Free images pictures Security & Risk Analysis

wordpress.org/plugins/free-images-pictures

Search Free images and pictures from various sources - Flickr, Pixabay and Wikimedia. Place free images to articles or pages as media.

20 active installs v0.2 PHP + WP 3.0.1+ Updated Jun 9, 2015
free-imagespictures
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Free images pictures Safe to Use in 2026?

Generally Safe

Score 85/100

Free images pictures has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "free-images-pictures" plugin version 0.2 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by not utilizing dangerous functions, performing no file operations, and not making external HTTP requests. All SQL queries are properly prepared, which is a significant strength. The absence of known vulnerabilities in its history also suggests a degree of stability.

However, there are notable security concerns. The plugin has a single AJAX handler that lacks any authentication or capability checks, creating a significant attack vector. Furthermore, a substantial portion (42%) of its output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped output contains user-supplied data. The lack of nonce checks on the AJAX endpoint is a critical omission that, combined with the lack of capability checks, makes it susceptible to CSRF attacks.

In conclusion, while the plugin avoids some common pitfalls like raw SQL or dangerous functions, the presence of an unprotected AJAX endpoint and a high rate of unescaped output represent immediate and significant risks. The vulnerability history is currently clean, but the current code analysis reveals weaknesses that could be easily exploited. Addressing the unauthenticated AJAX handler and improving output escaping are paramount for securing this plugin.

Key Concerns

  • Unprotected AJAX handler
  • High percentage of unescaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Free images pictures Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Free images pictures Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

58% escaped12 total outputs
Attack Surface
1 unprotected

Free images pictures Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_save_imagefree-images-pictures.php:37
WordPress Hooks 7
actionadmin_menuconfig.php:22
actionadmin_initconfig.php:23
actionmedia_buttons_contextfree-images-pictures.php:26
actionadmin_footerfree-images-pictures.php:30
actionadmin_menufree-images-pictures.php:33
actionadmin_enqueue_scriptsfree-images-pictures.php:36
filtersanitize_file_namefree-images-pictures.php:100
Maintenance & Trust

Free images pictures Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJun 9, 2015
PHP min version
Downloads3K

Community Trust

Rating20/100
Number of ratings1
Active installs20
Developer Profile

Free images pictures Developer Profile

adamsbk

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Free images pictures

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/free-images-pictures/dist/script.js

HTML / DOM Fingerprints

CSS Classes
fip-search-button
Data Attributes
id="fip-search-button"id="free-image-search"name="enabled-sources"name="max-results"name="api-key"id="found-images"
JS Globals
ajax_object
FAQ

Frequently Asked Questions about Free images pictures