Custom Featured Image Metabox Security & Risk Analysis

wordpress.org/plugins/custom-featured-image-metabox

Custom the title, content and set / remove link text in the Featured Image metabox.

70 active installs v1.0.1 PHP + WP 3.5+ Updated Jan 1, 2015
featured-imagemetabox
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Featured Image Metabox Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Featured Image Metabox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "custom-featured-image-metabox" plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events means there are no readily identifiable public-facing entry points into the plugin's functionality, and consequently, no apparent unprotected attack surface. Furthermore, the code analysis shows no dangerous functions, file operations, external HTTP requests, or bundled libraries, which are common vectors for vulnerabilities. The single SQL query is properly prepared, mitigating risks associated with SQL injection. However, a significant concern arises from the output escaping, where only 20% of the outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, as unsanitized output displayed to users could be manipulated to execute malicious scripts.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, suggesting the developers have either maintained a secure codebase or the plugin has not been a target of widespread security research or exploitation. However, the lack of historical vulnerabilities, coupled with the identified output escaping issue, warrants careful consideration. It's possible the plugin's simplicity has contributed to its security record so far, but the identified weakness needs addressing to maintain this trend. In conclusion, while the plugin demonstrates good practices in several critical security areas and has no known vulnerabilities, the poor output escaping is a notable weakness that requires immediate attention to prevent potential XSS attacks and ensure a robust security profile.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Custom Featured Image Metabox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Featured Image Metabox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
8
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

20% escaped10 total outputs
Attack Surface

Custom Featured Image Metabox Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menuadmin\class-custom-featured-image-metabox-admin.php:73
actionadd_meta_boxesadmin\class-custom-featured-image-metabox-admin.php:79
filteradmin_post_thumbnail_htmladmin\class-custom-featured-image-metabox-admin.php:80
filtermedia_view_stringsadmin\class-custom-featured-image-metabox-admin.php:81
actionadmin_initadmin\includes\settings.php:38
actionplugins_loadedcustom-featured-image-metabox.php:46
actionplugins_loadedcustom-featured-image-metabox.php:59
actioninitpublic\class-custom-featured-image-metabox.php:65
actionadmin_noticespublic\class-custom-featured-image-metabox.php:68
Maintenance & Trust

Custom Featured Image Metabox Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedJan 1, 2015
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Custom Featured Image Metabox Developer Profile

Yoren Chang

6 plugins · 4K total installs

79
trust score
Avg Security Score
87/100
Avg Patch Time
51 days
View full developer profile
Detection Fingerprints

How We Detect Custom Featured Image Metabox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-featured-image-metabox/admin/assets/css/style.css/wp-content/plugins/custom-featured-image-metabox/admin/assets/js/admin.js
Script Paths
/wp-content/plugins/custom-featured-image-metabox/admin/assets/js/admin.js
Version Parameters
custom-featured-image-metabox/admin/assets/css/style.css?ver=custom-featured-image-metabox/admin/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
cfim-instruction
FAQ

Frequently Asked Questions about Custom Featured Image Metabox