Image lazyloading by Fastseen Security & Risk Analysis

wordpress.org/plugins/fastseen-lazyloading

Boost your website to lightning speed with image lazyloading. Free plan with live chat support available.

0 active installs v1.0.2 PHP 5.4+ WP 4.0+ Updated Jun 12, 2020
fastimage-optimizationlazy-loadlazyloadlazyloading
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image lazyloading by Fastseen Safe to Use in 2026?

Generally Safe

Score 85/100

Image lazyloading by Fastseen has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "fastseen-lazyloading" plugin v1.0.2 presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerability history or dangerous functions. The absence of file operations and external HTTP requests is also a positive indicator. However, significant concerns arise from the static analysis. The plugin exposes a notable attack surface with 2 REST API routes, both of which lack permission callbacks, meaning they are unprotected and can be accessed by any user. Furthermore, the plugin exhibits a critical weakness in output escaping, with 0% of its 7 outputs being properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not sanitized before being displayed.

The taint analysis shows no identified flows, which is a positive sign, but this is in the context of the limited flows analyzed. The lack of nonce checks and capability checks on the identified entry points further exacerbates the risks associated with the unprotected REST API routes. The plugin's current state indicates a need for immediate attention to address the unprotected API endpoints and the prevalent output escaping issues. While the absence of historical vulnerabilities is encouraging, it does not negate the immediate risks identified in the current version's code.

Key Concerns

  • REST API routes without permission callbacks
  • Outputs not properly escaped
  • REST API routes lack capability checks
Vulnerabilities
None known

Image lazyloading by Fastseen Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Image lazyloading by Fastseen Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface
2 unprotected

Image lazyloading by Fastseen Attack Surface

Entry Points2
Unprotected2

REST API Routes 2

POST/wp-json/fastseen/account/authfastseen.php:35
POST/wp-json/fastseen/account/disconnectfastseen.php:41
WordPress Hooks 5
actionadmin_menufastseen.php:25
actionadmin_enqueue_scriptsfastseen.php:28
actionwp_enqueue_scriptsfastseen.php:31
actionrest_api_initfastseen.php:34
actionrest_api_initfastseen.php:40
Maintenance & Trust

Image lazyloading by Fastseen Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 12, 2020
PHP min version5.4
Downloads937

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Image lazyloading by Fastseen Developer Profile

dathoangnd

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image lazyloading by Fastseen

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fastseen-lazyloading/scripts/admin_scripts.js/wp-content/plugins/fastseen-lazyloading/styles/admin_styles.css
Script Paths
https://fastseen.herokuapp.com/cdn/lazyload.js

HTML / DOM Fingerprints

JS Globals
ftsn_scriptsftsn_public_scripts
REST Endpoints
/wp-json/fastseen/account/auth/wp-json/fastseen/account/disconnect
FAQ

Frequently Asked Questions about Image lazyloading by Fastseen