
Image Editor by Pixo Security & Risk Analysis
wordpress.org/plugins/image-editor-by-pixoReplaces the default image editor in wp-admin with more powerful one - Pixo. It can also be used in the front-end.
Is Image Editor by Pixo Safe to Use in 2026?
Mostly Safe
Score 77/100Image Editor by Pixo is generally safe to use. 2 past CVEs were resolved.
The "image-editor-by-pixo" plugin v2.3.8 presents a mixed security posture with some positive attributes but notable concerns. On the positive side, the plugin demonstrates good practices in SQL query handling, with 100% of queries using prepared statements. It also has a reasonable number of nonce and capability checks relative to its entry points, and no dangerous functions were identified. However, the presence of an unprotected AJAX handler significantly expands the attack surface, creating a direct pathway for unauthenticated malicious input. The taint analysis reveals a concerning number of flows with unsanitized paths, even though they are not classified as critical or high severity in this specific scan.
The vulnerability history is a significant red flag. With two known CVEs, one of which remains unpatched, and both being medium severity with a common theme of Cross-site Scripting (XSS), this plugin has a demonstrated history of security flaws. The recent date of the last vulnerability (2025-09-22) suggests ongoing issues. While the current code scan didn't reveal exploitable vulnerabilities in the same vein, the historical pattern of XSS and the unsanitized paths in the taint analysis strongly suggest a propensity for input validation and output escaping weaknesses.
In conclusion, while the plugin has some strengths in its database interaction and basic security checks, the unprotected AJAX endpoint, concerning taint analysis results, and a history of unpatched XSS vulnerabilities collectively indicate a moderate to high-risk profile. Users should exercise caution, and developers should prioritize patching the known vulnerability and addressing the identified unsanitized input paths.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths
- Currently unpatched CVEs
- Output escaping is low (46%)
- Known XSS vulnerabilities in history
Image Editor by Pixo Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Image Editor by Pixo <= 2.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Image Editor by Pixo <= 2.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via download Parameter
Image Editor by Pixo Release Timeline
Image Editor by Pixo Code Analysis
Output Escaping
Data Flow Analysis
Image Editor by Pixo Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 20
Maintenance & Trust
Image Editor by Pixo Maintenance & Trust
Maintenance Signals
Community Trust
Image Editor by Pixo Alternatives
Image Optimizer – Optimize Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly
quickwebp
QuickWebP is a free WordPress plugin that converts images to WebP, optimizes performance, improves SEO, auto-fills metadata, and resizes images—no API …
WP Paint – WordPress Image Editor
wp-paint
WP Paint - WordPress Image Editor is a browser based Image Editor for WordPress media images.
ImageRecycle pdf & image compression
imagerecycle-pdf-image-compression
ImageRecycle image & PDF compression. Make WordPress loads faster by using an automatic image and PDF optimization.
Squeeze – Image Optimization & Compression, WEBP Conversion
squeeze
Unlimited. Private. Instant. Squeeze compresses and converts your images directly in your browser — no external servers and no upload limits.
Image Editor by Pixo Developer Profile
1 plugin · 800 total installs
How We Detect Image Editor by Pixo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-editor-by-pixo/admin.css/wp-content/plugins/image-editor-by-pixo/admin.jshttps://pixoeditor.com/editor/scripts/bridge.m.jsimage-editor-by-pixo/admin.css?ver=image-editor-by-pixo/admin.js?ver=HTML / DOM Fingerprints
data-pixo-idPixo