Display All Image Sizes Security & Risk Analysis

wordpress.org/plugins/display-all-image-sizes

Displays all sizes of each image, including name, dimensions, and permalink for each size.

1K active installs v1.1.6 PHP + WP 3.5+ Updated May 4, 2017
different-image-sizesimage-sizespicture-sizesview-image-size-linksview-image-sizes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Display All Image Sizes Safe to Use in 2026?

Generally Safe

Score 85/100

Display All Image Sizes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of the "display-all-image-sizes" plugin version 1.1.6 reveals a strong security posture. The absence of any identified attack surface entry points, dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and nonce/capability checks is a significant positive. This indicates that the plugin has been developed with security best practices in mind, minimizing potential vectors for exploitation. The taint analysis further supports this, showing no identified flows with unsanitized paths, meaning sensitive data is unlikely to be mishandled.

The plugin's vulnerability history is also entirely clean, with zero recorded CVEs. This absence of known vulnerabilities, coupled with the robust static analysis results, suggests a well-maintained and secure codebase. While the lack of certain security checks like nonces and capabilities might seem like a concern in isolation, in this specific context, it appears to be a consequence of the plugin's extremely limited functionality and lack of direct user interaction points. The overall conclusion is that this plugin, based on the provided data, presents a very low security risk.

Vulnerabilities
None known

Display All Image Sizes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Display All Image Sizes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Display All Image Sizes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_enqueue_scriptsdisplay-all-image-sizes.php:11
filterattachment_fields_to_editdisplay-all-image-sizes.php:17
filterimage_size_names_choosedisplay-all-image-sizes.php:105
Maintenance & Trust

Display All Image Sizes Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedMay 4, 2017
PHP min version
Downloads27K

Community Trust

Rating100/100
Number of ratings10
Active installs1K
Developer Profile

Display All Image Sizes Developer Profile

pressupinc

3 plugins · 5K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Display All Image Sizes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/display-all-image-sizes/display-all-image-sizes.js/wp-content/plugins/display-all-image-sizes/display-all-image-sizes.css
Script Paths
/wp-content/plugins/display-all-image-sizes/display-all-image-sizes.js
Version Parameters
display-all-image-sizes/display-all-image-sizes.js?ver=display-all-image-sizes/display-all-image-sizes.css?ver=

HTML / DOM Fingerprints

CSS Classes
display-sizesif-jsif-no-js
Data Attributes
id="all-image-sizes-dropdown"id="all-image-sizes-urls"
FAQ

Frequently Asked Questions about Display All Image Sizes