
Genesis Featured Image Header Security & Risk Analysis
wordpress.org/plugins/genesis-featured-image-headerEasily add a featured image to the header of every page on your site including Custom Post Type archive pages.
Is Genesis Featured Image Header Safe to Use in 2026?
Generally Safe
Score 92/100Genesis Featured Image Header has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The genesis-featured-image-header plugin v1.3 exhibits a seemingly robust security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code analysis shows no dangerous functions, no raw SQL queries, and no file operations or external HTTP requests, which are all positive indicators. The vulnerability history also shows no known CVEs, suggesting a stable and well-maintained codebase in the past.
However, a critical concern arises from the output escaping analysis, which indicates that 0% of the 16 total outputs are properly escaped. This presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed by the plugin that is not properly escaped could be manipulated by an attacker to inject malicious scripts. While taint analysis shows no flows with unsanitized paths, the lack of output escaping means that even if data were to become unsanitized in a future version or interaction, the escape mechanism would be absent, exacerbating the risk. The absence of nonce checks and capability checks, while not directly indicative of a current vulnerability given the limited attack surface, means that if new entry points were introduced, they might be vulnerable.
In conclusion, the plugin's strengths lie in its minimal attack surface and avoidance of common risky functionalities like raw SQL and dangerous functions. Nevertheless, the complete lack of output escaping is a major weakness that demands immediate attention. This significantly overshadows the other positive findings and makes the plugin susceptible to XSS attacks.
Key Concerns
- 0% of outputs properly escaped
- No nonce checks
- No capability checks
Genesis Featured Image Header Security Vulnerabilities
Genesis Featured Image Header Code Analysis
Output Escaping
Genesis Featured Image Header Attack Surface
WordPress Hooks 4
Maintenance & Trust
Genesis Featured Image Header Maintenance & Trust
Maintenance Signals
Community Trust
Genesis Featured Image Header Alternatives
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
Multiple Featured Images
multiple-featured-images
Enables multiple featured images for all post types (including custom post types and WooCommerce products). Comes with a widget and a handy shortcode …
Genesis Featured Widget Amplified
genesis-featured-widget-amplified
Genesis Featured Posts with support for custom post types, taxonomies, and so much more
Display Featured Image for Genesis
display-featured-image-genesis
This plugin works within the Genesis Framework, to display featured images in beautiful and dynamic ways.
SNY Auto Featured Image
wp-auto-featured-image
Automatically set a default featured image for posts, pages, or custom post types when none is assigned.
Genesis Featured Image Header Developer Profile
15 plugins · 13K total installs
How We Detect Genesis Featured Image Header
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/genesis-featured-image-header/js/media-uploader.js/wp-content/plugins/genesis-featured-image-header/js/woo-hooks.jswp-includes/js/wp-media-uploader.jswp-includes/js/media-uploader.jsgenesis-featured-image-header/js/media-uploader.js?ver=genesis-featured-image-header/js/woo-hooks.js?ver=HTML / DOM Fingerprints
Prevent direct access to the pluginCheck if Genesis is InstalledFeatured Image on Normal PagesFeatured Image On Archive Pages Settings Pageid="upload_image_button"gfih_action_locationgfih_get_cptscustom_uploadergfih_on_pagesgfih_on_productgfih_action_location<img src="