External Thumbnail Security & Risk Analysis

wordpress.org/plugins/external-thumbnail

Using external images from anywhere to make thumbnail

10K active installs v1.2.1 PHP + WP 3.3+ Updated Jun 17, 2016
external-featured-imageexternal-thumbnailremote-thumbnailthumbnail-via-url
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is External Thumbnail Safe to Use in 2026?

Generally Safe

Score 85/100

External Thumbnail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "external-thumbnail" v1.2.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any detected dangerous functions, raw SQL queries, file operations, or external HTTP requests is a significant positive indicator. Furthermore, the plugin demonstrates good practices in output escaping, with a high percentage of outputs being properly escaped, and it includes capability checks, which are crucial for access control.

However, the analysis reveals a critical absence of nonce checks and a notable lack of any detected taint flows. While the absence of taint flows is positive, the complete lack of any analysis in this area suggests that the taint analysis itself might not be comprehensive or that the plugin's functionality is very limited, which is also suggested by the zero attack surface. The fact that there are no AJAX handlers, REST API routes, shortcodes, or cron events means there are no entry points to analyze for vulnerabilities, which is both a strength (fewer potential attack vectors) and a weakness (limited functionality or scope for security issues).

The plugin's vulnerability history is completely clean, with no recorded CVEs. This, combined with the static analysis findings, suggests that for its current scope, it has likely been developed with security in mind or has not yet been a target for significant security research. The overall conclusion is that the plugin appears secure for its current functionality, but the limited scope and lack of comprehensive taint analysis leave some room for theoretical, albeit unproven, concerns.

Key Concerns

  • No nonce checks detected
  • No taint flow analysis performed
Vulnerabilities
None known

External Thumbnail Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

External Thumbnail Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
6 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped7 total outputs
Attack Surface

External Thumbnail Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionthe_postmain.php:11
filterpost_thumbnail_htmlmain.php:12
actionadd_meta_boxesmain.php:14
actionsave_postmain.php:15
Maintenance & Trust

External Thumbnail Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJun 17, 2016
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs10K
Developer Profile

External Thumbnail Developer Profile

mrtaiw

2 plugins · 10K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect External Thumbnail

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
id="External-Thumbnail"
JS Globals
jQuery
FAQ

Frequently Asked Questions about External Thumbnail