ImageEngine – Optimize the Images on Your WordPress Site Like No Other Plugin Security & Risk Analysis

wordpress.org/plugins/image-cdn

Automatically optimize and serve WEBP, AVIF and JPEGXL with ImageEngine, the global Image CDN. 60 sec setup.

90 active installs v1.2.7 PHP 7.4+ WP 5.3+ Updated Jul 11, 2025
avifimage-cdnimageenginejpegxlwebp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ImageEngine – Optimize the Images on Your WordPress Site Like No Other Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

ImageEngine – Optimize the Images on Your WordPress Site Like No Other Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "image-cdn" plugin v1.2.7 exhibits a mixed security posture. While it demonstrates good practices such as 100% use of prepared statements for SQL queries and a significant percentage of properly escaped output, there are notable areas of concern. The presence of two AJAX handlers without authentication checks presents a direct attack surface that could be exploited by unauthenticated users. This is further compounded by the lack of nonce checks on these unprotected entry points, making them susceptible to Cross-Site Request Forgery (CSRF) attacks. Fortunately, the taint analysis revealed no critical or high-severity unsanitized flows, and the plugin has no recorded vulnerabilities in its history, indicating a lack of past exploitable issues. However, the unprotected AJAX endpoints are a significant weakness that warrants immediate attention and mitigation.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX
  • Bundled outdated Guzzle library
  • Unescaped output present
Vulnerabilities
None known

ImageEngine – Optimize the Images on Your WordPress Site Like No Other Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ImageEngine – Optimize the Images on Your WordPress Site Like No Other Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
49 escaped
Nonce Checks
5
Capability Checks
4
File Operations
0
External Requests
3
Bundled Libraries
1

Bundled Libraries

Guzzle1.1

Output Escaping

65% escaped75 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<class-imagecdn> (imageengine\class-imagecdn.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

ImageEngine – Optimize the Images on Your WordPress Site Like No Other Plugin Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_image_cdn_test_configimageengine\class-imagecdn.php:131
authwp_ajax_image_cdn_analyticsimageengine\class-imagecdn.php:137
WordPress Hooks 21
actionplugins_loadedimage-cdn.php:44
actionactivated_pluginimage-cdn.php:45
actionadmin_noticesimage-cdn.php:48
actiontemplate_redirectimageengine\class-imagecdn.php:100
filterthe_contentimageengine\class-imagecdn.php:103
actionsend_headersimageengine\class-imagecdn.php:109
filterrest_post_dispatchimageengine\class-imagecdn.php:112
filterimage_cdn_urlimageengine\class-imagecdn.php:115
filterimage_cdn_htmlimageengine\class-imagecdn.php:116
filtertve_landing_page_contentimageengine\class-imagecdn.php:120
filterthrive_css_file_contentimageengine\class-imagecdn.php:121
filterget_post_metadataimageengine\class-imagecdn.php:122
actionadmin_initimageengine\class-imagecdn.php:127
actionadmin_initimageengine\class-imagecdn.php:128
actionadmin_menuimageengine\class-imagecdn.php:129
actionadmin_footerimageengine\class-imagecdn.php:130
actionadmin_post_registerimageengine\class-imagecdn.php:133
actionadmin_post_loginimageengine\class-imagecdn.php:134
actionadmin_post_logoutimageengine\class-imagecdn.php:135
actionadmin_footerimageengine\class-imagecdn.php:136
filterget_post_metadataimageengine\class-imagecdn.php:636
Maintenance & Trust

ImageEngine – Optimize the Images on Your WordPress Site Like No Other Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 11, 2025
PHP min version7.4
Downloads16K

Community Trust

Rating100/100
Number of ratings4
Active installs90
Developer Profile

ImageEngine – Optimize the Images on Your WordPress Site Like No Other Plugin Developer Profile

ImageEngine

1 plugin · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ImageEngine – Optimize the Images on Your WordPress Site Like No Other Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-cdn/imageengine/assets/css/image-cdn-admin.css/wp-content/plugins/image-cdn/imageengine/assets/js/image-cdn-admin.js
Script Paths
/wp-content/plugins/image-cdn/imageengine/assets/js/image-cdn-admin.js
Version Parameters
/wp-content/plugins/image-cdn/imageengine/assets/css/image-cdn-admin.css?ver=/wp-content/plugins/image-cdn/imageengine/assets/js/image-cdn-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
image-cdn-admin-formimage-cdn-admin-wrap
Data Attributes
data-image-cdn-url
JS Globals
ImageCDNAdminimage_cdn_admin_params
REST Endpoints
/wp-json/image-cdn/v1/settings
FAQ

Frequently Asked Questions about ImageEngine – Optimize the Images on Your WordPress Site Like No Other Plugin