
Featured Image Resize Security & Risk Analysis
wordpress.org/plugins/featured-image-resizeThis plugin will regenerate all missing image sizes for an image when it's chosen as a featured image for any post. No settings whatsoever.
Is Featured Image Resize Safe to Use in 2026?
Generally Safe
Score 85/100Featured Image Resize has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'featured-image-resize' plugin v0.3 exhibits a concerning security posture due to critical vulnerabilities identified in its static analysis. A significant weakness is the presence of an unprotected AJAX handler, which represents a direct entry point for potential attackers without any authentication or authorization checks. Furthermore, the taint analysis reveals two critical flows with unsanitized paths, indicating that user-supplied data could be manipulated to execute unintended actions or compromise the system. The complete lack of nonce checks on this entry point exacerbates this risk. The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator of past diligence. However, this does not negate the current, severe risks found in the code itself. The plugin's strengths lie in its proper output escaping and lack of dangerous functions or file operations. The primary concern remains the unprotected AJAX endpoint and the identified unsanitized taint flows, which require immediate attention despite the absence of a public vulnerability record.
Key Concerns
- Unprotected AJAX handler
- Critical taint flow with unsanitized path
- Critical taint flow with unsanitized path
- No nonce checks on AJAX handler
- Raw SQL without prepared statements
Featured Image Resize Security Vulnerabilities
Featured Image Resize Code Analysis
SQL Query Safety
Data Flow Analysis
Featured Image Resize Attack Surface
AJAX Handlers 1
Maintenance & Trust
Featured Image Resize Maintenance & Trust
Maintenance Signals
Community Trust
Featured Image Resize Alternatives
Export media with selected content (by DKZR)
export-media-with-selected-content
Include all relevant attachments in your export.
File Upload Types by WPForms
file-upload-types
Easily allow WordPress to accept and upload any file type extension or MIME type, including custom file types.
Lightbox with PhotoSwipe
lightbox-photoswipe
Integration of PhotoSwipe (http://photoswipe.com) for WordPress.
Document Gallery
document-gallery
This plugin generates thumbnails for documents and displays them in a gallery-like format for easy sharing.
Download Attachments
download-attachments
Download Attachments is a new approach to managing downloads in WordPress. It allows you to easily add and display download links in any post or page.
Featured Image Resize Developer Profile
7 plugins · 8K total installs
How We Detect Featured Image Resize
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.