
Image Meta Save Security & Risk Analysis
wordpress.org/plugins/image-meta-saveImage Meta Save can be used to add meta data to images and upload them to the WordPress media library.
Is Image Meta Save Safe to Use in 2026?
Generally Safe
Score 85/100Image Meta Save has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "image-meta-save" v1.0 plugin exhibits a concerning security posture primarily due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in its use of prepared statements for SQL queries and has no recorded vulnerability history, the presence of 7 AJAX handlers without any authentication or capability checks presents a substantial attack surface. The taint analysis reveals 6 high-severity flows with unsanitized paths, indicating that user-supplied input could be manipulated to achieve unintended and potentially malicious outcomes. The absence of nonce checks on these AJAX handlers further exacerbates this risk, allowing for potential cross-site request forgery (CSRF) attacks. Despite the lack of known CVEs and a clean history, the identified code signals and taint analysis results point to a critical need for security hardening, particularly around user input validation and access control for its AJAX endpoints.
Key Concerns
- AJAX handlers without auth checks
- High severity unsanitized paths in taint flows
- Missing nonce checks
- Capability checks on only 1 entry point
- Unescaped output percentage low
Image Meta Save Security Vulnerabilities
Image Meta Save Release Timeline
Image Meta Save Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Image Meta Save Attack Surface
AJAX Handlers 7
WordPress Hooks 2
Maintenance & Trust
Image Meta Save Maintenance & Trust
Maintenance Signals
Community Trust
Image Meta Save Alternatives
MMWW
mmww
Media Metadata Workflow Wizard: Integrate your media metadata workflow with WordPress's Media Library
Remove exif and metadata
remove-exif-and-metadata
Automatically remove exif and metadata data after uploading. Just moment supported format: JPG and PNG. Using ImageMagick
X3P0: Media Data
x3p0-media-data
Display image, audio, and video metadata fields—EXIF, ID3, and more—right inside the WordPress block editor, instantly and flexibly.
WP Strip Image Metadata
wp-strip-image-metadata
Strip image metadata on upload or via bulk action, and view image EXIF data.
Strip Image Metadata for JPG and WEBP
strip-image-metadata-for-jpg-and-webp
Strip Image Metadata for JPG and WEBP Files
Image Meta Save Developer Profile
1 plugin · 0 total installs
How We Detect Image Meta Save
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-meta-save/css/admin.css/wp-content/plugins/image-meta-save/js/admin.jsjs/admin.jsHTML / DOM Fingerprints
imgMD_header_divimgMD_line_dividerimgMD_location_divimgMD_location_listimgMD_location_list_itemimgMD_preset_divid="imgMD_city_name"id="imgMD_state_name"id="imgMD_latitude"id="imgMD_longitude"id="imgMD_add_location_btn"id="imgMD_location_list"+25 more