
Image Annotator Security & Risk Analysis
wordpress.org/plugins/image-annotatorThis is a plugin that uses the HTML5 canvas and FabricJS to allow you to add shapes and text on top of images and display those images.
Is Image Annotator Safe to Use in 2026?
Generally Safe
Score 85/100Image Annotator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The image-annotator plugin v1.0 exhibits a generally good security posture with no known historical vulnerabilities or critical code signals indicating immediate danger. The plugin diligently uses prepared statements for SQL queries, includes nonce checks, and implements capability checks, demonstrating an awareness of basic security principles. The absence of external HTTP requests and file operations further minimizes its attack surface. However, a significant concern arises from the complete lack of output escaping. With 13 total outputs and 0% properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic content displayed by the plugin, especially user-generated or plugin-generated data that isn't rigorously escaped, could be exploited by attackers to inject malicious scripts. While the plugin is currently clean and uses secure coding practices in many areas, the unescaped output is a critical flaw that requires immediate attention to prevent potential exploitation.
Key Concerns
- Output escaping is missing
Image Annotator Security Vulnerabilities
Image Annotator Code Analysis
Bundled Libraries
Output Escaping
Image Annotator Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Image Annotator Maintenance & Trust
Maintenance Signals
Community Trust
Image Annotator Alternatives
Canvas-Nest.js
canvas-nestjs
[正版]A wordpress plugin for canvas-nest.js | 一个很炫酷网页背景效果(canvas-nest.js)的wordpress插件。
WP-TagCanvas
wp-tagcanvas
WP-TagCanvas is a plugin using Javascript class which will draw and animate a HTML5 canvas based tag cloud. It support three shape
Web To Print Shop : uDraw – Widescreen UI
web-to-print-shop-udraw-widescreen-ui
uDraw Designer Widescreen UI by Racad Tech
Wp Game Of Life
wp-game-of-life
A game of life simulation using HTML5 canvas. Not very useful except for entertainment purposes.
Easy Video Player
easy-video-player
Easy Video Player is a WordPress video player that allows you to add videos to your WordPress site.
Image Annotator Developer Profile
3 plugins · 30 total installs
How We Detect Image Annotator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-annotator/admin/css/style.css/wp-content/plugins/image-annotator/admin/js/script.js/wp-content/plugins/image-annotator/admin/js/fabric.canvasex.js/wp-content/plugins/image-annotator/lib/fabricjs/js/fabric.js/wp-content/plugins/image-annotator/lib/imagesLoaded/imagesloaded.pkgd.min.js/wp-content/plugins/image-annotator/admin/js/script.js/wp-content/plugins/image-annotator/admin/js/fabric.canvasex.js/wp-content/plugins/image-annotator/lib/fabricjs/js/fabric.js/wp-content/plugins/image-annotator/lib/imagesLoaded/imagesloaded.pkgd.min.jsimage-annotator/admin/css/style.css?ver=image-annotator/admin/js/script.js?ver=image-annotator/admin/js/fabric.canvasex.js?ver=image-annotator/lib/fabricjs/js/fabric.js?ver=image-annotator/lib/imagesLoaded/imagesloaded.pkgd.min.js?ver=HTML / DOM Fingerprints
wpia-annotate-containerdata-wpia-image-iddata-wpia-annotation-datadata-wpia-canvas-sizecurrentWIPAObject<div class="wpia-annotate-container" data-wpia-image-id="" data-wpia-annotation-data="" data-wpia-canvas-size="