EyeDrop AI Alt Text Security & Risk Analysis

wordpress.org/plugins/eyedrop-ai-alt-text

Automatically applies AI-generated alt text embedded by EyeDrop for Mac to your WordPress images on upload.

0 active installs v1.0.0 PHP + WP 6.0+ Updated Mar 2, 2026
accessibilityai-alt-textalt-texteyedropimage-metadata
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is EyeDrop AI Alt Text Safe to Use in 2026?

Generally Safe

Score 100/100

EyeDrop AI Alt Text has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "eyedrop-ai-alt-text" v1.0.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any identified critical or high-severity vulnerabilities in its history, coupled with the lack of known CVEs, suggests a well-maintained or recently developed plugin. The code analysis reveals no dangerous functions, no SQL queries without prepared statements, and no external HTTP requests, all of which are strong security indicators. Taint analysis also returned no critical or high-severity issues, further reinforcing its secure foundation.

However, there are areas for improvement. The plugin has a relatively low output escaping rate of 47%, meaning a significant portion of its output is not properly sanitized, potentially exposing it to cross-site scripting (XSS) vulnerabilities. Additionally, the absence of nonce checks across its zero entry points is a concern; while the attack surface is currently zero, if any entry points were to be introduced in future updates without proper nonce validation, it could create security holes. The single file operation, without context, also warrants a closer look to ensure it's handled securely.

Overall, the plugin appears to be built with good security practices in mind, especially regarding database interactions and external communications. The primary risk lies in the insufficient output escaping and the potential for future vulnerabilities if new entry points are added without robust security checks like nonces. Continued vigilance in output sanitization and thorough security reviews for any future updates are recommended.

Key Concerns

  • Low output escaping rate
  • Missing nonce checks on potential future entry points
Vulnerabilities
None known

EyeDrop AI Alt Text Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

EyeDrop AI Alt Text Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
8
7 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

47% escaped15 total outputs
Attack Surface

EyeDrop AI Alt Text Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterwp_generate_attachment_metadataeyedrop-ai-alt-text.php:24
actionadmin_menueyedrop-ai-alt-text.php:26
actionadmin_initeyedrop-ai-alt-text.php:27
Maintenance & Trust

EyeDrop AI Alt Text Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 2, 2026
PHP min version
Downloads132

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

EyeDrop AI Alt Text Developer Profile

EyeDrop AI

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EyeDrop AI Alt Text

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
eyedrop:versioneyedrop:description
FAQ

Frequently Asked Questions about EyeDrop AI Alt Text