
iLoveIMG Security & Risk Analysis
wordpress.org/plugins/iloveimgOptimize your website images and improve your page load speed. Reduce the size of your photos and gain maximum compression while keeping sharp images.
Is iLoveIMG Safe to Use in 2026?
Generally Safe
Score 99/100iLoveIMG has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The iloveimg plugin version 2.2.13 exhibits a mixed security posture. While it has a relatively small attack surface with only 5 entry points, two of these AJAX handlers lack authentication checks, presenting a direct vulnerability to unauthorized actions. The presence of dangerous functions like `unserialize` is concerning, especially when combined with the taint analysis revealing 5 flows with unsanitized paths and 4 of high severity. This strongly suggests potential for deserialization vulnerabilities if untrusted data can reach these flows.
The plugin's vulnerability history, marked by a single high-severity CVE related to deserialization, reinforces these concerns. The fact that this CVE is now patched is a positive sign, but the recurring pattern of deserialization issues and the current taint analysis findings indicate that this remains a critical area of weakness. Although the plugin shows strengths in areas like a reasonable number of nonces and capability checks (though only one is present), and a majority of outputs are escaped, the identified vulnerabilities in authentication, sanitization, and historical patterns warrant significant caution.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function 'unserialize' used
- SQL queries not using prepared statements
- High severity taint flows
- Flows with unsanitized paths
- Bundled library Guzzle
- Low number of capability checks
iLoveIMG Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Image Compressor & Optimizer - iLoveIMG <= 1.0.5 - Authenticated (Administrator+) PHP Object Injection
iLoveIMG Release Timeline
iLoveIMG Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
iLoveIMG Attack Surface
AJAX Handlers 5
WordPress Hooks 15
Maintenance & Trust
iLoveIMG Maintenance & Trust
Maintenance Signals
Community Trust
iLoveIMG Alternatives
NaveenCodes Image Optimizer
naveencodes-image-optimizer
Optimize WordPress images with bulk compression, upload optimization, Media Library actions, and zero tracking.
Nish Image Optimizer
nish-image-optimizer
Lightweight WordPress image optimizer. Compress JPEG, PNG, WebP, and AVIF automatically for faster websites.
Rudra Image Optimizer
rudra-image-optimizer
Analyze, compress, and optimize images from any webpage. Supports WebP, JPEG, PNG, bulk optimization, and performance reporting.
Smush – Image Optimization, Compression, Lazy Load, WebP & CDN
wp-smushit
Compress and optimize images, enable lazy load, serve WebP & AVIF, and speed up your site with a global image CDN.
Cloudinary – Deliver Images and Videos at Scale
cloudinary-image-management-and-manipulation-in-the-cloud-cdn
Boost the performance of your WordPress site by optimizing your images and videos with the Cloudinary WordPress Plugin. WordPress developers, content …
iLoveIMG Developer Profile
3 plugins · 710 total installs
How We Detect iLoveIMG
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/iloveimg/dist/main.css/wp-content/plugins/iloveimg/dist/main.js/wp-content/plugins/iloveimg/dist/vendors.js/wp-content/plugins/iloveimg/dist/main.js/wp-content/plugins/iloveimg/dist/vendors.jsiloveimg/dist/main.css?ver=iloveimg/dist/main.js?ver=iloveimg/dist/vendors.js?ver=HTML / DOM Fingerprints
iloveimg-containeriloveimg-modaliloveimg-btniloveimg-loaderdata-iloveimg-compress-optionsiloveimg_compress_settingsiloveimg_compress_obj/wp-json/iloveimg-compress/v1/settings/wp-json/iloveimg-compress/v1/bulk-optimize