Delete Unscaled Images Security & Risk Analysis

wordpress.org/plugins/delete-unscaled-images

Deletes original image files if they have been resized

600 active installs v1.2.4 PHP + WP 5.3+ Updated Apr 15, 2024
imagesmedia-uploader
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Delete Unscaled Images Safe to Use in 2026?

Generally Safe

Score 92/100

Delete Unscaled Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'delete-unscaled-images' v1.2.4 exhibits a very strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is excellent. Furthermore, the code signals indicate a robust approach to security, with no dangerous functions, all SQL queries using prepared statements, and the presence of nonce and capability checks. The clean taint analysis with zero unsanitized paths further reinforces this positive assessment.

While the overall security is commendable, there are minor areas for improvement. The 67% output escaping rate suggests that two out of three outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. Additionally, the presence of file operations, while not inherently dangerous, warrants careful consideration to ensure they are implemented securely and do not expose sensitive files or operations.

The plugin's vulnerability history is also a significant strength, with zero recorded CVEs and no past vulnerabilities. This suggests a history of secure development and maintenance. In conclusion, 'delete-unscaled-images' v1.2.4 appears to be a highly secure plugin, with its strengths far outweighing its minor potential weaknesses. The primary area of focus for improvement would be ensuring all output is properly escaped.

Key Concerns

  • Outputs not properly escaped
Vulnerabilities
None known

Delete Unscaled Images Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Delete Unscaled Images Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

Delete Unscaled Images Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionplugins_loadeddelete-unscaled-images.php:21
filterwp_generate_attachment_metadatadelete-unscaled-images.php:37
actionadmin_menudelete-unscaled-images.php:52
Maintenance & Trust

Delete Unscaled Images Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 15, 2024
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings5
Active installs600
Developer Profile

Delete Unscaled Images Developer Profile

swinggraphics

3 plugins · 1K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Delete Unscaled Images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrap
FAQ

Frequently Asked Questions about Delete Unscaled Images