
Featured Image on Top Security & Risk Analysis
wordpress.org/plugins/featured-image-on-topTired of having to move your "Featured Images" metabox to the top? I've got a fix for that!
Is Featured Image on Top Safe to Use in 2026?
Generally Safe
Score 85/100Featured Image on Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "featured-image-on-top" v1.0 plugin exhibits a mixed security posture. On the positive side, it has a remarkably small attack surface with no registered AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, it has no known historical vulnerabilities (CVEs), suggesting a relatively clean past. The complete absence of raw SQL queries and file operations are also strong indicators of good security practices.
However, there are significant concerns stemming from the static code analysis. The presence of the `unserialize` function is a critical red flag, as it can lead to Remote Code Execution (RCE) vulnerabilities if used with untrusted data. Compounding this risk is the complete lack of output escaping, meaning any data that is outputted could potentially be rendered in an unsafe manner, leading to Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks on any potential entry points (though currently zero) also leaves a door open for future insecure additions.
In conclusion, while the plugin benefits from a small attack surface and no prior vulnerability history, the identified use of `unserialize` and the complete lack of output escaping represent serious security weaknesses that require immediate attention. These are common vectors for severe attacks and should be addressed to improve the plugin's overall security.
Key Concerns
- Unescaped output detected
- Dangerous function 'unserialize' detected
- Missing nonce checks
- Missing capability checks
Featured Image on Top Security Vulnerabilities
Featured Image on Top Code Analysis
Dangerous Functions Found
Output Escaping
Featured Image on Top Attack Surface
WordPress Hooks 2
Maintenance & Trust
Featured Image on Top Maintenance & Trust
Maintenance Signals
Community Trust
Featured Image on Top Alternatives
Acme Fix Images – Regenerate Thumbnails
acme-fix-images
Fix image sizes after you have changed image sizes from Media Settings. Ensure your images display consistently across your website.
WP Random Post Thumbnails
wp-random-post-thumbnails
Allows you to select images to be shown at random for posts without a featured image.
AOC Multiple Post Images
aoc-multiple-post-images
AOC Multiple Post Images allows a user to upload multiple featured images to a post.
Auto Featured Image (Auto Post Thumbnail)
auto-post-thumbnail
Automatically generate, assign, and manage featured images in bulk so every post on your site has a featured image.
Quick Featured Images
quick-featured-images
The time-saving solution for managing tons of featured images within minutes: Set, replace and delete in bulk and set default images for future posts.
Featured Image on Top Developer Profile
4 plugins · 40 total installs
How We Detect Featured Image on Top
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/featured-image-on-top/fit.phpHTML / DOM Fingerprints
name="dws_fit[override-user-custom]"