Grey Owl Thumbnail Resize Lite Security & Risk Analysis

wordpress.org/plugins/grey-owl-thumbnail-resize-lite

best solution for thumbnail editing

20 active installs v1.3.2 PHP + WP 4.4+ Updated Jul 22, 2023
imageimage-editormediathumbnailthumbnails
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Grey Owl Thumbnail Resize Lite Safe to Use in 2026?

Generally Safe

Score 85/100

Grey Owl Thumbnail Resize Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The grey-owl-thumbnail-resize-lite plugin, version 1.3.2, exhibits a mixed security posture. While it has no recorded vulnerabilities and a relatively low number of entry points, there are significant concerns within its code. The presence of an unprotected AJAX handler is a critical weakness, opening the door for unauthorized actions. Furthermore, the plugin's handling of SQL queries is problematic, with 100% of them lacking prepared statements, which is a common vector for SQL injection vulnerabilities. The low percentage of properly escaped output (19%) also suggests a risk of cross-site scripting (XSS) attacks, especially when combined with the unsanitized path flows identified in the taint analysis.

Although the plugin has no historical CVEs, this absence should not be interpreted as a guarantee of future security. The current code analysis reveals several best practice violations that, if exploited, could lead to severe security incidents. The lack of proper sanitization and authentication on certain entry points, coupled with insecure database query practices, presents a substantial risk. The plugin demonstrates some security awareness with nonce and capability checks, but these are insufficient given the identified weaknesses.

In conclusion, while the plugin's history is clean, its current implementation has serious security flaws. The unprotected AJAX handler and the rampant use of raw SQL queries without prepared statements are the most pressing concerns. The poor output escaping further exacerbates the potential for exploitation. Users should be aware of these risks and consider alternative solutions or wait for significant security improvements in future versions.

Key Concerns

  • Unprotected AJAX handler
  • Raw SQL queries without prepared statements
  • Low percentage of properly escaped output
  • Flows with unsanitized paths
Vulnerabilities
None known

Grey Owl Thumbnail Resize Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Grey Owl Thumbnail Resize Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
43
10 escaped
Nonce Checks
5
Capability Checks
2
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

19% escaped53 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

7 flows2 with unsanitized paths
gotrl_admin_page_start (functions\actions\header-page.php:4)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Grey Owl Thumbnail Resize Lite Attack Surface

