Extended Folder Compression for TinyPNG Security & Risk Analysis

wordpress.org/plugins/extended-folder-compression

Uses the TinyPNG API to bulk optimize images in any directory including nested folders.

10 active installs v1.1.14 PHP + WP 6.0+ Updated Feb 24, 2026
directoryfolder-compressionimage-optimizationtinypng
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Extended Folder Compression for TinyPNG Safe to Use in 2026?

Generally Safe

Score 100/100

Extended Folder Compression for TinyPNG has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "extended-folder-compression" plugin version 1.1.14 exhibits a strong security posture based on the provided static analysis. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate good development practices, with all SQL queries utilizing prepared statements, a high percentage of output being properly escaped, and the presence of nonce and capability checks. The taint analysis also shows no identified flows with unsanitized paths, indicating a low risk of injection vulnerabilities.

The plugin's vulnerability history is exceptionally clean, with zero known CVEs, suggesting a history of secure development and maintenance. This lack of past vulnerabilities further reinforces the positive security assessment. While the static analysis reveals no immediate critical or high-severity flaws, the limited attack surface and robust code signals make this plugin appear very secure. The only area for potential minor improvement, though not a deduction given the current context of other strong signals, would be to ensure all outputs are 100% escaped in future versions, even though the current 88% is generally acceptable for the analyzed code.

In conclusion, "extended-folder-compression" v1.1.14 presents a remarkably secure profile. The minimal attack surface, adherence to secure coding practices like prepared statements and output escaping, and a clean vulnerability history all contribute to a very low-risk assessment. There are no significant weaknesses identified in the provided data that warrant substantial deductions.

Vulnerabilities
None known

Extended Folder Compression for TinyPNG Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Extended Folder Compression for TinyPNG Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
23 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped26 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
efctin_settings (efc_functions.php:79)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Extended Folder Compression for TinyPNG Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuefc_functions.php:20
actionadmin_enqueue_scriptsefc_functions.php:68
actioninitefc_functions.php:268
Maintenance & Trust

Extended Folder Compression for TinyPNG Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 24, 2026
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Extended Folder Compression for TinyPNG Developer Profile

RLDD

8 plugins · 5K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Extended Folder Compression for TinyPNG

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/extended-folder-compression/icon-256x256.png

HTML / DOM Fingerprints

CSS Classes
efctin_err
Data Attributes
id="efctin_form"id="efctin_result"id="efctin_begin"id="efctin_stop"id="efctin_running"id="efctin_optimize"+17 more
JS Globals
efctin_startefctin_runningefctin_stopefctin_E
FAQ

Frequently Asked Questions about Extended Folder Compression for TinyPNG