Image Caption Links Security & Risk Analysis

wordpress.org/plugins/image-caption-links

Automatically add links to the full size images below captions.

10 active installs v1.1 PHP + WP 2.8+ Updated Sep 13, 2012
captionsimageslinks
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Image Caption Links Safe to Use in 2026?

Generally Safe

Score 85/100

Image Caption Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "image-caption-links" plugin v1.1 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, direct SQL queries, file operations, external HTTP requests, and the complete lack of critical or high-severity taint flows are strong indicators of well-written code. Furthermore, the plugin has no recorded vulnerabilities (CVEs), which suggests a history of responsible development and maintenance. The analysis shows a low attack surface with zero entry points found, and importantly, zero unprotected entry points, which is a significant strength. However, the analysis does highlight a weakness in output escaping, with 67% of outputs properly escaped, implying that one out of every three outputs might be vulnerable to cross-site scripting (XSS) if the data originates from user input and is not otherwise sanitized. While the current data doesn't reveal specific vulnerabilities related to this, it remains a potential risk area that warrants attention. The lack of capability checks and nonce checks is not necessarily a weakness in this specific instance given the zero attack surface, but it's a good practice to implement them if any entry points were to be introduced in future versions.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Image Caption Links Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Image Caption Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

Image Caption Links Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterimg_caption_shortcodeimage-caption-links.php:31
actionwp_headimage-caption-links.php:34
Maintenance & Trust

Image Caption Links Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedSep 13, 2012
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Image Caption Links Developer Profile

Matthew Muro

4 plugins · 23K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
1663 days
View full developer profile
Detection Fingerprints

How We Detect Image Caption Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-caption-links/css/image-caption-links.css

HTML / DOM Fingerprints

CSS Classes
image-caption-photo
Data Attributes
figcaption_
Shortcode Output
<a href="" class="image-caption-photo">High Quality Photo</a>
FAQ

Frequently Asked Questions about Image Caption Links