
Image Sizes Panel Security & Risk Analysis
wordpress.org/plugins/image-sizes-panelDisplay a meta box when viewing a media item in the admin that display all generated images sizes.
Is Image Sizes Panel Safe to Use in 2026?
Generally Safe
Score 85/100Image Sizes Panel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "image-sizes-panel" v0.4 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals indicate good practices such as the exclusive use of prepared statements for SQL queries and the absence of dangerous functions, file operations, or external HTTP requests. The lack of known vulnerabilities in its history further reinforces this positive assessment, suggesting diligent security efforts by the developers. However, a significant concern arises from the low percentage of properly escaped output (9%). While the total number of outputs is small (11), this indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is ever processed and rendered without adequate sanitization. Despite this, the overall lack of direct entry points and the absence of critical code signals or historical vulnerabilities paint a picture of a relatively safe plugin, with the output escaping being the primary area of caution.
Key Concerns
- Low percentage of properly escaped output
Image Sizes Panel Security Vulnerabilities
Image Sizes Panel Code Analysis
Output Escaping
Image Sizes Panel Attack Surface
WordPress Hooks 2
Maintenance & Trust
Image Sizes Panel Maintenance & Trust
Maintenance Signals
Community Trust
Image Sizes Panel Alternatives
Disable Media Sizes
disable-media-sizes
Provides options to disable the extra images generated by WordPress.
WP Tesseract
wp-tesseract
A plugin for extracting text from attached images using OCR via Tesseract.
Auto Delete Unattached Media
auto-delete-unattached-media
Automatically delete unattached/unused media/images/attachments every minute silently in the background.
AIR Download Attachments
air-download-attachments
The AIR Download Attachments plugin adds a "Download All Attachments" button to posts, allowing users to download all attached images as a z …
Image Copyright Manager
image-copyright-manager
Add copyright information to WordPress media files with a custom field and display them using shortcodes. Now includes JSON-LD for Image SEO.
Image Sizes Panel Developer Profile
16 plugins · 21K total installs
How We Detect Image Sizes Panel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-sizes-panel/admin/css/admin.css/wp-content/plugins/image-sizes-panel/admin/js/admin.js/wp-content/plugins/image-sizes-panel/admin/js/admin.jsimage-sizes-panel/admin/css/admin.css?ver=image-sizes-panel/admin/js/admin.js?ver=HTML / DOM Fingerprints
image_sizes_panelgeneratednot-generatedundefinedinfosizediminfo-content+1 moreid="image_sizes_panel"