Image Uploader for Welcart Security & Risk Analysis

wordpress.org/plugins/image-uploader-for-welcart

Create metabox with image uploader for ‘Welcart e-Commerce’. It allows user to upload and sort images directory from each edit page.

3K active installs v1.4.6 PHP + WP 4.0+ Updated Feb 13, 2020
imagemedia-uploaderuploaderwelcartwelcart-e-commerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Uploader for Welcart Safe to Use in 2026?

Generally Safe

Score 85/100

Image Uploader for Welcart has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The plugin "image-uploader-for-welcart" v1.4.6 presents a generally positive security posture, with no recorded vulnerabilities in its history and a clean static analysis report regarding critical code signals like dangerous functions, file operations, and external requests. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the presence of nonce and capability checks, even if only one instance each, suggests some attention to security fundamentals. The taint analysis showing no unsanitized paths or critical/high severity flows is also reassuring.

However, there are notable areas for improvement. The most significant concern is the SQL query handling. With two SQL queries identified and 0% using prepared statements, there is a clear risk of SQL injection vulnerabilities. Additionally, the output escaping is very poor, with only 11% of outputs properly escaped, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities. While the plugin has no known CVEs, the lack of robust security practices in data handling (SQL and output) means that vulnerabilities could easily be introduced in future updates or through user-supplied data.

In conclusion, the plugin benefits from a very small attack surface and no prior vulnerability history. These are strong points. Nevertheless, the significant deficiencies in SQL query preparation and output escaping represent substantial security risks that need immediate attention. Addressing these issues would dramatically improve the plugin's overall security.

Key Concerns

  • Raw SQL queries without prepared statements
  • Low percentage of properly escaped output
Vulnerabilities
None known

Image Uploader for Welcart Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image Uploader for Welcart Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
8
1 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

11% escaped9 total outputs
Attack Surface

Image Uploader for Welcart Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadd_meta_boxesimage-uploader-for-welcart.php:24
actionsave_postimage-uploader-for-welcart.php:25
filterattachment_fields_to_editimage-uploader-for-welcart.php:26
Maintenance & Trust

Image Uploader for Welcart Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedFeb 13, 2020
PHP min version
Downloads31K

Community Trust

Rating100/100
Number of ratings2
Active installs3K
Developer Profile

Image Uploader for Welcart Developer Profile

Mizuho Ogino

2 plugins · 3K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image Uploader for Welcart

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-uploader-for-welcart/js/iu4w-admin.js/wp-content/plugins/image-uploader-for-welcart/css/iu4w-admin.css
Script Paths
/wp-content/plugins/image-uploader-for-welcart/js/iu4w-admin.js
Version Parameters
image-uploader-for-welcart/js/iu4w-admin.js?ver=image-uploader-for-welcart/css/iu4w-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
iu4w-liiu4w-wrapiu4w-removeiu4w-imgiu4w-editoriu4w-openiu4w-editor-openiu4w-editor-close
Data Attributes
id="iu4w-ul"name="iu4w_attr"name="_iu4w_images[]"id="iu4w-media"class="iu4w-open"id="iu4w_view"+24 more
JS Globals
iu4w_liiu4w_wrapiu4w_removeiu4w_imgiu4w_editoriu4w_open+2 more
FAQ

Frequently Asked Questions about Image Uploader for Welcart