
Image Credits nofollow Security & Risk Analysis
wordpress.org/plugins/image-credits-nofollowAdds credits to the media uploads: Source and source URL. URLs are nofollow by default.
Is Image Credits nofollow Safe to Use in 2026?
Generally Safe
Score 100/100Image Credits nofollow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'image-credits-nofollow' plugin version 1.5 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and properly escaping a high percentage of its output. Furthermore, the absence of file operations and external HTTP requests reduces potential attack vectors. The vulnerability history is also clean, with no recorded CVEs, suggesting a well-maintained and secure codebase.
However, a few areas warrant attention. The analysis indicates zero nonce checks and zero capability checks across its entry points. While the attack surface is currently small and reportedly has no unprotected entry points, this lack of explicit authorization checks for its shortcode is a concern. If the shortcode were to process any user-supplied data or perform sensitive actions, this omission could lead to privilege escalation or unintended functionality execution by unauthorized users. The absence of taint analysis data is also noted; a complete security assessment would ideally include this to confirm the absence of subtle vulnerabilities.
In conclusion, the plugin is fundamentally well-coded with robust data handling practices and a clean vulnerability record. The primary area of concern is the absence of authorization checks for its shortcode, which, despite the limited attack surface, represents a potential weakness that could be exploited if the shortcode's functionality evolves or if unexpected interactions occur. Continued vigilance and consideration for adding nonce and capability checks to its shortcode would further enhance its security.
Key Concerns
- Missing nonce checks
- Missing capability checks
Image Credits nofollow Security Vulnerabilities
Image Credits nofollow Code Analysis
Output Escaping
Image Credits nofollow Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Image Credits nofollow Maintenance & Trust
Maintenance Signals
Community Trust
Image Credits nofollow Alternatives
Better Image Credits
better-image-credits
This plugin adds credits, link and license fields to media uploads and offer several options to display image credits on your posts and pages.
Image Rights
image-rights
Adds additional fields for setting image credits in the media library.
Photo Credits
photo-credits
Photo credits helps to display Author credits for the images on your website
FSM Custom Featured Image Caption
fsm-custom-featured-image-caption
Allows adding custom captions to the featured images of the posts.
Image Source Control Lite – Show Image Credits and Captions
image-source-control-isc
Show image credits, image captions, and copyrights. Manage image sources and warn if they are missing. The original plugin since 2012.
Image Credits nofollow Developer Profile
28 plugins · 61K total installs
How We Detect Image Credits nofollow
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-credits-nofollow/css/image-credits-nofollow.css/wp-content/plugins/image-credits-nofollow/js/image-credits-nofollow.js/wp-content/plugins/image-credits-nofollow/js/image-credits-nofollow.jsimage-credits-nofollow/css/image-credits-nofollow.css?ver=image-credits-nofollow/js/image-credits-nofollow.js?ver=HTML / DOM Fingerprints
image-creditsattachments-[0-9]+-source_dofollowattachments-[0-9]+-credits_sourceattachments-[0-9]+-credits_link<p class="image-credits">