Featured Image Extended Security & Risk Analysis

wordpress.org/plugins/featured-image-extended

Feature Image Extended extends featured image builtin functionality.

0 active installs v1.0.2 PHP 5.2.4+ WP 4.4+ Updated Jun 28, 2018
categoryfeatured-imagepostthemethumbnail
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Featured Image Extended Safe to Use in 2026?

Generally Safe

Score 85/100

Featured Image Extended has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'featured-image-extended' plugin version 1.0.2 exhibits an excellent security posture based on the provided static analysis. The complete absence of identified entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly minimizes its attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions, all SQL queries using prepared statements, and a high percentage of properly escaped output. The lack of file operations, external HTTP requests, and recorded vulnerabilities in its history further reinforces this positive assessment.

While the static analysis reveals no direct vulnerabilities or concerning code patterns, the complete absence of nonce and capability checks across all identified entry points (even though there are none) is a theoretical concern. If any entry points were to be introduced in future versions without proper authentication and authorization mechanisms, it could lead to significant security risks. The lack of taint analysis flows is also notable, suggesting either limited complexity or an absence of detectable vulnerabilities through this method.

In conclusion, 'featured-image-extended' v1.0.2 appears to be a highly secure plugin. Its strengths lie in its minimal attack surface and strong adherence to secure coding practices like prepared statements and output escaping. The only minor point of attention would be the theoretical implication of absent authentication checks on non-existent entry points, which should be a priority if the plugin evolves to include interactive functionalities.

Vulnerabilities
None known

Featured Image Extended Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Featured Image Extended Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
104 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped106 total outputs
Attack Surface

Featured Image Extended Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionplugins_loadedfeatured-image-extended.php:68
actioninitphp\class-featured-image-extended-admin.php:63
actionadmin_menuphp\class-featured-image-extended-admin.php:78
actionadmin_initphp\class-featured-image-extended-admin.php:81
filteradmin_post_thumbnail_htmlphp\class-featured-image-extended-admin.php:131
actionsave_postphp\class-featured-image-extended-admin.php:134
filtermanage_posts_columnsphp\class-featured-image-extended-admin.php:137
filtermanage_pages_columnsphp\class-featured-image-extended-admin.php:138
filterplugin_action_links_featured-image-extended/featured-image-extended.phpphp\class-featured-image-extended-admin.php:142
actionmanage_posts_custom_columnphp\class-featured-image-extended-admin.php:268
actionmanage_pages_custom_columnphp\class-featured-image-extended-admin.php:269
actionquick_edit_custom_boxphp\class-featured-image-extended-admin.php:276
filterpost_thumbnail_htmlphp\class-featured-image-extended.php:83
Maintenance & Trust

Featured Image Extended Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJun 28, 2018
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Featured Image Extended Developer Profile

Enrico Sorcinelli

5 plugins · 1K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Featured Image Extended

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/featured-image-extended/css/admin-featured-image-extended.css/wp-content/plugins/featured-image-extended/js/admin-featured-image-extended.js/wp-content/plugins/featured-image-extended/js/featured-image-extended.js
Script Paths
/wp-content/plugins/featured-image-extended/js/admin-featured-image-extended.js/wp-content/plugins/featured-image-extended/js/featured-image-extended.js
Version Parameters
featured-image-extended/css/admin-featured-image-extended.css?ver=featured-image-extended/js/admin-featured-image-extended.js?ver=featured-image-extended/js/featured-image-extended.js?ver=

HTML / DOM Fingerprints

CSS Classes
featured-image-extended-optionsfeatured-image-extended-wrap
Data Attributes
data-featured-image-extended
JS Globals
featured_image_extended_vars
FAQ

Frequently Asked Questions about Featured Image Extended