Disable Auto-Sizes Security & Risk Analysis

wordpress.org/plugins/disable-auto-sizes

A lightweight plugin to disable the automatic addition of the auto value in the sizes attribute for images in WordPress.

50 active installs v1.0 PHP 7.2.24+ WP 6.7.1+ Updated Nov 27, 2024
auto-sizesperformanceresponsive-imagessizes-attribute
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Disable Auto-Sizes Safe to Use in 2026?

Generally Safe

Score 92/100

Disable Auto-Sizes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'disable-auto-sizes' v1.0 exhibits an excellent security posture based on the provided static analysis. The complete absence of an attack surface (AJAX handlers, REST API routes, shortcodes, cron events) and the strict adherence to secure coding practices are particularly noteworthy. The code signals indicate no dangerous functions, 100% prepared SQL queries, and 100% properly escaped output, all of which are strong indicators of secure development. Furthermore, the lack of file operations, external HTTP requests, nonce checks, and capability checks, while contributing to a minimal attack surface, also means there are no potential points of failure related to these areas within the plugin's code itself. The taint analysis revealing zero unsanitized paths further reinforces this strong security profile.

The plugin's vulnerability history is entirely clean, with no recorded CVEs, which is a significant strength. This suggests a history of stable and secure development, or at least a lack of publicly discovered vulnerabilities. While the absence of explicit capability checks and nonce checks might seem like a potential concern, it is directly tied to the plugin's minimal attack surface. If there are no entry points for user interaction that would typically require such checks, their absence is not a weakness in this context. However, it is always prudent to consider future extensibility and ensure that if new features are added that introduce an attack surface, these security measures are implemented.

In conclusion, 'disable-auto-sizes' v1.0 is a highly secure plugin. Its strengths lie in its minimal attack surface and strict adherence to secure coding principles as evidenced by the static analysis. The lack of any vulnerability history further solidifies its secure standing. The only minor point of consideration is the implicit reliance on the absence of an attack surface for security, meaning any future expansion of functionality would require careful integration of standard WordPress security practices. Overall, this plugin appears to be very safe to use.

Vulnerabilities
None known

Disable Auto-Sizes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Disable Auto-Sizes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Disable Auto-Sizes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterwp_img_tag_add_auto_sizesdisable-auto-sizes.php:14
Maintenance & Trust

Disable Auto-Sizes Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 27, 2024
PHP min version7.2.24
Downloads997

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Disable Auto-Sizes Developer Profile

Mukesh Panchal

5 plugins · 1K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disable Auto-Sizes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Disable Auto-Sizes