Featured Image for Categories and pages. Security & Risk Analysis

wordpress.org/plugins/hmk-add-images-for-categories-and-pages

Featured Images enables the user to set different featured image for each category, sub category or page.

100 active installs v1.2.1 PHP + WP 4.1+ Updated Mar 19, 2018
adds-imageadminaffiliate-imagecategory-imagesheader-image
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Featured Image for Categories and pages. Safe to Use in 2026?

Generally Safe

Score 85/100

Featured Image for Categories and pages. has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin "hmk-add-images-for-categories-and-pages" v1.2.1 exhibits a generally good security posture based on the provided static analysis. The plugin has a minimal attack surface with only one entry point (a shortcode) and no unprotected ones. The absence of dangerous functions, file operations, and external HTTP requests is also a positive indicator. Furthermore, the plugin demonstrates good practices by including nonce and capability checks, and a low percentage of SQL queries not using prepared statements is encouraging.

Despite these strengths, there are areas for concern. The taint analysis reveals one flow with an unsanitized path, which, although not flagged as critical or high severity, still represents a potential avenue for exploitation if not handled carefully. The low percentage of properly escaped output (31%) is a significant weakness, as it indicates that user-supplied data or dynamic content might be rendered directly to the browser, potentially leading to Cross-Site Scripting (XSS) vulnerabilities.

The plugin's vulnerability history is completely clean, with no recorded CVEs. This suggests that the plugin has either been well-maintained and secured or has not been a significant target for attackers. However, this lack of history, combined with the identified output escaping issues, means that future vulnerabilities could still emerge if the code is not further hardened. Overall, the plugin is relatively secure but has a notable weakness in output sanitization that requires attention.

Key Concerns

  • Unsanitized path flow in taint analysis
  • Low percentage of properly escaped output
  • SQL queries not using prepared statements
Vulnerabilities
None known

Featured Image for Categories and pages. Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Featured Image for Categories and pages. Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
9
4 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

31% escaped13 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
z_save_taxonomy_image (hmk-adds-images.php:496)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Featured Image for Categories and pages. Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[header_ads_image] hmk-adds-images.php:937
WordPress Hooks 13
actionadmin_inithmk-adds-images.php:33
actionadmin_enqueue_scriptshmk-adds-images.php:69
actionwp_enqueue_scriptshmk-adds-images.php:70
actionedit_termhmk-adds-images.php:492
actioncreate_termhmk-adds-images.php:494
actionadmin_headhmk-adds-images.php:699
actionquick_edit_custom_boxhmk-adds-images.php:701
filterattribute_escapehmk-adds-images.php:703
actionadmin_menuhmk-adds-images.php:711
actionadmin_inithmk-adds-images.php:717
filtersite_transient_update_pluginshmk-adds-images.php:803
actionadd_meta_boxeshmk-adds-images.php:815
actionsave_posthmk-adds-images.php:855
Maintenance & Trust

Featured Image for Categories and pages. Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 19, 2018
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Featured Image for Categories and pages. Developer Profile

Muhammad Kashif

3 plugins · 310 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Featured Image for Categories and pages.

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hmk-add-images-for-categories-and-pages/css/hmk_style_admin.css/wp-content/plugins/hmk-add-images-for-categories-and-pages/css/hmk_style_front.css

HTML / DOM Fingerprints

CSS Classes
taxonomy-imagez_upload_image_buttonhmk-inputz_remove_image_buttontax_list
Data Attributes
data-id
JS Globals
z_script
FAQ

Frequently Asked Questions about Featured Image for Categories and pages.