Display Featured Image for Genesis Security & Risk Analysis

wordpress.org/plugins/display-featured-image-genesis

This plugin works within the Genesis Framework, to display featured images in beautiful and dynamic ways.

1K active installs v3.2.3 PHP 7.4+ WP 5.2+ Updated Nov 11, 2023
bannerfeatured-imagefeatured-imagesgenesisstudiopress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Display Featured Image for Genesis Safe to Use in 2026?

Generally Safe

Score 85/100

Display Featured Image for Genesis has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "display-featured-image-genesis" plugin v3.2.3 exhibits a generally positive security posture, with strong adherence to best practices in several key areas. The complete absence of dangerous functions, file operations, and external HTTP requests is commendable. Furthermore, all SQL queries are secured using prepared statements, and a high percentage of output is properly escaped, minimizing the risk of cross-site scripting (XSS) vulnerabilities. The plugin also demonstrates good use of nonces and capability checks.

However, a significant concern arises from the plugin's attack surface. It exposes two AJAX handlers, both of which lack authentication checks. This is a critical oversight, as it allows any user, regardless of their privileges, to trigger these handlers, potentially leading to unintended actions or information disclosure. While taint analysis shows no current flows, the presence of unprotected entry points creates a high risk that future vulnerabilities could be introduced or exploited.

The plugin's vulnerability history is currently clear, with no recorded CVEs. This, combined with the strong coding practices observed, suggests a developer who is likely aware of security principles. Nevertheless, the unprotected AJAX endpoints represent a notable weakness that should be addressed to maintain a robust security profile.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
None known

Display Featured Image for Genesis Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Display Featured Image for Genesis Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
12
202 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

