FSM Custom Featured Image Caption Security & Risk Analysis

wordpress.org/plugins/fsm-custom-featured-image-caption

Allows adding custom captions to the featured images of the posts.

5K active installs v1.25.1 PHP + WP + Updated Jan 8, 2025
captioncopyrightcreditsfeatured-imageimages
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVEFeb 25, 2026
Download
Safety Verdict

Is FSM Custom Featured Image Caption Safe to Use in 2026?

Mostly Safe

Score 70/100

FSM Custom Featured Image Caption is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Feb 25, 2026Updated 1yr ago
Risk Assessment

The "fsm-custom-featured-image-caption" v1.25.1 plugin demonstrates a generally strong security posture based on the static analysis. The absence of dangerous functions, external HTTP requests, file operations, and raw SQL queries is commendable. The presence of nonce and capability checks on all identified entry points, including the single shortcode, further enhances its security. Taint analysis showing zero flows with unsanitized paths is also a positive indicator. The plugin has no recorded vulnerability history, suggesting a commitment to secure coding practices. However, a small concern arises from the output escaping, where 30% of outputs are not properly escaped. While this might not immediately translate to a critical vulnerability, it represents a potential weakness that could be exploited in conjunction with other factors or in future versions if not addressed.

Key Concerns

  • Outputs not properly escaped
Vulnerabilities
1 published

FSM Custom Featured Image Caption Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-39693medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

FSM Custom Featured Image Caption <= 1.25.1 - Authenticated (Author+) Stored Cross-Site Scripting

Feb 25, 2026Unpatched
Version History

FSM Custom Featured Image Caption Release Timeline

v1.251 CVE
v1.241 CVE
v1.231 CVE
v1.221 CVE
v1.211 CVE
v1.201 CVE
v1.191 CVE
v1.181 CVE
v1.171 CVE
v1.161 CVE
v1.151 CVE
v1.141 CVE
v1.131 CVE
v1.121 CVE
v1.111 CVE
v1.101 CVE
v1.011 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

FSM Custom Featured Image Caption Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
19 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

70% escaped27 total outputs
Attack Surface

FSM Custom Featured Image Caption Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[FSM_featured_image] fsm-custom-featured-image-caption.php:596
WordPress Hooks 11
actioninitfsm-custom-featured-image-caption.php:23
actionadmin_menufsm-custom-featured-image-caption.php:37
actionadmin_initfsm-custom-featured-image-caption.php:38
actionadmin_enqueue_scriptsfsm-custom-featured-image-caption.php:57
actioncurrent_screenfsm-custom-featured-image-caption.php:265
actionenqueue_block_editor_assetsfsm-custom-featured-image-caption.php:286
actionadd_meta_boxesfsm-custom-featured-image-caption.php:292
actionsave_postfsm-custom-featured-image-caption.php:295
filterpost_thumbnail_htmlfsm-custom-featured-image-caption.php:889
filterdivi_thumbnail_htmlfsm-custom-featured-image-caption.php:890
actionrest_api_initfsm-custom-featured-image-caption.php:912
Maintenance & Trust

FSM Custom Featured Image Caption Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 8, 2025
PHP min version
Downloads122K

Community Trust

Rating92/100
Number of ratings22
Active installs5K
Developer Profile

FSM Custom Featured Image Caption Developer Profile

Fesomia

2 plugins · 5K total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FSM Custom Featured Image Caption

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fsm-custom-featured-image-caption/js/FSMFIC_options_page.js
Script Paths
/wp-content/plugins/fsm-custom-featured-image-caption/js/FSMFIC_options_page.js

HTML / DOM Fingerprints

CSS Classes
wp-caption-text
Data Attributes
name="fsm_custom_featured_image_caption_options[custom_class]"name="fsm_custom_featured_image_caption_options[custom_style]"name="fsm_custom_featured_image_caption_options[CSS_options]"name="fsm_custom_featured_image_caption_options[allow_html]"name="fsm_custom_featured_image_caption_options[allow_shortcodes]"name="fsm_custom_featured_image_caption_options[show_in_lists]"+2 more
JS Globals
FSMFIC_options_page
FAQ

Frequently Asked Questions about FSM Custom Featured Image Caption