Cosimo – Change Of Scene Image Many Often Security & Risk Analysis

wordpress.org/plugins/cosimo

Change the background image of the BODY-Tag. A pool of images from Media Library and / or a NextGEN gallery can be used.

10 active installs v0.5 PHP + WP 2.7+ Updated May 9, 2015
backgroundbackgroundscssimages
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cosimo – Change Of Scene Image Many Often Safe to Use in 2026?

Generally Safe

Score 85/100

Cosimo – Change Of Scene Image Many Often has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "cosimo" plugin version 0.5 exhibits a generally positive security posture, characterized by a small attack surface and the absence of known vulnerabilities or critical taint flows. The static analysis indicates no exposed AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no direct entry points for attackers to exploit. The plugin also avoids dangerous functions and external HTTP requests, further reducing potential risks. However, there are some areas for improvement. The lack of output escaping for all identified output points presents a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is directly displayed. Additionally, while there is one nonce check present, the absence of capability checks for any potential internal operations could leave certain functionalities exposed if the attack surface were to expand in future versions. The complete absence of recorded vulnerabilities in its history is a strong indicator of diligent development practices. Overall, "cosimo" v0.5 is a relatively secure plugin, with the primary concern being the unescaped output.

Key Concerns

  • 0% output escaping
  • 0 capability checks
Vulnerabilities
None known

Cosimo – Change Of Scene Image Many Often Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Cosimo – Change Of Scene Image Many Often Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
1 prepared
Unescaped Output
2
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared2 total queries

Output Escaping

0% escaped2 total outputs
Attack Surface

Cosimo – Change Of Scene Image Many Often Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterwp_headcosimo.php:37
actionadmin_menucosimo.php:76
Maintenance & Trust

Cosimo – Change Of Scene Image Many Often Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedMay 9, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Cosimo – Change Of Scene Image Many Often Developer Profile

UnderWordPressure

2 plugins · 50 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cosimo – Change Of Scene Image Many Often

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cosimo/CosimoAdmin.class.php/wp-content/plugins/cosimo/Cosimo.class.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Cosimo – Change Of Scene Image Many Often