Delete Thumbnails Security & Risk Analysis
wordpress.org/plugins/delete-thumbnailsFind and delete thumbnails & resized images from your Media Library
Is Delete Thumbnails Safe to Use in 2026?
Generally Safe
Score 85/100Delete Thumbnails has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "delete-thumbnails" plugin v2.2 exhibits a generally strong security posture with no identified vulnerabilities in its history and a seemingly limited attack surface. The absence of known CVEs and a clean taint analysis report are positive indicators. However, a significant concern arises from the static analysis revealing that 0% of its 13 output operations are properly escaped. This lack of output sanitization presents a notable risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the WordPress admin area or on the frontend, depending on where these outputs are rendered.
While the plugin demonstrates good practices by utilizing prepared statements for SQL queries and includes a nonce check, the complete absence of capability checks on any entry points (though there are no entry points identified) and the lack of output escaping are critical weaknesses. The vulnerability history being entirely clean might suggest the plugin has historically been secure, but this does not negate the immediate risks identified in the current code analysis. The overall assessment is that the plugin has a potentially good foundation but suffers from a critical oversight in output sanitization that needs immediate attention.
Key Concerns
- Outputs are not properly escaped
- No capability checks on entry points
Delete Thumbnails Security Vulnerabilities
Delete Thumbnails Code Analysis
Output Escaping
Delete Thumbnails Attack Surface
WordPress Hooks 3
Maintenance & Trust
Delete Thumbnails Maintenance & Trust
Maintenance Signals
Community Trust
Delete Thumbnails Alternatives
Crop-Thumbnails
crop-thumbnails
"Crop Thumbnails" made it easy to get exacly that specific image-detail you want to show in your featured image or gallery image.
Remove Broken Images
remove-broken-images
Very simply, uses JavaScript to remove broken images from page display.
Thumbnail Updater
thumbnail-updater
A plugin for updating your thumbnails whenever a new thumbnail size is added with add_image_size()
Pro Uploads Cleaner
pro-uploads-cleaner
Scan and clean unused images from your WordPress uploads folder safely.
Trashify – Exclusão de Imagens
trashify-image-deletion
Facilita a exclusão de mídias diretamente da biblioteca do WordPress, de forma segura, organizada e seletiva.
Delete Thumbnails Developer Profile
3 plugins · 210 total installs
How We Detect Delete Thumbnails
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/delete-thumbnails/style.css/wp-content/plugins/delete-thumbnails/dltumbs.js/wp-content/plugins/delete-thumbnails/dltumbs.jsdelete-thumbnails/style.css?ver=delete-thumbnails/dltumbs.js?ver=HTML / DOM Fingerprints
dlthumbsid='dlthumbs'