
EchBay – JPEG, PNG image compression Security & Risk Analysis
wordpress.org/plugins/echbay-optimize-imagesSpeed up your website. Optimize your JPEG, PNG images with EchBay ( Nhiệm vụ: Dọn dẹp và tối ưu lại hình ảnh hiện có trong thư mục uploads )
Is EchBay – JPEG, PNG image compression Safe to Use in 2026?
Generally Safe
Score 100/100EchBay – JPEG, PNG image compression has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The echbay-optimize-images plugin version 1.1.2 presents a mixed security posture. On the positive side, the plugin has a remarkably small attack surface with zero identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no recorded vulnerabilities (CVEs) in its history, suggesting a history of relatively secure development or limited exposure. However, the static analysis reveals significant concerns regarding code quality and potential security weaknesses.
The most critical issue is the presence of a high-severity taint flow, indicating that unsanitized data is being processed in a way that could lead to vulnerabilities if exploited. Coupled with this, the plugin's handling of SQL queries is problematic. It uses two SQL queries, neither of which utilizes prepared statements, making it vulnerable to SQL injection attacks. Additionally, a very low percentage (7%) of output escaping suggests that sensitive data displayed to users might not be properly sanitized, opening the door for cross-site scripting (XSS) vulnerabilities.
While the lack of known CVEs is reassuring, it should not be seen as a guarantee of complete security, especially given the identified code quality issues. The absence of explicit capability checks and nonce checks on any entry points (which there are none) means that if entry points were ever introduced, they would likely be unprotected. In conclusion, the plugin's minimal attack surface is a strength, but the significant code-level vulnerabilities in data handling and SQL query practices represent a substantial risk that requires immediate attention.
Key Concerns
- High severity taint flow identified
- SQL queries without prepared statements
- Low percentage of properly escaped output
- No capability checks on entry points
- No nonce checks on entry points
EchBay – JPEG, PNG image compression Security Vulnerabilities
EchBay – JPEG, PNG image compression Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
EchBay – JPEG, PNG image compression Attack Surface
WordPress Hooks 2
Maintenance & Trust
EchBay – JPEG, PNG image compression Maintenance & Trust
Maintenance Signals
Community Trust
EchBay – JPEG, PNG image compression Alternatives
Optimize Images Resizing
optimize-images-resizing
Plugin optimizes the process of generating custom image sizes in WordPress and offers a cleanup functionality for preexisting images.
Image SEO – AI-Driven Image SEO Optimizer
imageseo
Improve your images alt, title, captions and filenames for better SEO rankings.
Media Sweep – WordPress Media Cleaner
media-sweep
Clean up your WordPress Media Library by finding and removing unused files. Safely scan, preview, and sweep away orphaned media to keep your site fast …
Cloudimage
cloudimage
The easiest way to resize, compress, optimise and deliver lightning fast images to your users on any device via CDN.
Quick Media Inspect
quick-media-inspect
Detect unused images across your entire WordPress site, clean up your Media Library safely, and generate alt text from filenames.
EchBay – JPEG, PNG image compression Developer Profile
8 plugins · 2K total installs
How We Detect EchBay – JPEG, PNG image compression
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/echbay-optimize-images/includes/js/eoi-settings.js/wp-content/plugins/echbay-optimize-images/includes/css/eoi-settings.cssincludes/js/eoi-settings.jsechbay-optimize-images/includes/js/eoi-settings.js?v=echbay-optimize-images/includes/css/eoi-settings.css?v=