Double Image for Gutenberg Security & Risk Analysis

wordpress.org/plugins/double-image

A custom block designed to insert two images side by side or stacked with optional overlay text.

10 active installs v1.2.1 PHP 5.6+ WP 4.9+ Updated Feb 21, 2019
blocksgallerygutenberggutenberg-blockspage-builder
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Double Image for Gutenberg Safe to Use in 2026?

Generally Safe

Score 85/100

Double Image for Gutenberg has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The double-image plugin v1.2.1 demonstrates a strong security posture based on the provided static analysis. The plugin has a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no known vulnerabilities or CVEs associated with this plugin, nor any history of past security issues. This lack of vulnerabilities and a well-controlled attack surface suggests a development team that is likely security-conscious.

However, a closer look at the code signals reveals a minor area for improvement. While the plugin performs a good job with output escaping (78% properly escaped), there is still a percentage of output that is not being properly sanitized. This, combined with the presence of one nonce check and four capability checks, indicates that while the plugin does implement some security measures, there's a slight potential for information leakage or unauthorized actions if these checks are not consistently applied or if the unescaped outputs are in sensitive contexts. Taint analysis reported zero flows, which is a very positive sign, suggesting that data entered into the plugin is not being improperly propagated in a way that could lead to vulnerabilities.

In conclusion, the double-image plugin v1.2.1 appears to be a relatively safe plugin due to its minimal attack surface and clean vulnerability history. The most significant area to monitor would be the 22% of output that is not properly escaped, as this could present a minor risk if exploited. Overall, the strengths in attack surface management and lack of known vulnerabilities outweigh the minor concerns.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Double Image for Gutenberg Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Double Image for Gutenberg Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
18 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped23 total outputs
Attack Surface

Double Image for Gutenberg Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadeddouble-image.php:99
actionenqueue_block_editor_assetsdouble-image.php:100
filterplugin_row_metaincludes\admin\class-admin-action-links.php:23
actionplugins_loadedincludes\admin\class-admin-checks.php:23
actionadmin_noticesincludes\admin\class-admin-checks.php:38
actionadmin_initincludes\admin\class-admin-feedback.php:83
actionadmin_initincludes\admin\class-admin-feedback.php:84
actionadmin_noticesincludes\admin\class-admin-feedback.php:164
actionenqueue_block_assetsincludes\class-block-assets.php:49
actionenqueue_block_editor_assetsincludes\class-block-assets.php:50
actioninitincludes\class-register-block.php:23
Maintenance & Trust

Double Image for Gutenberg Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedFeb 21, 2019
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Double Image for Gutenberg Developer Profile

Sébastien Dumont

15 plugins · 2K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Double Image for Gutenberg

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/double-image/dist/blocks.style.build.css/wp-content/plugins/double-image/dist/blocks.editor.build.css/wp-content/plugins/double-image/dist/blocks.build.js
Script Paths
/wp-content/plugins/double-image/dist/blocks.build.js
Version Parameters
double-image-style?ver=double-image-editor?ver=double-image-editor?ver=time()

HTML / DOM Fingerprints

JS Globals
double_image_editor_config
FAQ

Frequently Asked Questions about Double Image for Gutenberg