Easy Alt Import Lite Security & Risk Analysis

wordpress.org/plugins/easy-alt-import-lite

Bulk edit image ALT texts from a CSV with preview, selective apply, and one-click undo — improve SEO, image accessibility, and WooCommerce product vis …

0 active installs v2.3.3 PHP 8.0+ WP 5.0+ Updated Dec 5, 2025
alt-textbulk-image-editingcsv-importimage-seomedia-library
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Easy Alt Import Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Easy Alt Import Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "easy-alt-import-lite" v2.3.3 plugin demonstrates a generally good security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points significantly limits the potential attack surface. The plugin also utilizes prepared statements for all SQL queries and includes a reasonable number of capability checks and a nonce check, indicating an awareness of common security best practices. The vulnerability history being clean further reinforces this positive outlook.

However, there are a few areas that warrant attention. The output escaping is only 53% properly handled, meaning a significant portion of its output is not being sanitized, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly validated before being outputted. Additionally, the single file operation and one instance of an unsanitized path flow in the taint analysis, while not critical or high severity, suggest potential areas where malicious input could be used to manipulate file operations or access unintended files. These are minor concerns in the context of the overall clean history and limited attack surface, but they should not be overlooked.

In conclusion, "easy-alt-import-lite" v2.3.3 appears to be a relatively secure plugin with a limited attack surface and no known significant vulnerabilities. The strengths lie in its minimal entry points and adherence to prepared statements for SQL. The primary weaknesses are the concerning percentage of unescaped output and the presence of unsanitized path flows, which, although not currently exploited or leading to high-severity issues, represent potential vectors for vulnerabilities that should be addressed in future development.

Key Concerns

  • Low percentage of properly escaped output
  • Unsanitized path flow detected
Vulnerabilities
None known

Easy Alt Import Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Easy Alt Import Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
75
83 escaped
Nonce Checks
1
Capability Checks
4
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped158 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
process_upload (easy-alt-import-lite.php:415)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Easy Alt Import Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_noticeseasy-alt-import-lite.php:37
actionadmin_menueasy-alt-import-lite.php:663
actionadmin_enqueue_scriptseasy-alt-import-lite.php:664
actionadmin_noticeseasy-alt-import-lite.php:665
actionadmin_post_easy_alt_import_download_templateeasy-alt-import-lite.php:668
actionadmin_post_easy_alt_import_uploadeasy-alt-import-lite.php:669
actionadmin_post_easy_alt_import_applyeasy-alt-import-lite.php:670
actionadmin_post_easy_alt_import_undoeasy-alt-import-lite.php:671
actionplugins_loadedeasy-alt-import-lite.php:1699
actionadmin_noticeseasy-alt-import-lite.php:1709
Maintenance & Trust

Easy Alt Import Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version8.0
Downloads288

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Easy Alt Import Lite Developer Profile

ftmpub

3 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Alt Import Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-alt-import-lite/css/admin.css/wp-content/plugins/easy-alt-import-lite/js/admin.js/wp-content/plugins/easy-alt-import-lite/js/vendor/bootstrap.bundle.min.js/wp-content/plugins/easy-alt-import-lite/js/vendor/jquery.dataTables.min.js/wp-content/plugins/easy-alt-import-lite/js/vendor/dataTables.bootstrap5.min.js
Script Paths
/wp-content/plugins/easy-alt-import-lite/js/admin.js/wp-content/plugins/easy-alt-import-lite/js/vendor/bootstrap.bundle.min.js/wp-content/plugins/easy-alt-import-lite/js/vendor/jquery.dataTables.min.js/wp-content/plugins/easy-alt-import-lite/js/vendor/dataTables.bootstrap5.min.js
Version Parameters
easy-alt-import-lite/css/admin.css?ver=easy-alt-import-lite/js/admin.js?ver=easy-alt-import-lite/js/vendor/bootstrap.bundle.min.js?ver=easy-alt-import-lite/js/vendor/jquery.dataTables.min.js?ver=easy-alt-import-lite/js/vendor/dataTables.bootstrap5.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
easy-alt-import-lite-containereail-header-titleeail-subheadereail-form-uploadeail-csv-preview-tableeail-action-buttons
HTML Comments
<!-- BEGIN Easy Alt Import Lite --><!-- END Easy Alt Import Lite --><!-- Easy Alt Import Lite Settings --><!-- CSV Upload Form -->+1 more
Data Attributes
data-eail-actiondata-eail-security-noncedata-eail-image-iddata-eail-image-alt-text
JS Globals
window.easyAltImport
FAQ

Frequently Asked Questions about Easy Alt Import Lite