
Featured Image for Categories and pages. Security & Risk Analysis
wordpress.org/plugins/hmk-add-images-for-categories-and-pagesFeatured Images enables the user to set different featured image for each category, sub category or page.
Is Featured Image for Categories and pages. Safe to Use in 2026?
Generally Safe
Score 85/100Featured Image for Categories and pages. has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "hmk-add-images-for-categories-and-pages" v1.2.1 exhibits a generally good security posture based on the provided static analysis. The plugin has a minimal attack surface with only one entry point (a shortcode) and no unprotected ones. The absence of dangerous functions, file operations, and external HTTP requests is also a positive indicator. Furthermore, the plugin demonstrates good practices by including nonce and capability checks, and a low percentage of SQL queries not using prepared statements is encouraging.
Despite these strengths, there are areas for concern. The taint analysis reveals one flow with an unsanitized path, which, although not flagged as critical or high severity, still represents a potential avenue for exploitation if not handled carefully. The low percentage of properly escaped output (31%) is a significant weakness, as it indicates that user-supplied data or dynamic content might be rendered directly to the browser, potentially leading to Cross-Site Scripting (XSS) vulnerabilities.
The plugin's vulnerability history is completely clean, with no recorded CVEs. This suggests that the plugin has either been well-maintained and secured or has not been a significant target for attackers. However, this lack of history, combined with the identified output escaping issues, means that future vulnerabilities could still emerge if the code is not further hardened. Overall, the plugin is relatively secure but has a notable weakness in output sanitization that requires attention.
Key Concerns
- Unsanitized path flow in taint analysis
- Low percentage of properly escaped output
- SQL queries not using prepared statements
Featured Image for Categories and pages. Security Vulnerabilities
Featured Image for Categories and pages. Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Featured Image for Categories and pages. Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Featured Image for Categories and pages. Maintenance & Trust
Maintenance Signals
Community Trust
Featured Image for Categories and pages. Alternatives
WP Display Header
wp-display-header
Select a specific header or random header image for each content item or archive page.
Banner Image for post and page
banner-image-for-post-and-page
Banner Image is a great plugin to implement custom banner Image for each page. You can set images easily and later can manage CSS from your theme.
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
wp-maintenance-mode
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
Featured Image for Categories and pages. Developer Profile
3 plugins · 310 total installs
How We Detect Featured Image for Categories and pages.
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hmk-add-images-for-categories-and-pages/css/hmk_style_admin.css/wp-content/plugins/hmk-add-images-for-categories-and-pages/css/hmk_style_front.cssHTML / DOM Fingerprints
taxonomy-imagez_upload_image_buttonhmk-inputz_remove_image_buttontax_listdata-idz_script