
Enhanced Captions Security & Risk Analysis
wordpress.org/plugins/enhanced-captionsAllows you to add a title to WordPress captions
Is Enhanced Captions Safe to Use in 2026?
Generally Safe
Score 85/100Enhanced Captions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The enhanced-captions v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The plugin has zero known vulnerabilities, suggesting a history of secure development or infrequent exposure to complex attack vectors. Importantly, all SQL queries are properly prepared, and output is consistently escaped, which are fundamental security practices that prevent common injection and cross-site scripting vulnerabilities. The absence of file operations and external HTTP requests further reduces the attack surface. However, a notable concern is the lack of nonce checks and capability checks across its single entry point (a shortcode). While there are no unauthenticated REST API routes or AJAX handlers to exploit, a shortcode without proper authorization checks could still be a vector for privilege escalation or unauthorized content manipulation if its functionality is sensitive. The bundled TinyMCE library, while common, should ideally be kept updated to prevent potential vulnerabilities in the library itself. Despite these minor concerns, the plugin's overall security is good, with its strengths lying in the robust handling of data and SQL.
Key Concerns
- No nonce checks
- No capability checks
- Bundled TinyMCE library
Enhanced Captions Security Vulnerabilities
Enhanced Captions Code Analysis
Bundled Libraries
Output Escaping
Enhanced Captions Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Enhanced Captions Maintenance & Trust
Maintenance Signals
Community Trust
Enhanced Captions Alternatives
Image Source Control Lite – Show Image Credits and Captions
image-source-control-isc
Show image credits, image captions, and copyrights. Manage image sources and warn if they are missing. The original plugin since 2012.
WP-Cycle Plus Captions
wp-cycle-plus-captions
The WP-Cycle Plus Captions plugin allows you to upload images from your computer, which will then be used to generate a jQuery Cycle Plugin slideshow.
Image Source Overlay
image-source-overlay
With Image Source Overlay you can manage image sources in media library. Plugin will then generate small overlay for every image crediting the origina …
Caption Single Product Images
caption-single-product-images
This plugin displays captions under the product thumbnails on Single Product Pages in the WooCommerce Product Gallery.
Lity – Responsive Lightboxes
lity-responsive-lightboxes
A lightweight, accessible and responsive WordPress lightbox plugin.
Enhanced Captions Developer Profile
3 plugins · 120 total installs
How We Detect Enhanced Captions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/enhanced-captions/js/enhanced-captions.js/wp-content/plugins/enhanced-captions/js/enhanced-captions.js/wp-content/plugins/enhanced-captions/js/enhanced-captions-tinymce.jsenhanced-captions/js/enhanced-captions.js?ver=HTML / DOM Fingerprints
js-add-enhanced-captionenhanced-captionenhanced-caption--titleenhanced-caption--textjs-add-enhanced-caption<figure class="wp-caption enhanced-caption"><div class="enhanced-caption--title"><div class="enhanced-caption--text">