Easy Thumbnail Sizes Security & Risk Analysis
wordpress.org/plugins/easythumbnail-sizesThe easiest way to add custom sized thumbnails to any installed theme. No coding required.
Is Easy Thumbnail Sizes Safe to Use in 2026?
Generally Safe
Score 85/100Easy Thumbnail Sizes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "easythumbnail-sizes" plugin v1.0.1 presents a significant security concern due to its unprotected AJAX handler, which serves as a direct entry point into the application without any authentication or authorization checks. While the static analysis did not identify any dangerous functions, SQL injection vulnerabilities via raw SQL queries, or critical taint flows, the presence of unsanitized paths in taint flows, combined with the complete lack of capability checks and nonce verification, raises alarms. The plugin's history of zero known CVEs is a positive indicator, suggesting a generally stable codebase or low exposure. However, this positive historical data is overshadowed by the immediate and exploitable entry point found in the current version. The limited number of output escaping issues and absence of file operations or external HTTP requests are strengths. Nevertheless, the unprotected AJAX handler is a critical weakness that could be leveraged by an attacker to execute arbitrary actions on the site.
Key Concerns
- Unprotected AJAX handler
- No nonce checks on AJAX
- No capability checks
- SQL queries without prepared statements
- Taint flows with unsanitized paths
Easy Thumbnail Sizes Security Vulnerabilities
Easy Thumbnail Sizes Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Easy Thumbnail Sizes Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Easy Thumbnail Sizes Maintenance & Trust
Maintenance Signals
Community Trust
Easy Thumbnail Sizes Alternatives
Image Processing Queue
image-processing-queue
On-the-fly image processing done right.
WP Crop Stop
wp-crop-stop
Just stop cropping images.
Theme Blvd Featured Image Link Override
theme-blvd-featured-image-link-override
When using a theme with Theme Blvd framework version 2.1+, this plugin allows you to set featured image link options globally throughout your site.
Jump Start Banners
jumpstart-banners
Restores the banner functionality from Jump Start v2.0, when updating to v2.1+.
WP Fake Image Replacer
wp-fake-image-replacer
WP Fake Image Replacer generates fake post thumbnail images. Useful in theme development process. Now works with ACF fields.
Easy Thumbnail Sizes Developer Profile
8 plugins · 2K total installs
How We Detect Easy Thumbnail Sizes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easythumbnail-sizes/EasyThumbnailSizes.js/wp-content/plugins/easythumbnail-sizes/EasyThumbnailSizes.jsHTML / DOM Fingerprints
customize-control-titleid="selectAddImageSize"id="add_button"id="error_message"id="easythumbnailsizes_name"id="easythumbnailsizes_width"id="easythumbnailsizes_height"+5 morevarsi18n