Image Copytrack Security & Risk Analysis

wordpress.org/plugins/image-copytrack

Copytrack detects where your images has been used on the web and assist you in the legal process, for free. This plugin will upload your Media Library …

80 active installs v1.2.4 PHP 7.0+ WP 4.8+ Updated Jul 12, 2022
copyrightcopytracklegalphotographyscan
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Copytrack Safe to Use in 2026?

Generally Safe

Score 85/100

Image Copytrack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The image-copytrack plugin v1.2.4 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The complete absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events is a significant strength, minimizing the potential attack surface. Furthermore, the plugin demonstrates good practices in output escaping, with a high percentage of outputs being properly handled, and the presence of capability checks suggests an awareness of access control. The lack of recorded vulnerabilities in its history is also a positive indicator of its security development.

However, there are some areas for concern. The presence of SQL queries that do not utilize prepared statements is a notable risk. While the taint analysis shows no critical or high severity unsanitized flows, the unescaped SQL could potentially lead to injection vulnerabilities if not handled carefully within the application's broader context. The inclusion of the Guzzle library, although not inherently insecure, raises a flag for potential issues if it's an outdated or vulnerable version, as bundled libraries can introduce risks if not managed and updated.

In conclusion, image-copytrack v1.2.4 appears to be a relatively secure plugin, primarily due to its limited attack surface and good output sanitization. The primary risk lies in the direct SQL queries. The vulnerability history is a strong positive, indicating a low likelihood of previously undiscovered issues. Addressing the SQL query practice and ensuring the bundled Guzzle library is up-to-date would further enhance its security.

Key Concerns

  • Raw SQL queries without prepared statements
  • Bundled library (Guzzle) present
Vulnerabilities
None known

Image Copytrack Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image Copytrack Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
2
9 escaped
Nonce Checks
0
Capability Checks
8
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

0% prepared2 total queries

Output Escaping

82% escaped11 total outputs
Attack Surface

Image Copytrack Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_menuclasses\admin.php:8
actionadmin_enqueue_scriptsclasses\admin.php:9
actionplugins_loadedclasses\core.php:22
filtermanage_media_columnsclasses\library.php:9
actionmanage_media_custom_columnclasses\library.php:10
actionrest_api_initclasses\rest.php:12
actionadmin_menucommon\admin.php:27
filteradmin_footer_textcommon\admin.php:30
actionadmin_noticescommon\admin.php:46
filterplugin_row_metacommon\admin.php:52
filteredd_sl_api_request_verify_sslcommon\admin.php:53
actionadmin_noticescommon\ratings.php:21
actionrest_api_initcommon\rest.php:15
Maintenance & Trust

Image Copytrack Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 12, 2022
PHP min version7.0
Downloads7K

Community Trust

Rating80/100
Number of ratings3
Active installs80
Developer Profile

Image Copytrack Developer Profile

Jordy Meow

27 plugins · 371K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
372 days
View full developer profile
Detection Fingerprints

How We Detect Image Copytrack

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-copytrack/app/index.js/wp-content/plugins/image-copytrack/app/vendor.js
Script Paths
/wp-content/plugins/image-copytrack/app/vendor.js/wp-content/plugins/image-copytrack/app/index.js
Version Parameters
image-copytrack/app/index.js?ver=image-copytrack/app/vendor.js?ver=

HTML / DOM Fingerprints

CSS Classes
mct-admin-dashboard
Data Attributes
data-api-noncedata-api-urldata-rest-urldata-plugin-urldata-prefixdata-domain+1 more
JS Globals
mct_image_copytrack
REST Endpoints
/wp-json/image-copytrack/v1/update_option//wp-json/image-copytrack/v1/status//wp-json/image-copytrack/v1/upload//wp-json/image-copytrack/v1/pending//wp-json/image-copytrack/v1/account/
FAQ

Frequently Asked Questions about Image Copytrack