Entry Points5
Unprotected1

AJAX Handlers 5

authwp_ajax_gotrl_unset_collection_to_attachmentfunctions\ajax.php:3
authwp_ajax_gotrl_set_collection_to_attachmentfunctions\ajax.php:25
authwp_ajax_gotrl_set_check_images_paramfunctions\ajax.php:47
authwp_ajax_grey_owl_thumbnail_resize_lite_callbackfunctions\ajax.php:65
authwp_ajax_gotrl_get_thumbnail_namefunctions\ajax.php:78
WordPress Hooks 37
actiongotrl_admin_page_footerfunctions\actions\footer-page.php:3
actiongotrl_admin_page_footerfunctions\actions\footer-page.php:15
actiongrey_owl_thumbnail_resize_lite_thumbnails_listfunctions\actions\gort-thumbnails-list.php:3
actiongrey_owl_thumbnail_resize_lite_thumbnails_listfunctions\actions\gort-thumbnails-list.php:11
actiongrey_owl_thumbnail_resize_lite_thumbnails_listfunctions\actions\gort-thumbnails-list.php:34
actiongrey_owl_thumbnail_resize_lite_editorfunctions\actions\gotr-editor.php:3
actiongrey_owl_thumbnail_resize_lite_editorfunctions\actions\gotr-editor.php:12
actiongrey_owl_thumbnail_resize_lite_editorfunctions\actions\gotr-editor.php:21
actiongrey_owl_thumbnail_resize_lite_editorfunctions\actions\gotr-editor.php:183
actiongrey_owl_thumbnail_resize_lite_editorfunctions\actions\gotr-editor.php:270
actiongrey_owl_thumbnail_resize_lite_editorfunctions\actions\gotr-editor.php:306
actiongrey_owl_thumbnail_resize_lite_editorfunctions\actions\gotr-editor.php:314
actiongotrl_admin_page_headerfunctions\actions\header-page.php:3
actiongotrl_admin_page_headerfunctions\actions\header-page.php:11
actiongotrl_admin_page_headerfunctions\actions\header-page.php:25
actiongotrl_admin_page_headerfunctions\actions\header-page.php:32
actiongrey_owl_thumbnail_resize_lite_images_listfunctions\actions\images-list.php:5
actiongrey_owl_thumbnail_resize_lite_images_listfunctions\actions\images-list.php:25
actiongrey_owl_thumbnail_resize_lite_images_listfunctions\actions\images-list.php:110
actiongrey_owl_thumbnail_resize_lite_images_listfunctions\actions\images-list.php:206
actiongotrl_settings_pagefunctions\actions\settings.php:3
actiongotrl_settings_pagefunctions\actions\settings.php:18
actiongotrl_settings_pagefunctions\actions\settings.php:56
actionadmin_enqueue_scriptsfunctions\enqueue.php:5
actionwp_enqueue_scriptsfunctions\enqueue.php:61
actionactivate_pluginfunctions\functions.php:3
actionwp_footerfunctions\hooks.php:2
filterwp_get_attachment_image_srcfunctions\hooks.php:8
actionwp_enqueue_mediafunctions\hooks.php:23
actionadmin_footerfunctions\hooks.php:30
actioninitfunctions\hooks.php:80
filterattachment_fields_to_editfunctions\hooks.php:83
filterattachment_fields_to_editfunctions\hooks.php:148
actionadmin_bar_menufunctions\setup.php:72
actionadmin_initgo-thumbnail-resize-lite.php:42
actionadmin_menugo-thumbnail-resize-lite.php:46
filterattachment_fields_to_editgo-thumbnail-resize-lite.php:49
Maintenance & Trust

Grey Owl Thumbnail Resize Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJul 22, 2023
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

Grey Owl Thumbnail Resize Lite Developer Profile

greyowl0015

2 plugins · 60 total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
289 days
View full developer profile
Detection Fingerprints

How We Detect Grey Owl Thumbnail Resize Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/grey-owl-thumbnail-resize-lite/css/gotrl-admin-style.min.css/wp-content/plugins/grey-owl-thumbnail-resize-lite/js/gotrl-editor-script.js/wp-content/plugins/grey-owl-thumbnail-resize-lite/js/gotrl-admin-script.js/wp-content/plugins/grey-owl-thumbnail-resize-lite/css/gotrl-attachment-style.min.css/wp-content/plugins/grey-owl-thumbnail-resize-lite/js/media-views.js/wp-content/plugins/grey-owl-thumbnail-resize-lite/css/gotrl-style.min.css/wp-content/plugins/grey-owl-thumbnail-resize-lite/js/gotrl-scripts.js
Script Paths
/wp-content/plugins/grey-owl-thumbnail-resize-lite/js/gotrl-editor-script.js/wp-content/plugins/grey-owl-thumbnail-resize-lite/js/gotrl-admin-script.js/wp-content/plugins/grey-owl-thumbnail-resize-lite/js/media-views.js/wp-content/plugins/grey-owl-thumbnail-resize-lite/js/gotrl-scripts.js
Version Parameters
/wp-content/plugins/grey-owl-thumbnail-resize-lite/css/gotrl-style.min.css?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
goi-corners-screen
Data Attributes
data-nonce_tokendata-ajax_urldata-image_iddata-image_widthdata-image_heightdata-image_ratio+7 more
JS Globals
gotrl_added_objgotr_admin_objgotr_attachment_obj
FAQ

Frequently Asked Questions about Grey Owl Thumbnail Resize Lite