Imagero – Auto Image Optimizer & Watermark with R2 Offload Security & Risk Analysis

wordpress.org/plugins/imagero

Automatically resize, convert to WebP, and watermark uploaded images. Optionally offload to Cloudflare R2.

10 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Jan 9, 2026
image-optimizationwatermarkwebp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Imagero – Auto Image Optimizer & Watermark with R2 Offload Safe to Use in 2026?

Generally Safe

Score 100/100

Imagero – Auto Image Optimizer & Watermark with R2 Offload has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "imagero" plugin version 1.0.0 demonstrates a generally strong security posture based on the provided static analysis. The plugin has no recorded vulnerabilities, which is a significant positive indicator. The code analysis reveals a minimal attack surface, with only one AJAX handler that correctly implements nonce and capability checks, meaning there are no directly unprotected entry points.

Furthermore, the plugin adheres to good coding practices. It avoids dangerous functions, uses prepared statements for all SQL queries, and properly escapes most of its output. The taint analysis found no critical or high severity unsanitized flows, and the plugin does not bundle any external libraries, reducing the risk of inherited vulnerabilities. The single file operation and single external HTTP request are not inherently risky without further context, but they represent potential areas for future scrutiny if issues arise.

While the plugin is commendably secure in its current state, the limited analysis (2 taint flows) and the presence of file operations and external requests are minor points of consideration. The absence of any past vulnerabilities is excellent, but it's crucial to maintain vigilance with ongoing updates and security practices, as new vulnerabilities can emerge in any software. Overall, "imagero" v1.0.0 appears to be a secure plugin with robust security measures in place, exhibiting a low-risk profile.

Vulnerabilities
None known

Imagero – Auto Image Optimizer & Watermark with R2 Offload Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Imagero – Auto Image Optimizer & Watermark with R2 Offload Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Imagero – Auto Image Optimizer & Watermark with R2 Offload Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
31 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

97% escaped32 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
imagero_save_settings_ajax (imagero.php:97)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Imagero – Auto Image Optimizer & Watermark with R2 Offload Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_imagero_save_settingsimagero.php:126
WordPress Hooks 8
actionadmin_initimagero.php:57
actionadmin_enqueue_scriptsimagero.php:94
actionadmin_initincludes\admin-page.php:29
actionadmin_menuincludes\admin-page.php:40
filterwp_handle_uploadincludes\image-processor.php:10
filterwp_generate_attachment_metadataincludes\image-processor.php:11
filterwp_get_attachment_urlincludes\image-processor.php:12
filterwp_calculate_image_srcsetincludes\image-processor.php:13
Maintenance & Trust

Imagero – Auto Image Optimizer & Watermark with R2 Offload Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 9, 2026
PHP min version7.4
Downloads351

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Imagero – Auto Image Optimizer & Watermark with R2 Offload Developer Profile

wpnovate

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Imagero – Auto Image Optimizer & Watermark with R2 Offload

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/imagero/assets/js/tailwind.js/wp-content/plugins/imagero/assets/css/admin.css/wp-content/plugins/imagero/assets/js/admin.js
Script Paths
/wp-content/plugins/imagero/assets/js/tailwind.js/wp-content/plugins/imagero/assets/js/admin.js
Version Parameters
imagero/assets/css/admin.css?ver=imagero/assets/js/admin.js?ver=imagero/assets/js/tailwind.js?ver=

HTML / DOM Fingerprints

Data Attributes
imagero_ajaximagero_save_settings_nonce
JS Globals
imagero_ajax
FAQ

Frequently Asked Questions about Imagero – Auto Image Optimizer & Watermark with R2 Offload