
Featured Image Zoom Security & Risk Analysis
wordpress.org/plugins/featured-image-zoomAdd a [zoom] shortcode to display a zoomable featured image.
Is Featured Image Zoom Safe to Use in 2026?
Generally Safe
Score 100/100Featured Image Zoom has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "featured-image-zoom" plugin v2.1.0 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, proper use of prepared statements for SQL queries, and complete output escaping are strong indicators of secure coding practices. The plugin also has no known vulnerabilities or CVEs, which is a positive sign of its stability and maintenance. The limited attack surface, with only one shortcode and no unprotected entry points, further contributes to its strong security profile.
However, a significant concern arises from the complete lack of nonce checks and capability checks. While the static analysis did not identify any specific vulnerabilities stemming from this, it represents a potential gap in security. Without these checks, certain functionalities could theoretically be exploited if an attacker could trick a logged-in user into triggering them. The absence of taint analysis results is also noted, though this may be due to the nature of the plugin's functionality or the limitations of the analysis tool used.
In conclusion, the plugin is currently in a strong security state due to its clean code and lack of historical vulnerabilities. The primary weakness lies in the missing authentication and authorization checks for its entry points, which, while not exploited in this version, present a theoretical risk that should be addressed in future development to maintain its excellent security.
Key Concerns
- Missing nonce checks
- Missing capability checks
Featured Image Zoom Security Vulnerabilities
Featured Image Zoom Code Analysis
Output Escaping
Featured Image Zoom Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Featured Image Zoom Maintenance & Trust
Maintenance Signals
Community Trust
Featured Image Zoom Alternatives
Auto Featured Image (Auto Post Thumbnail)
auto-post-thumbnail
Automatically generate, assign, and manage featured images in bulk so every post on your site has a featured image.
Quick Featured Images
quick-featured-images
The time-saving solution for managing tons of featured images within minutes: Set, replace and delete in bulk and set default images for future posts.
Conditionally display featured image on singular posts and pages
conditionally-display-featured-image-on-singular-pages
Easily control whether the featured image appears in the single post or page view (doesn't hide it in archive/list view).
XO Featured Image Tools
xo-featured-image-tools
Automatically generate the featured image from the image of the post.
Multiple Post Thumbnails
multiple-post-thumbnails
Adds multiple post thumbnails to a post type. If you've ever wanted more than one Featured Image on a post, this plugin is for you.
Featured Image Zoom Developer Profile
17 plugins · 21K total installs
How We Detect Featured Image Zoom
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/featured-image-zoom/js/imagezoom.js/wp-content/plugins/featured-image-zoom/css/imagezoom.cssjs/imagezoom.jsfeatured-image-zoom/js/imagezoom.js?ver=featured-image-zoom/css/imagezoom.css?ver=HTML / DOM Fingerprints
zoomdata-zoomphp_vars<div data-zoom=