Filikod – ALT Text Audit & Bulk Management Security & Risk Analysis

wordpress.org/plugins/filikod

Audit every image in your media library, get an ALT Quality Score, and fix missing or weak ALT text in bulk. No AI. No external API. Full control.

80 active installs v1.0.7 PHP 7.4+ WP 5.8+ Updated Mar 7, 2026
accessibilityalt-auditalt-textimage-seomedia-library
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Filikod – ALT Text Audit & Bulk Management Safe to Use in 2026?

Generally Safe

Score 100/100

Filikod – ALT Text Audit & Bulk Management has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 26d ago
Risk Assessment

The "filikod" plugin v1.0.7 demonstrates generally strong security practices, particularly in its use of prepared statements for SQL queries and proper output escaping, with very few exceptions noted in the static analysis. The plugin also incorporates a healthy number of nonce and capability checks, indicating an awareness of common WordPress security mechanisms. The absence of known CVEs and a clean vulnerability history further contribute to a positive security outlook, suggesting the plugin has historically been maintained with security in mind.

However, the taint analysis reveals a significant concern: four out of five analyzed flows have unsanitized paths. While no critical or high severity taint flows were explicitly identified in this specific analysis, unsanitized paths are a direct precursor to potential path traversal vulnerabilities, which could allow attackers to access or manipulate files outside of the intended directory. This is a key area for improvement. The plugin's attack surface, while small and seemingly protected by authentication, would benefit from a review of the AJAX handlers to ensure the zero unprotected entry points remain accurate and robust.

In conclusion, "filikod" v1.0.7 presents a largely secure profile with robust handling of database interactions and output. The primary weakness identified is the presence of unsanitized paths in the taint analysis, which introduces a notable risk that needs to be addressed. Addressing this specific finding in the taint analysis would elevate the plugin's security posture to an even higher level.

Key Concerns

  • Flows with unsanitized paths detected
Vulnerabilities
None known

Filikod – ALT Text Audit & Bulk Management Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Filikod – ALT Text Audit & Bulk Management Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
24 prepared
Unescaped Output
5
152 escaped
Nonce Checks
8
Capability Checks
12
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

96% prepared25 total queries

Output Escaping

97% escaped157 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

5 flows4 with unsanitized paths
<alt-audit> (admin\views\alt-audit.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Filikod – ALT Text Audit & Bulk Management Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_filikod_save_altincludes\dashboard\class-filikod-dashboard.php:16
authwp_ajax_filikod_get_total_images_countincludes\settings\class-filikod-settings.php:79
authwp_ajax_filikod_process_existing_images_resize_batchincludes\settings\class-filikod-settings.php:82
authwp_ajax_filikod_get_total_images_count_accessibilityincludes\settings\class-filikod-settings.php:85
authwp_ajax_filikod_process_existing_images_accessibility_batchincludes\settings\class-filikod-settings.php:88
WordPress Hooks 18
actioninitfilikod.php:191
actioninitfilikod.php:193
actionadd_attachmentincludes\accessibility\class-filikod-accessibility.php:81
filterwp_get_attachment_image_attributesincludes\accessibility\class-filikod-accessibility.php:87
actionadmin_menuincludes\admin\class-filikod-admin.php:23
actionadmin_enqueue_scriptsincludes\admin\class-filikod-admin.php:24
actionadmin_footerincludes\admin\class-filikod-admin.php:25
filterupload_mimesincludes\file-types\class-filikod-file-types.php:109
filterwp_handle_upload_prefilterincludes\file-types\class-filikod-file-types.php:115
filterwp_handle_uploadincludes\file-types\class-filikod-file-types.php:121
filterwp_check_filetype_and_extincludes\file-types\class-filikod-file-types.php:127
actiontemplate_redirectincludes\file-types\class-filikod-file-types.php:133
filterbig_image_size_thresholdincludes\optimizations\class-filikod-image-resizer.php:127
filterwp_generate_attachment_metadataincludes\optimizations\class-filikod-image-resizer.php:139
actionadd_attachmentincludes\optimizations\class-filikod-image-resizer.php:148
actionafter_setup_themeincludes\optimizations\class-filikod-image-resizer.php:157
filterwp_generate_attachment_metadataincludes\optimizations\class-filikod-image-resizer.php:1066
actionadmin_initincludes\settings\class-filikod-settings.php:70
Maintenance & Trust

Filikod – ALT Text Audit & Bulk Management Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 7, 2026
PHP min version7.4
Downloads644

Community Trust

Rating100/100
Number of ratings4
Active installs80
Developer Profile

Filikod – ALT Text Audit & Bulk Management Developer Profile

Filikod

2 plugins · 110 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Filikod – ALT Text Audit & Bulk Management

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/filikod/assets/css/admin.css/wp-content/plugins/filikod/assets/css/dashboard.css/wp-content/plugins/filikod/assets/css/main.css/wp-content/plugins/filikod/assets/js/admin.js/wp-content/plugins/filikod/assets/js/dashboard.js/wp-content/plugins/filikod/assets/js/filikod-backend.js/wp-content/plugins/filikod/assets/js/filikod-frontend.js/wp-content/plugins/filikod/assets/js/vendor/jquery.js+1 more
Script Paths
/wp-content/plugins/filikod/assets/js/admin.js/wp-content/plugins/filikod/assets/js/dashboard.js/wp-content/plugins/filikod/assets/js/filikod-backend.js/wp-content/plugins/filikod/assets/js/filikod-frontend.js/wp-content/plugins/filikod/assets/js/vendor/jquery.js/wp-content/plugins/filikod/assets/js/vendor/select2.js
Version Parameters
filikod/assets/css/admin.css?ver=filikod/assets/css/dashboard.css?ver=filikod/assets/css/main.css?ver=filikod/assets/js/admin.js?ver=filikod/assets/js/dashboard.js?ver=filikod/assets/js/filikod-backend.js?ver=filikod/assets/js/filikod-frontend.js?ver=filikod/assets/js/vendor/jquery.js?ver=filikod/assets/js/vendor/select2.js?ver=

HTML / DOM Fingerprints

CSS Classes
filikod-alt-text-auditfilikod-bulk-management
Data Attributes
data-filikod-id
JS Globals
filikod_ajax_objectfilikod_vars
FAQ

Frequently Asked Questions about Filikod – ALT Text Audit & Bulk Management