory_edit_formcategory-featured-images-extended.php:33
actionedited_categorycategory-featured-images-extended.php:35
actionseries_edit_formcategory-featured-images-extended.php:36
actionedited_seriescategory-featured-images-extended.php:38
actionpost_tag_edit_formcategory-featured-images-extended.php:39
actionedited_post_tagcategory-featured-images-extended.php:41
actionadmin_initcategory-featured-images-extended.php:42
actionadmin_menucategory-featured-images-extended.php:43
actionplugins_loadedcategory-featured-images-extended.php:44
actioninitcategory-featured-images-extended.php:45
filterget_post_metadatacategory-featured-images-extended.php:49
Maintenance & Trust

Category Featured Images Extended Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 7, 2017
PHP min version5.6
Downloads10K

Community Trust

Rating88/100
Number of ratings7
Active installs500
Developer Profile

Category Featured Images Extended Developer Profile

CK MacLeod

4 plugins · 540 total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Category Featured Images Extended

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/category-featured-images-extended/settings.php/wp-content/plugins/category-featured-images-extended/js/cfix-media-upload.js/wp-content/plugins/category-featured-images-extended/js/cfix-select-cat-image.js
Script Paths
js/cfix-media-upload.jsjs/cfix-select-cat-image.js
Version Parameters
category-featured-images-extended/js/cfix-media-upload.js?ver=category-featured-images-extended/js/cfix-select-cat-image.js?ver=

HTML / DOM Fingerprints

JS Globals
button_textselect_cat_strings
Shortcode Output
[cfix_featured_image]
FAQ

Frequently Asked Questions about Category Featured Images Extended