94% escaped214 total outputs
Attack Surface
2 unprotected

Display Featured Image for Genesis Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_displayfeaturedimagegenesis_blockincludes\widgets\class-displayfeaturedimagegenesis-widgets-blocks.php:43
authwp_ajax_widget_selectorincludes\widgets\displayfeaturedimagegenesis-taxonomy-widget.php:43
WordPress Hooks 59
actionadmin_enqueue_scriptsincludes\class-displayfeaturedimagegenesis-admin.php:20
actionpre_get_postsincludes\class-displayfeaturedimagegenesis-admin.php:21
filtermanage_users_columnsincludes\class-displayfeaturedimagegenesis-admin.php:82
filtermanage_users_custom_columnincludes\class-displayfeaturedimagegenesis-admin.php:83
filterjetpack_photon_override_image_downsizeincludes\class-displayfeaturedimagegenesis-common.php:50
actionadmin_initincludes\class-displayfeaturedimagegenesis.php:109
actionafter_setup_themeincludes\class-displayfeaturedimagegenesis.php:116
actionplugins_loadedincludes\class-displayfeaturedimagegenesis.php:117
actioninitincludes\class-displayfeaturedimagegenesis.php:119
actionadmin_initincludes\class-displayfeaturedimagegenesis.php:122
actionadmin_enqueue_scriptsincludes\class-displayfeaturedimagegenesis.php:123
actionwidgets_initincludes\class-displayfeaturedimagegenesis.php:126
actionwidgets_initincludes\class-displayfeaturedimagegenesis.php:127
actioninitincludes\class-displayfeaturedimagegenesis.php:128
actionadmin_enqueue_scriptsincludes\class-displayfeaturedimagegenesis.php:129
filterdisplayfeaturedimagegenesis_get_taxonomiesincludes\class-displayfeaturedimagegenesis.php:132
actionadmin_initincludes\class-displayfeaturedimagegenesis.php:133
actionadmin_initincludes\class-displayfeaturedimagegenesis.php:134
actionadd_meta_boxesincludes\class-displayfeaturedimagegenesis.php:137
filteradmin_post_thumbnail_htmlincludes\class-displayfeaturedimagegenesis.php:138
actionsave_postincludes\class-displayfeaturedimagegenesis.php:139
actionadmin_menuincludes\class-displayfeaturedimagegenesis.php:142
filterdisplayfeaturedimagegenesis_get_settingincludes\class-displayfeaturedimagegenesis.php:143
actioncustomize_registerincludes\class-displayfeaturedimagegenesis.php:146
actionget_headerincludes\class-displayfeaturedimagegenesis.php:149
filtergenesis_get_image_default_argsincludes\class-displayfeaturedimagegenesis.php:150
actiontemplate_redirectincludes\class-displayfeaturedimagegenesis.php:153
actionadmin_noticesincludes\class-displayfeaturedimagegenesis.php:164
actionprofile_personal_optionsincludes\meta\class-displayfeaturedimagegenesis-author.php:28
actionpersonal_options_updateincludes\meta\class-displayfeaturedimagegenesis-author.php:29
actionedit_user_profileincludes\meta\class-displayfeaturedimagegenesis-author.php:31
actionedit_user_profile_updateincludes\meta\class-displayfeaturedimagegenesis-author.php:32
actionload-edit-tags.phpincludes\meta\class-displayfeaturedimagegenesis-taxonomies.php:46
actionsplit_shared_termincludes\meta\class-displayfeaturedimagegenesis-taxonomies.php:49
actionwp_print_scriptsincludes\output\class-displayfeaturedimagegenesis-enqueue.php:71
filterjetpack_photon_override_image_downsizeincludes\output\class-displayfeaturedimagegenesis-output.php:37
actionwp_enqueue_scriptsincludes\output\class-displayfeaturedimagegenesis-output.php:38
filterbody_classincludes\output\class-displayfeaturedimagegenesis-output.php:55
actiongenesis_before_loopincludes\output\class-displayfeaturedimagegenesis-output.php:146
filterjetpack_photon_override_image_downsizeincludes\output\class-displayfeaturedimagegenesis-output.php:162
actiongenesis_before_loopincludes\output\class-displayfeaturedimagegenesis-output.php:211
filteruser_profile_update_errorsincludes\settings\class-displayfeaturedimagegenesis-settings-validate-image.php:45
actionadmin_initincludes\sixtenpress-shortcodes\includes\class-sixtenpress-shortcodes.php:9
actionadmin_enqueue_scriptsincludes\sixtenpress-shortcodes\includes\class-sixtenpress-shortcodes.php:136
actionmedia_buttonsincludes\sixtenpress-shortcodes\includes\class-sixtenpress-shortcodes.php:144
actionadmin_footerincludes\sixtenpress-shortcodes\includes\class-sixtenpress-shortcodes.php:145
filtersixtenpress_admin_color_pickerincludes\sixtenpress-shortcodes\includes\class-sixtenpress-shortcodes.php:146
filtersixtenpress_shortcode_localizationincludes\sixtenpress-shortcodes\includes\class-sixtenpress-shortcodes.php:148
actionadmin_print_scriptsincludes\sixtenpress-shortcodes\includes\class-sixtenpress-shortcodes.php:187
filtersixtenpress_admin_styleincludes\sixtenpress-shortcodes\includes\class-sixtenpress-shortcodes.php:197
actionsixtenpressshortcodes_loadincludes\sixtenpress-shortcodes\sixtenpress-shortcodes.php:97
actionmuplugins_loadedincludes\sixtenpress-shortcodes\sixtenpress-shortcodes.php:103
actionplugins_loadedincludes\sixtenpress-shortcodes\sixtenpress-shortcodes.php:104
actionafter_setup_themeincludes\sixtenpress-shortcodes\sixtenpress-shortcodes.php:105
actionenqueue_block_editor_assetsincludes\widgets\class-displayfeaturedimagegenesis-widgets-blocks.php:42
actionadmin_enqueue_scriptsincludes\widgets\class-displayfeaturedimagegenesis-widgets-shortcodes-editor.php:33
filtersixtenpress_shortcode_inline_cssincludes\widgets\class-displayfeaturedimagegenesis-widgets.php:45
actionsixtenpress_shortcode_initincludes\widgets\class-displayfeaturedimagegenesis-widgets.php:46
actionsixtenpress_shortcode_modalincludes\widgets\class-displayfeaturedimagegenesis-widgets.php:47
Maintenance & Trust

Display Featured Image for Genesis Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedNov 11, 2023
PHP min version7.4
Downloads86K

Community Trust

Rating98/100
Number of ratings33
Active installs1K
Developer Profile

Display Featured Image for Genesis Developer Profile

Robin Cornett

4 plugins · 17K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
223 days
View full developer profile
Detection Fingerprints

How We Detect Display Featured Image for Genesis

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/display-featured-image-genesis/assets/css/admin-style.css/wp-content/plugins/display-featured-image-genesis/assets/css/customizer-preview.css/wp-content/plugins/display-featured-image-genesis/assets/js/admin-script.js/wp-content/plugins/display-featured-image-genesis/assets/js/customizer-preview.js
Script Paths
/wp-content/plugins/display-featured-image-genesis/assets/js/admin-script.js/wp-content/plugins/display-featured-image-genesis/assets/js/customizer-preview.js
Version Parameters
display-featured-image-genesis/assets/css/admin-style.css?ver=display-featured-image-genesis/assets/css/customizer-preview.css?ver=display-featured-image-genesis/assets/js/admin-script.js?ver=display-featured-image-genesis/assets/js/customizer-preview.js?ver=

HTML / DOM Fingerprints

CSS Classes
display-featured-image-genesis-admin-notice
FAQ

Frequently Asked Questions about Display Featured Image for Genesis