
Image Source Control Lite – Show Image Credits and Captions Security & Risk Analysis
wordpress.org/plugins/image-source-control-iscShow image credits, image captions, and copyrights. Manage image sources and warn if they are missing. The original plugin since 2012.
Is Image Source Control Lite – Show Image Credits and Captions Safe to Use in 2026?
Generally Safe
Score 97/100Image Source Control Lite – Show Image Credits and Captions has a strong security track record. Known vulnerabilities have been patched promptly.
The 'image-source-control-isc' plugin v3.8.0 exhibits a mixed security posture. While it demonstrates good practices with a high percentage of SQL queries using prepared statements and a significant number of nonce and capability checks, several concerns warrant attention. The presence of a dangerous function like 'unserialize' without further context on its usage is a potential risk, as is the single identified file operation which could be a vector if not handled securely. The taint analysis shows no critical or high severity flows, which is positive, but the presence of two flows with unsanitized paths, even if classified lower, suggests potential for manipulation if inputs are not rigorously validated.
The plugin's vulnerability history is concerning, with four known medium severity CVEs, including authorization bypass and XSS. Although currently unpatched, the absence of active critical or high vulnerabilities is a slight positive, but the pattern of past issues, particularly authorization bypass, indicates a recurring area of weakness. The fact that all past vulnerabilities were medium severity, and none are currently unpatched, suggests that the developers are responsive to fixing issues, but the frequency and types of past vulnerabilities still represent a risk. Overall, while the plugin has strengths in its current security implementation, the past vulnerability record and the identified code signals necessitate careful consideration and monitoring.
Key Concerns
- Unprotected AJAX handler
- Dangerous function 'unserialize' used
- Flows with unsanitized paths found
- Four past medium severity CVEs
Image Source Control Lite – Show Image Credits and Captions Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Image Source Control Lite – Show Image Credits and Captions <= 2.28.0 - Reflected Cross-Site Scripting
Image Source Control <= 2.29.0 - Reflected Cross-Site Scripting
Image Source Control <= 2.17.0 - Sensitive Information Exposure via Log File
Image Source Control Lite < 2.3.1 - Insecure Direct Object Reference
Image Source Control Lite – Show Image Credits and Captions Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Image Source Control Lite – Show Image Credits and Captions Attack Surface
AJAX Handlers 11
Shortcodes 2
WordPress Hooks 45
Maintenance & Trust
Image Source Control Lite – Show Image Credits and Captions Maintenance & Trust
Maintenance Signals
Community Trust
Image Source Control Lite – Show Image Credits and Captions Alternatives
Image Rights
image-rights
Adds additional fields for setting image credits in the media library.
Image Source Overlay
image-source-overlay
With Image Source Overlay you can manage image sources in media library. Plugin will then generate small overlay for every image crediting the origina …
FSM Custom Featured Image Caption
fsm-custom-featured-image-caption
Allows adding custom captions to the featured images of the posts.
Footer Credits
footer-credits
A Customizer control to make footer credits editable.
GamiPress – WooCommerce Points Per Purchase Total
gamipress-wc-points-per-purchase-total
Award points based on WooCommerce purchase total.
Image Source Control Lite – Show Image Credits and Captions Developer Profile
2 plugins · 3K total installs
How We Detect Image Source Control Lite – Show Image Credits and Captions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-source-control-isc/admin/assets/css/isc.cssisc_image_settings_css?ver=HTML / DOM Fingerprints
isc-get-proisc-notice<!-- wp:image<!-- wp:media-text<!-- wp:cover<!-- wp:post-featured-image+1 moreisc_image_sourceisc_image_source_urlisc_image_licenceisc_image_source_ownisc/wp-json/wp/v2/media