Fr Thumbnails Folder Security & Risk Analysis

wordpress.org/plugins/fr-thumbnails-folder

Move thumbnails file location to {$upload_path}/thumbnails or {$upload_path}/sites/{$blog_id}/thumbnails for multisite.

80 active installs v1.4.0 PHP + WP 4.4.0+ Updated Oct 26, 2024
folderimageimagesthumbnailthumbnails
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fr Thumbnails Folder Safe to Use in 2026?

Generally Safe

Score 92/100

Fr Thumbnails Folder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The fr-thumbnails-folder plugin v1.4.0 demonstrates a generally good security posture, with no recorded vulnerabilities or exploitable taint flows. The static analysis shows adherence to several security best practices, including the use of prepared statements for all SQL queries and a relatively small attack surface. The presence of a nonce check and a capability check further contributes to its security, mitigating common attack vectors.

However, there is one significant concern identified in the static analysis: a single unprotected AJAX handler. While the overall number of entry points is low, the lack of authentication on this handler presents a potential risk. If this AJAX handler performs any sensitive operations or processes user-supplied data without proper validation, it could be exploited by unauthenticated users. The absence of critical or high-severity taint flows is a positive indicator, suggesting that data flowing through the plugin is generally handled with care, but the unprotected AJAX endpoint warrants careful scrutiny.

In conclusion, the plugin's security is strengthened by its clean vulnerability history and good coding practices like prepared statements. The main weakness lies in the unprotected AJAX handler, which, despite a small attack surface, requires immediate attention to ensure it cannot be leveraged for malicious purposes. Addressing this single unprotected entry point would significantly improve the plugin's overall security.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

Fr Thumbnails Folder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fr Thumbnails Folder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

67% escaped3 total outputs
Attack Surface
1 unprotected

Fr Thumbnails Folder Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_fr_thumbnails_folder_delete_image_sizesincludes\class-fr-thumbnails-folder.php:170
WordPress Hooks 9
actionplugins_loadedincludes\class-fr-thumbnails-folder.php:140
filterintermediate_image_sizes_advancedincludes\class-fr-thumbnails-folder.php:151
filterfallback_intermediate_image_sizesincludes\class-fr-thumbnails-folder.php:152
filterimage_downsizeincludes\class-fr-thumbnails-folder.php:153
filterwp_generate_attachment_metadataincludes\class-fr-thumbnails-folder.php:154
actiondelete_attachmentincludes\class-fr-thumbnails-folder.php:155
filterwp_calculate_image_srcsetincludes\class-fr-thumbnails-folder.php:156
actionadmin_menuincludes\class-fr-thumbnails-folder.php:169
actionadmin_enqueue_scriptsincludes\class-fr-thumbnails-folder.php:172
Maintenance & Trust

Fr Thumbnails Folder Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 26, 2024
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs80
Developer Profile

Fr Thumbnails Folder Developer Profile

fahrirusliyadi

4 plugins · 4K total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fr Thumbnails Folder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fr-thumbnails-folder/js/fr-thumbnails-folder-admin.js
Script Paths
/wp-content/plugins/fr-thumbnails-folder/js/fr-thumbnails-folder-admin.js
Version Parameters
fr-thumbnails-folder/style.css?ver=fr-thumbnails-folder-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-iddata-name
JS Globals
fr_thumbnails_folder
FAQ

Frequently Asked Questions about Fr Thumbnails Folder