Cloudflare Image Resizing – Optimize & Accelerate Your Images Security & Risk Analysis

wordpress.org/plugins/cf-image-resizing

Optimize images on-the-fly using Cloudflare's Image Resizing service, improving performance and core web vitals.

200 active installs v1.5.9 PHP 7.0+ WP 5.0+ Updated Mar 11, 2026
cloudflareimage-optimizationimage-resizingpagespeedperformance
95
A · Safe
CVEs total1
Unpatched0
Last CVEAug 18, 2025
Safety Verdict

Is Cloudflare Image Resizing – Optimize & Accelerate Your Images Safe to Use in 2026?

Generally Safe

Score 95/100

Cloudflare Image Resizing – Optimize & Accelerate Your Images has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Aug 18, 2025Updated 23d ago
Risk Assessment

The plugin 'cf-image-resizing' v1.5.9 demonstrates a generally good security posture with several robust practices in place. The complete absence of unsanitized paths in taint analysis and the use of prepared statements for all SQL queries are significant strengths. Additionally, the plugin effectively employs nonce and capability checks for its entry points, and the vast majority of its output is properly escaped, minimizing risks of XSS vulnerabilities. The limited attack surface, consisting only of two AJAX handlers with authentication checks, further contributes to its secure design.

Despite these strengths, the plugin's history presents a notable concern: one past critical vulnerability related to 'Code Injection'. While this vulnerability is currently unpatched, its past occurrence highlights a potential area of weakness that requires careful monitoring. The static analysis, however, does not reveal any immediate exploitable code vulnerabilities in the current version, such as dangerous functions, raw SQL, or unescaped outputs in critical areas. The single external HTTP request and two file operations are not inherently risky without further context on their implementation, but warrant consideration during a deeper code review.

In conclusion, 'cf-image-resizing' v1.5.9 benefits from strong foundational security practices. The absence of critical issues in the current static and taint analysis is positive. However, the historical critical vulnerability, even if patched in subsequent versions or addressed in the current one, necessitates vigilance. The overall risk is moderate, leaning towards lower, but the past critical vulnerability prevents a perfect score and suggests that code quality in sensitive areas should be continuously monitored.

Key Concerns

  • Total known CVEs: 1 critical
Vulnerabilities
1

Cloudflare Image Resizing – Optimize & Accelerate Your Images Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Critical
1

1 total CVE

CVE-2025-8723critical · 9.8Improper Control of Generation of Code ('Code Injection')

Cloudflare Image Resizing <= 1.5.6 - Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook

Aug 18, 2025 Patched in 1.5.7 (1d)
Code Analysis
Analyzed Mar 16, 2026

Cloudflare Image Resizing – Optimize & Accelerate Your Images Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
14 escaped
Nonce Checks
2
Capability Checks
2
File Operations
2
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

93% escaped15 total outputs
Attack Surface

Cloudflare Image Resizing – Optimize & Accelerate Your Images Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_cf_image_resizing_save_settingscf-image-resizing.php:672
authwp_ajax_dismiss_cf_image_resizing_admin_noticecf-image-resizing.php:1021
WordPress Hooks 10
filterwp_get_attachment_image_srccf-image-resizing.php:600
filterwp_calculate_image_srcsetcf-image-resizing.php:606
filterwp_get_attachment_urlcf-image-resizing.php:612
filterattribute_escapecf-image-resizing.php:618
filterclean_urlcf-image-resizing.php:624
filterthe_contentcf-image-resizing.php:630
actionadmin_initcf-image-resizing.php:638
actionadmin_menucf-image-resizing.php:670
actionadmin_initcf-image-resizing.php:671
actionadmin_noticescf-image-resizing.php:1007
Maintenance & Trust

Cloudflare Image Resizing – Optimize & Accelerate Your Images Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.0
Downloads16K

Community Trust

Rating90/100
Number of ratings17
Active installs200
Developer Profile

Cloudflare Image Resizing – Optimize & Accelerate Your Images Developer Profile

Mecanik1337

1 plugin · 200 total installs

97
trust score
Avg Security Score
95/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Cloudflare Image Resizing – Optimize & Accelerate Your Images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf-image-resizing/dist/css/style.css/wp-content/plugins/cf-image-resizing/dist/js/admin.js
Script Paths
/wp-content/plugins/cf-image-resizing/dist/js/admin.js
Version Parameters
cf-image-resizing/dist/css/style.css?ver=cf-image-resizing/dist/js/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-cf-image-resizing-options
JS Globals
cf_image_resizing_params
FAQ

Frequently Asked Questions about Cloudflare Image Resizing – Optimize & Accelerate Your Images