Image Pro – Image resizing and media management done right Security & Risk Analysis

wordpress.org/plugins/image-pro-wordpress-image-media-management-and-resizing-done-right

Upload, resize, add, change images instantly. Manage your media collection with ease and use it for any post or page. A new way of managing content!

200 active installs v0.36 PHP + WP 3.0.0+ Updated Jan 30, 2017
editorimageimagespicturespost
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Pro – Image resizing and media management done right Safe to Use in 2026?

Generally Safe

Score 85/100

Image Pro – Image resizing and media management done right has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "image-pro-wordpress-image-media-management-and-resizing-done-right" plugin v0.36 exhibits a generally strong security posture, characterized by a clean vulnerability history and an absence of known CVEs. The static analysis reveals a commendable effort in employing secure coding practices, with 100% of SQL queries utilizing prepared statements, a robust number of output escaping checks (72% proper), and the presence of nonce and capability checks. The attack surface appears minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission callbacks.

However, there are specific areas of concern that warrant attention. The presence of the 'exec' function, a potentially dangerous function, represents a significant risk if not handled with extreme caution and robust input validation. Furthermore, the taint analysis indicates 3 out of 4 flows with unsanitized paths, which is a serious indicator of potential vulnerabilities related to how data is processed. While no critical or high severity taint flows were explicitly flagged, the presence of unsanitized paths suggests a risk of privilege escalation or arbitrary code execution if these paths are reachable by unauthenticated users or if the data influencing them is not properly sanitized before use.

The plugin's lack of recorded vulnerabilities is a positive sign, suggesting consistent security awareness from the developers. Nevertheless, the identified code signals, particularly the 'exec' function and the unsanitized taint flows, indicate that a deeper review is necessary to ensure these potentially risky areas are secured. The minimal attack surface is a significant strength, but the potential impact of vulnerabilities within the existing code, if exploited, could be severe.

Key Concerns

  • Dangerous function 'exec' present
  • Unsanitized paths in taint analysis (3/4 flows)
  • Output escaping not fully proper (72%)
Vulnerabilities
None known

Image Pro – Image resizing and media management done right Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Image Pro – Image resizing and media management done right Release Timeline

v0.36Current
v0.35
v0.34
v0.33
v0.32
v0.31
v0.30
v0.29
v0.28
v0.27
v0.26
v0.25
v0.24
v0.23
v0.22
v0.21
v0.20
v0.19
v0.18
v0.17
Code Analysis
Analyzed Mar 16, 2026

Image Pro – Image resizing and media management done right Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
1 prepared
Unescaped Output
41
107 escaped
Nonce Checks
1
Capability Checks
5
File Operations
77
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

execexec('cjpeg '.$lpszFileName.'.bmp >'.$lpszFileName.' 2>/dev/null');src\thumb\phpthumb.gif.php:117

SQL Query Safety

100% prepared1 total queries

Output Escaping

72% escaped148 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
SendSaveAsFileHeaderIfNeeded (src\thumb\phpThumb.php:35)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Image Pro – Image resizing and media management done right Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
filterimg_caption_shortcodeimagepro.php:51
actionadmin_print_footer_scriptsimagepro.php:64
actionadd_meta_boxesimagepro.php:65
actionadd_meta_boxesimagepro.php:66
filtermce_cssimagepro.php:68
actionwp_headimagepro.php:74
actionadmin_print_footer_scriptssrc\editor.php:6
actionadmin_print_footer_scriptssrc\folder.php:15
actionadmin_noticessrc\log.php:37
actionadmin_noticessrc\requirements.php:79
filtercontent_save_presrc\thumbs.php:15
filtercontent_edit_presrc\thumbs.php:17
Maintenance & Trust

Image Pro – Image resizing and media management done right Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedJan 30, 2017
PHP min version
Downloads78K

Community Trust

Rating86/100
Number of ratings6
Active installs200
Developer Profile

Image Pro – Image resizing and media management done right Developer Profile

mihaivalentin

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image Pro – Image resizing and media management done right

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-pro-wordpress-image-media-management-and-resizing-done-right/src/editor-styles.css
Script Paths
/wp-content/plugins/image-pro-wordpress-image-media-management-and-resizing-done-right/src/js/impro.js

HTML / DOM Fingerprints

CSS Classes
imagepro-frames
Data Attributes
data-imagepro-framesimagepro-frames
JS Globals
impro.urlimpro.admin_urlimpro.nonce.deleteNonce
Shortcode Output
[caption][imagepro-frames]
FAQ

Frequently Asked Questions about Image Pro – Image resizing and media management done right