Image Credits nofollow Security & Risk Analysis

wordpress.org/plugins/image-credits-nofollow

Adds credits to the media uploads: Source and source URL. URLs are nofollow by default.

200 active installs v1.5 PHP 7.4+ WP 3.0.1+ Updated Feb 1, 2026
creditcreditsimageimage-creditsmedia
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Credits nofollow Safe to Use in 2026?

Generally Safe

Score 100/100

Image Credits nofollow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'image-credits-nofollow' plugin version 1.5 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and properly escaping a high percentage of its output. Furthermore, the absence of file operations and external HTTP requests reduces potential attack vectors. The vulnerability history is also clean, with no recorded CVEs, suggesting a well-maintained and secure codebase.

However, a few areas warrant attention. The analysis indicates zero nonce checks and zero capability checks across its entry points. While the attack surface is currently small and reportedly has no unprotected entry points, this lack of explicit authorization checks for its shortcode is a concern. If the shortcode were to process any user-supplied data or perform sensitive actions, this omission could lead to privilege escalation or unintended functionality execution by unauthorized users. The absence of taint analysis data is also noted; a complete security assessment would ideally include this to confirm the absence of subtle vulnerabilities.

In conclusion, the plugin is fundamentally well-coded with robust data handling practices and a clean vulnerability record. The primary area of concern is the absence of authorization checks for its shortcode, which, despite the limited attack surface, represents a potential weakness that could be exploited if the shortcode's functionality evolves or if unexpected interactions occur. Continued vigilance and consideration for adding nonce and capability checks to its shortcode would further enhance its security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Image Credits nofollow Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image Credits nofollow Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
25 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped27 total outputs
Attack Surface

Image Credits nofollow Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[image-credits] image-credits-nofollow.php:51
WordPress Hooks 10
filtermanage_media_columnsclass-admin.php:16
actionmanage_media_custom_columnclass-admin.php:17
filterplugin_action_links_image-credits-nofollow/image-credits-nofollow.phpclass-admin.php:21
actionplugins_loadedimage-credits-nofollow.php:28
actioninitimage-credits-nofollow.php:30
actionadmin_menuimage-credits-nofollow.php:31
filterload_textdomain_mofileimage-credits-nofollow.php:36
filterattachment_fields_to_editimage-credits-nofollow.php:47
filterattachment_fields_to_saveimage-credits-nofollow.php:48
filterthe_contentimage-credits-nofollow.php:54
Maintenance & Trust

Image Credits nofollow Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 1, 2026
PHP min version7.4
Downloads8K

Community Trust

Rating70/100
Number of ratings2
Active installs200
Developer Profile

Image Credits nofollow Developer Profile

apasionados

28 plugins · 61K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
326 days
View full developer profile
Detection Fingerprints

How We Detect Image Credits nofollow

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-credits-nofollow/css/image-credits-nofollow.css/wp-content/plugins/image-credits-nofollow/js/image-credits-nofollow.js
Script Paths
/wp-content/plugins/image-credits-nofollow/js/image-credits-nofollow.js
Version Parameters
image-credits-nofollow/css/image-credits-nofollow.css?ver=image-credits-nofollow/js/image-credits-nofollow.js?ver=

HTML / DOM Fingerprints

CSS Classes
image-credits
Data Attributes
attachments-[0-9]+-source_dofollowattachments-[0-9]+-credits_sourceattachments-[0-9]+-credits_link
Shortcode Output
<p class="image-credits">
FAQ

Frequently Asked Questions about Image Credits nofollow