
image_src Security & Risk Analysis
wordpress.org/plugins/image-srcAdd the "image_src" microformat.
Is image_src Safe to Use in 2026?
Generally Safe
Score 85/100image_src has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "image-src" plugin version 1.0.0 exhibits a strong security posture based on the provided static analysis. There are no identified attack surface entry points, indicating that the plugin does not expose any direct interfaces like AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited. Furthermore, the code analysis reveals no dangerous functions, raw SQL queries, file operations, or external HTTP requests. The absence of unsanitized taint flows and the use of prepared statements for all SQL queries are significant strengths.
However, there are areas for improvement. The plugin has a 50% rate of proper output escaping, meaning half of its outputs are not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is ever rendered directly. Additionally, the complete absence of nonce checks and capability checks across all potential (though currently zero) entry points is concerning. While the attack surface is currently zero, if any entry points are added in the future, these checks would be crucial for preventing Cross-Site Request Forgery (CSRF) and unauthorized access.
The plugin has no recorded vulnerability history, which is a positive indicator of its current security. This, combined with the clean static analysis, suggests a generally safe plugin. However, the lack of basic security checks like nonces and capability checks on any potential future entry points represents a weakness that should be addressed proactively to maintain a robust security profile as the plugin evolves.
Key Concerns
- Half of outputs are not properly escaped
- No nonce checks
- No capability checks
image_src Security Vulnerabilities
image_src Code Analysis
Output Escaping
image_src Attack Surface
WordPress Hooks 1
Maintenance & Trust
image_src Maintenance & Trust
Maintenance Signals
Community Trust
image_src Alternatives
Rich Contact Widget
rich-contact-widget
A simple contact widget enhanced with microdatas & microformats tags for your local SEO
Micropub
micropub
Allows you to publish to your site using Micropub clients.
Microformats 2
wp-uf2
Enhances your WordPress theme with Microformats 2 classes.
Custom Image_Src
custom-image-src
Specify a custom sharing image for Facebook. You can upload an image, use the first image in the post, or use the post thumbnail.
MF2 Feeds
mf2-feed
Add Microformats2 Feeds for WordPress
image_src Developer Profile
5 plugins · 50 total installs
How We Detect image_src
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<link rel='image_src' href='