
Image Optimizer by 10web – Image Optimizer and Compression plugin Security & Risk Analysis
wordpress.org/plugins/image-optimizer-wdImage Optimizer by 10Web optimizes and preserves image quality. Improve your website speed, bounce rate, and SEO with Image Optimizer.
Is Image Optimizer by 10web – Image Optimizer and Compression plugin Safe to Use in 2026?
Generally Safe
Score 91/100Image Optimizer by 10web – Image Optimizer and Compression plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The 'image-optimizer-wd' plugin v6.0.67 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and has no reported external HTTP requests or file operations, which are common sources of vulnerabilities. The absence of critical or high severity taint flows and a low number of total flows analyzed suggest a relatively clean internal code flow regarding sanitation.
However, significant concerns arise from the attack surface and past vulnerability history. The plugin exposes four AJAX handlers, three of which lack authentication checks. This is a substantial risk, as unauthenticated AJAX endpoints can be exploited by attackers to perform unintended actions. While the plugin has a good number of nonces (5), their placement within the code is not detailed, and the lack of capability checks on AJAX handlers is a direct security flaw. The vulnerability history is also concerning, with four known CVEs, all of which are currently patched. The types of past vulnerabilities, specifically Cross-site Scripting and Path Traversal, are serious and indicate potential weaknesses in input validation and file handling that, although patched, warrant vigilance.
In conclusion, while the plugin has strengths in database interaction and avoiding certain risky external operations, the unprotected AJAX endpoints represent a critical immediate risk. The historical prevalence of XSS and Path Traversal vulnerabilities, even if patched, suggests that developers should remain cautious and ensure thorough input validation and proper authentication mechanisms are in place for all user-accessible entry points. The plugin's overall security could be significantly improved by implementing proper authentication and authorization checks on all its AJAX handlers.
Key Concerns
- Unprotected AJAX handlers
- Vulnerability history (4 CVEs, 3 medium, 1 low)
- Low output escaping (76% properly escaped)
Image Optimizer by 10web – Image Optimizer and Compression plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Image Optimizer by 10web <= 1.0.26 - Authenticated(Administator+) Directory Traversal
Image Optimizer WD <= 1.0.26 - Reflected Cross-Site Scripting
Image Optimizer WD <= 1.0.26 - Authenticated (Administrator+) Stored Cross-Site Scripting
Image Optimizer by 10web <= 1.0.25 - Directory Traversal to Information Exposure
Image Optimizer by 10web – Image Optimizer and Compression plugin Code Analysis
Output Escaping
Data Flow Analysis
Image Optimizer by 10web – Image Optimizer and Compression plugin Attack Surface
AJAX Handlers 4
WordPress Hooks 10
Maintenance & Trust
Image Optimizer by 10web – Image Optimizer and Compression plugin Maintenance & Trust
Maintenance Signals
Community Trust
Image Optimizer by 10web – Image Optimizer and Compression plugin Alternatives
Image Optimizer – Optimize Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
TinyPNG – JPEG, PNG & WebP image compression
tiny-compress-images
Speed up your website. Optimize your JPEG, PNG, and WebP images automatically with TinyPNG.
WP Compress – Instant Performance & Speed Optimization
wp-compress-image-optimizer
Everything you need for a faster website – smart optimization, advanced caching, adaptive images, WebP creation, script improvements, optional CDN del …
QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly
quickwebp
QuickWebP is a free WordPress plugin that converts images to WebP, optimizes performance, improves SEO, auto-fills metadata, and resizes images—no API …
Image to WebP Converter
image-to-webp-converter
Automatically convert uploaded images (PNG, JPG, JPEG) to WebP format to enhance website performance and reduce load times.
Image Optimizer by 10web – Image Optimizer and Compression plugin Developer Profile
9 plugins · 365K total installs
How We Detect Image Optimizer by 10web – Image Optimizer and Compression plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-optimizer-wd/assets/css/deactivate_popup.css/wp-content/plugins/image-optimizer-wd/assets/js/deactivate_popup.js/wp-content/plugins/image-optimizer-wd/assets/js/deactivate_popup.jsimage-optimizer-wd/assets/css/deactivate_popup.css?ver=image-optimizer-wd/assets/js/deactivate_popup.js?ver=HTML / DOM Fingerprints
iowd-deactivate-popupiowd-deactivate-popup-bodyiowd-deactivate-popup-titleiowd-deactivate-popup-contentiowd-deactivate-popup-listiowd-deactivate-popup-itemiowd-deactivate-popup-buttonstwo-button-canceldata-iowd-deactivation-settingsiowd_deactivation/wp-json/tenwebio/v1/action/deactivate