
Image Uploader for Welcart Security & Risk Analysis
wordpress.org/plugins/image-uploader-for-welcartCreate metabox with image uploader for ‘Welcart e-Commerce’. It allows user to upload and sort images directory from each edit page.
Is Image Uploader for Welcart Safe to Use in 2026?
Generally Safe
Score 85/100Image Uploader for Welcart has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "image-uploader-for-welcart" v1.4.6 presents a generally positive security posture, with no recorded vulnerabilities in its history and a clean static analysis report regarding critical code signals like dangerous functions, file operations, and external requests. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the presence of nonce and capability checks, even if only one instance each, suggests some attention to security fundamentals. The taint analysis showing no unsanitized paths or critical/high severity flows is also reassuring.
However, there are notable areas for improvement. The most significant concern is the SQL query handling. With two SQL queries identified and 0% using prepared statements, there is a clear risk of SQL injection vulnerabilities. Additionally, the output escaping is very poor, with only 11% of outputs properly escaped, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities. While the plugin has no known CVEs, the lack of robust security practices in data handling (SQL and output) means that vulnerabilities could easily be introduced in future updates or through user-supplied data.
In conclusion, the plugin benefits from a very small attack surface and no prior vulnerability history. These are strong points. Nevertheless, the significant deficiencies in SQL query preparation and output escaping represent substantial security risks that need immediate attention. Addressing these issues would dramatically improve the plugin's overall security.
Key Concerns
- Raw SQL queries without prepared statements
- Low percentage of properly escaped output
Image Uploader for Welcart Security Vulnerabilities
Image Uploader for Welcart Code Analysis
SQL Query Safety
Output Escaping
Image Uploader for Welcart Attack Surface
WordPress Hooks 3
Maintenance & Trust
Image Uploader for Welcart Maintenance & Trust
Maintenance Signals
Community Trust
Image Uploader for Welcart Alternatives
Delete Unscaled Images
delete-unscaled-images
Deletes original image files if they have been resized
My Upload Images
my-upload-images
Create metabox with media uploader. It allows to upload and sort images in any post_type.
QBank Connector
qbank-dam-connector
Gain access to all your files in QBank that you can publish directly from Wordpress without leaving their interface.
Image Photoroll Creator For Photographers
image-photoroll-creator-for-photographers
Plugin adds aditional buttons to media upload module allowing of faster images edit and add to post.
Additional Featured Images and Media Uploader Anywhere
additional-featured-images-and-media-uploader-anywhere
Add additional featured images to any post type and display using either a built in image gallery/slideshow shortcode or by using a single image short …
Image Uploader for Welcart Developer Profile
2 plugins · 3K total installs
How We Detect Image Uploader for Welcart
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-uploader-for-welcart/js/iu4w-admin.js/wp-content/plugins/image-uploader-for-welcart/css/iu4w-admin.css/wp-content/plugins/image-uploader-for-welcart/js/iu4w-admin.jsimage-uploader-for-welcart/js/iu4w-admin.js?ver=image-uploader-for-welcart/css/iu4w-admin.css?ver=HTML / DOM Fingerprints
iu4w-liiu4w-wrapiu4w-removeiu4w-imgiu4w-editoriu4w-openiu4w-editor-openiu4w-editor-closeid="iu4w-ul"name="iu4w_attr"name="_iu4w_images[]"id="iu4w-media"class="iu4w-open"id="iu4w_view"+24 moreiu4w_liiu4w_wrapiu4w_removeiu4w_imgiu4w_editoriu4w_open+2 more