ImageBoss – Image Optimization & CDN Security & Risk Analysis

wordpress.org/plugins/imageboss

Optimize your images with compression, CDN delivery, and responsive images through the ImageBoss service.

10 active installs v5.0.3 PHP 5.3.0+ WP 4.0+ Updated Dec 8, 2025
cdnimage-compressionlazy-loadwebp
100
A · Safe
CVEs total1
Unpatched0
Last CVEMay 11, 2020
Download
Safety Verdict

Is ImageBoss – Image Optimization & CDN Safe to Use in 2026?

Generally Safe

Score 100/100

ImageBoss – Image Optimization & CDN has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: May 11, 2020Updated 5mo ago
Risk Assessment

The imageboss plugin v5.0.3 exhibits a generally good security posture based on static analysis. The absence of any identified attack surface points, dangerous functions, raw SQL queries, file operations, external HTTP requests, and nonce/capability checks suggests a conscious effort to minimize potential entry points for attackers. The use of prepared statements for all SQL queries is a strong indicator of secure database interaction. However, the static analysis does reveal some areas for improvement. A significant portion of output (25%) is not properly escaped, which could lead to Cross-Site Scripting vulnerabilities if user-supplied data is directly reflected in the output. The plugin also bundles TinyMCE, and without knowing the specific version and its security status, this could represent a potential risk if an outdated or vulnerable version is included.

The vulnerability history shows one past CVE, specifically a medium severity Cross-Site Scripting vulnerability. While this vulnerability is no longer listed as unpatched, its existence in the past, coupled with the observed unescaped output in the current version, warrants attention. The fact that the CVE was in 2020 and the current version is 5.0.3 suggests that the plugin developers have addressed past security issues. However, the unescaped output is a present concern that could manifest as a new vulnerability. The lack of any critical or high severity vulnerabilities in the history is a positive sign, but the presence of even one medium vulnerability, and the ongoing potential for XSS due to unescaped output, means the plugin is not entirely risk-free.

In conclusion, imageboss v5.0.3 has implemented several good security practices, particularly in its limited attack surface and secure database handling. The main weaknesses lie in the unescaped output, which presents a direct risk of XSS, and the potential, albeit unconfirmed, risk associated with the bundled TinyMCE library. The historical vulnerability, while patched, serves as a reminder of the types of issues that have affected the plugin. Addressing the unescaped output should be a priority to further strengthen the plugin's security.

Key Concerns

  • Unescaped output detected (25%)
  • Bundled library with potential unknown risk (TinyMCE)
Vulnerabilities
1 published

ImageBoss – Image Optimization & CDN Security Vulnerabilities

CVEs by Year

1 CVE in 2020
2020
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2021-24888medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ImageBoss – Images Up To 60% Smaller & CDN < 3.0.6 - Cross-Site Scripting

May 11, 2020 Patched in 3.0.6 (1352d)
Version History

ImageBoss – Image Optimization & CDN Release Timeline

v5.0.3Current
v5.0.2
v5.0.1
v5.0.0
v4.0.0
v3.0.11
v3.0.10
v3.0.9
v3.0.8
v3.0.7
v3.0.6
v3.0.51 CVE
v3.0.41 CVE
v3.0.31 CVE
v3.0.21 CVE
v3.0.11 CVE
v3.0.01 CVE
v2.1.21 CVE
v2.1.11 CVE
v2.1.01 CVE
Code Analysis
Analyzed Apr 16, 2026

ImageBoss – Image Optimization & CDN Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

75% escaped8 total outputs
Attack Surface

ImageBoss – Image Optimization & CDN Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwp_footeradmin/includes/assets-setup.php:4
actionwp_enqueue_scriptsadmin/includes/assets-setup.php:5
actionadmin_menuadmin/includes/menu-customization.php:4
filterplugin_action_linksadmin/includes/plugin-actionlinks.php:4
actionadmin_initadmin/includes/plugin-activation.php:9
actionadmin_initadmin/includes/settings-group.php:4
actionwp_headpublic/imageboss-public.php:4
actionwp_footerpublic/imageboss-public.php:5
Maintenance & Trust

ImageBoss – Image Optimization & CDN Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version5.3.0
Downloads14K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ImageBoss – Image Optimization & CDN Developer Profile

igorescobar

1 plugin · 10 total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
1352 days
View full developer profile
Detection Fingerprints

How We Detect ImageBoss – Image Optimization & CDN

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/imageboss/public/js/imageboss-web-5.1.4.min.js/wp-content/plugins/imageboss/public/js/lazysizes.min.js
Script Paths
/wp-content/plugins/imageboss/public/js/imageboss-web-5.1.4.min.js/wp-content/plugins/imageboss/public/js/lazysizes.min.js
Version Parameters
imageboss-web-5.1.4.min.js?ver=5.1.4lazysizes.min.js?ver=5.3.2

HTML / DOM Fingerprints

Data Attributes
data-srcdata-srcsetdata-lowsrc
JS Globals
window.ImageBoss
FAQ

Frequently Asked Questions about ImageBoss – Image Optimization & CDN