Image Widget Deluxe Security & Risk Analysis

wordpress.org/plugins/image-widget-deluxe

Image Widget Deluxe is an easy to use widget plugin that allows you to change display order of the fields.

1K active installs v2.0.1 PHP + WP 3.8+ Updated May 26, 2019
e-commerceecommerceimageimageswidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Widget Deluxe Safe to Use in 2026?

Generally Safe

Score 85/100

Image Widget Deluxe has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "image-widget-deluxe" plugin v2.0.1 exhibits a generally positive security posture based on the static analysis provided. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface, with no apparent unprotected entry points. Furthermore, the code demonstrates good practices regarding SQL queries by exclusively using prepared statements and avoiding file operations and external HTTP requests. The lack of any recorded vulnerabilities in its history is also a strong indicator of a well-maintained and secure plugin.

However, there are some areas for concern. The low percentage (38%) of properly escaped outputs suggests a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient sanitization before being displayed. The complete absence of nonce checks and capability checks across all entry points, coupled with the lack of taint analysis data, means that while no vulnerabilities were *detected* in this specific analysis, there's no built-in defense against common WordPress attack vectors like CSRF or unauthorized actions if new entry points were ever introduced or if existing ones were improperly handled.

In conclusion, the plugin has a strong foundation with a small attack surface and good SQL handling. The primary weakness lies in the insufficient output escaping, which could be a point of exploitation. The lack of direct security checks like nonces and capability checks on all potential entry points, though currently not exploited, represents an oversight that could become problematic in the future or with more complex interactions.

Key Concerns

  • Insufficient output escaping (38%)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Image Widget Deluxe Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image Widget Deluxe Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
64
39 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped103 total outputs
Attack Surface

Image Widget Deluxe Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionplugins_loadedimage-widget-deluxe.php:22
actionenqueue_scriptsimage-widget-deluxe.php:50
actionwidgets_initimage-widget-deluxe.php:462
Maintenance & Trust

Image Widget Deluxe Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedMay 26, 2019
PHP min version
Downloads30K

Community Trust

Rating100/100
Number of ratings5
Active installs1K
Developer Profile

Image Widget Deluxe Developer Profile

Mikkel Rommelhoff

3 plugins · 2K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image Widget Deluxe

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-widget-deluxe/css/image-widget-backend.css/wp-content/plugins/image-widget-deluxe/js/media.js
Script Paths
/wp-content/plugins/image-widget-deluxe/js/media.js
Version Parameters
image-widget-deluxe/css/image-widget-backend.css?ver=image-widget-deluxe/js/media.js?ver=

HTML / DOM Fingerprints

CSS Classes
rommeled_widget_image-fieldrommeled_widget_image-inner-titlerommeled_widget_imagerommeled_widget_image-imagerommeled_widget_image-textrommeled_widget_image-buttonrommeled_widget_image_inner
Data Attributes
data-iddata-namedata-titledata-descdata-urldata-url-target+5 more
JS Globals
ImageWidgetDeluxe
FAQ

Frequently Asked Questions about Image Widget Deluxe