EchBay – JPEG, PNG image compression Security & Risk Analysis

wordpress.org/plugins/echbay-optimize-images

Speed up your website. Optimize your JPEG, PNG images with EchBay ( Nhiệm vụ: Dọn dẹp và tối ưu lại hình ảnh hiện có trong thư mục uploads )

40 active installs v1.1.2 PHP + WP 4.8+ Updated Nov 28, 2025
cleanupimagesmediaoptimizeresizing
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EchBay – JPEG, PNG image compression Safe to Use in 2026?

Generally Safe

Score 100/100

EchBay – JPEG, PNG image compression has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The echbay-optimize-images plugin version 1.1.2 presents a mixed security posture. On the positive side, the plugin has a remarkably small attack surface with zero identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no recorded vulnerabilities (CVEs) in its history, suggesting a history of relatively secure development or limited exposure. However, the static analysis reveals significant concerns regarding code quality and potential security weaknesses.

The most critical issue is the presence of a high-severity taint flow, indicating that unsanitized data is being processed in a way that could lead to vulnerabilities if exploited. Coupled with this, the plugin's handling of SQL queries is problematic. It uses two SQL queries, neither of which utilizes prepared statements, making it vulnerable to SQL injection attacks. Additionally, a very low percentage (7%) of output escaping suggests that sensitive data displayed to users might not be properly sanitized, opening the door for cross-site scripting (XSS) vulnerabilities.

While the lack of known CVEs is reassuring, it should not be seen as a guarantee of complete security, especially given the identified code quality issues. The absence of explicit capability checks and nonce checks on any entry points (which there are none) means that if entry points were ever introduced, they would likely be unprotected. In conclusion, the plugin's minimal attack surface is a strength, but the significant code-level vulnerabilities in data handling and SQL query practices represent a substantial risk that requires immediate attention.

Key Concerns

  • High severity taint flow identified
  • SQL queries without prepared statements
  • Low percentage of properly escaped output
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

EchBay – JPEG, PNG image compression Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

EchBay – JPEG, PNG image compression Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
27
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

7% escaped29 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<compression_page> (includes\compression_page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

EchBay – JPEG, PNG image compression Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menueoi.php:67
actionadmin_initeoi.php:68
Maintenance & Trust

EchBay – JPEG, PNG image compression Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

EchBay – JPEG, PNG image compression Developer Profile

Dao Quoc Dai

8 plugins · 2K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect EchBay – JPEG, PNG image compression

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/echbay-optimize-images/includes/js/eoi-settings.js/wp-content/plugins/echbay-optimize-images/includes/css/eoi-settings.css
Script Paths
includes/js/eoi-settings.js
Version Parameters
echbay-optimize-images/includes/js/eoi-settings.js?v=echbay-optimize-images/includes/css/eoi-settings.css?v=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about EchBay – JPEG, PNG image compression