HTTPS Thumbnails Security & Risk Analysis

wordpress.org/plugins/https-thumbnails

Corrects http image links on a page delivered over https.

50 active installs v1.0.0 PHP + WP 3.2.0+ Updated Mar 11, 2015
httpssslthumbnails
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HTTPS Thumbnails Safe to Use in 2026?

Generally Safe

Score 85/100

HTTPS Thumbnails has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'https-thumbnails' plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. There are no identified entry points for attacks through AJAX, REST API, shortcodes, or cron events. The code also demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and properly escaping all outputs. Furthermore, there are no file operations, external HTTP requests, or indications of missing nonce or capability checks. Taint analysis also reveals no critical or high severity vulnerabilities. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a history of secure development and maintenance.

Despite the excellent static analysis results, the complete absence of any attack surface or identified flows might indicate a very limited functionality, or that the plugin's scope is exceptionally small. While this contributes to its current apparent security, it's important to remember that this assessment is based on the provided data alone. A truly comprehensive analysis would involve dynamic testing and a deeper dive into the plugin's purpose to ensure no potential edge cases or complex interactions have been overlooked. However, based on the evidence presented, 'https-thumbnails' v1.0.0 appears to be a very securely coded plugin.

Vulnerabilities
None known

HTTPS Thumbnails Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

HTTPS Thumbnails Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

HTTPS Thumbnails Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

HTTPS Thumbnails Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterwp_get_attachment_urlplugin.php:35
Maintenance & Trust

HTTPS Thumbnails Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedMar 11, 2015
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

HTTPS Thumbnails Developer Profile

Marty Kokes

1 plugin · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HTTPS Thumbnails

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/https-thumbnails/https-thumbnails.js
Script Paths
/wp-content/plugins/https-thumbnails/https-thumbnails.js
Version Parameters
https-thumbnails.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about HTTPS Thumbnails