
Crop and Resize Images Security & Risk Analysis
wordpress.org/plugins/crop-and-resize-imagesCrop and Resize Images Plugin allows you to easily modify WordPress uploaded images.
Is Crop and Resize Images Safe to Use in 2026?
Generally Safe
Score 85/100Crop and Resize Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'crop-and-resize-images' plugin version 1.2.4 presents a significant security risk due to its unprotected AJAX handlers. While the plugin avoids dangerous functions and uses prepared statements for its SQL queries, the complete absence of capability and nonce checks on all five identified AJAX entry points is a major concern. This leaves the plugin vulnerable to various attacks, including unauthorized actions and potential cross-site request forgery (CSRF) if these AJAX actions are sensitive. The static analysis also indicates that 100% of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected in the output without sanitization.
The plugin has no recorded vulnerability history, which is a positive sign and suggests a history of secure development. However, this should not overshadow the critical findings from the static analysis, as new vulnerabilities can emerge. The lack of taint analysis results is noted, but the existing code signals, particularly the unescaped output and unprotected AJAX, are sufficient to warrant concern. In conclusion, while the plugin has strengths in its SQL handling and lack of past vulnerabilities, the critical security gaps in its AJAX endpoints and output escaping require immediate attention to mitigate significant risks.
Key Concerns
- AJAX handlers without auth checks
- Output escaping: 0% properly escaped
- Nonce checks: 0
- Capability checks: 0
Crop and Resize Images Security Vulnerabilities
Crop and Resize Images Code Analysis
Output Escaping
Crop and Resize Images Attack Surface
AJAX Handlers 5
WordPress Hooks 6
Maintenance & Trust
Crop and Resize Images Maintenance & Trust
Maintenance Signals
Community Trust
Crop and Resize Images Alternatives
Presswell Art Direction
presswell-art-direction
Control how custom image thumbnail sizes are defined, cropped, and generated.
Multi Image Metabox
multi-image-metabox
Add a multi-image metabox to your posts, pages and custom post types
Acme Fix Images – Regenerate Thumbnails
acme-fix-images
Fix image sizes after you have changed image sizes from Media Settings. Ensure your images display consistently across your website.
WPThumb
wp-thumb
An on-demand image generation replacement for WordPress' image resizing.
Thumbnail Editor
thumbnail-editor
Manually Crop and Resize thumbnail images that are uploaded in the Media section.
Crop and Resize Images Developer Profile
1 plugin · 80 total installs
How We Detect Crop and Resize Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/crop-and-resize-images/css/style.min.css/wp-content/plugins/crop-and-resize-images/css/backbone.modal.min.css/wp-content/plugins/crop-and-resize-images/js/uie-main-script-min.js/wp-content/plugins/crop-and-resize-images/js/backbone.modal.min.js/wp-content/plugins/crop-and-resize-images/img/loader.gifjs/uie-main-script-min.jsjs/backbone.modal.min.jscrop-and-resize-images/css/style.min.css?ver=crop-and-resize-images/css/backbone.modal.min.css?ver=crop-and-resize-images/js/uie-main-script-min.js?ver=crop-and-resize-images/js/backbone.modal.min.js?ver=HTML / DOM Fingerprints
bbm-modal__topbarbbm-modal__titlebbm-buttonbbm-modal__sectionbbm-modal__bottombarappAdd backbone modal template to footerInsert aditional image sizez to 'insert media into post' dropdownInit HookAdmin Enqueue Scripts+1 moreid="modal-template"id="open-crop-and-resize"data-post-idjs_vars/wp-json/uie-get-editor/wp-json/uie-crop-and-save/wp-json/uie-scale-original-image/wp-json/uie-restore-original-image/wp-json/uie-crop-original-image<a id="open-crop-and-resize" data-post-id=" Crop and resize