
AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Security & Risk Analysis
wordpress.org/plugins/imghasteSpeed up your website using cutting edge Image Service. Service Worker, Client Hints, WebP, 100% white labeled. NO URL Rewrite required.
Is AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Safe to Use in 2026?
Generally Safe
Score 85/100AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The imghaste v1.2.0 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points significantly limits the plugin's direct attack surface. Furthermore, all SQL queries utilize prepared statements, and the plugin demonstrates a reasonable level of output escaping. The single capability check suggests some access control is in place, though its scope is not detailed.
Despite these positives, there are notable concerns arising from the taint analysis. The high number of flows with unsanitized paths (11 out of 12) is a significant red flag, even though no critical or high severity vulnerabilities were identified in this specific scan. This indicates potential weaknesses where user-supplied data might be processed without proper sanitization, which could lead to vulnerabilities if exploited in conjunction with other factors or in different contexts not covered by this static scan. The lack of any recorded vulnerability history, while good, doesn't entirely negate the risks identified in the taint analysis, as new vulnerabilities can emerge.
In conclusion, imghaste v1.2.0 benefits from a limited attack surface and secure data handling for SQL queries. However, the high number of unsanitized paths in taint flows warrants caution and further investigation. The plugin's security could be further improved by addressing these unsanitized flows to prevent potential future vulnerabilities. The absence of nonce checks and the presence of file operations and external HTTP requests, while not explicitly flagged as issues, represent areas that often contribute to vulnerabilities if not implemented with extreme care.
Key Concerns
- High number of unsanitized paths in taint flows
- Lack of nonce checks
- File operations present
- External HTTP requests present
- Only 1 capability check
AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Security Vulnerabilities
AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Attack Surface
WordPress Hooks 32
Maintenance & Trust
AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Maintenance & Trust
Maintenance Signals
Community Trust
AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Alternatives
ImageEngine – Optimize the Images on Your WordPress Site Like No Other Plugin
image-cdn
Automatically optimize and serve WEBP, AVIF and JPEGXL with ImageEngine, the global Image CDN. 60 sec setup.
Automatic Image Optimizer & CDN by wpimg.io
automatic-image-optimizer-cdn
Instantly speed up your site with automated image optimization, WebP/AVIF, and global CDN. Zero setup required.
Flux Media Optimizer by Flux Plugins
flux-media-optimizer
Automatically optimize images, compress videos, and deliver media via global CDN. Boost Core Web Vitals and SEO with 50-70% smaller file sizes.
Image Optimizer – Optimize Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
Imagify Image Optimization – Optimize Images | Compress Images | Convert WebP | Convert AVIF
imagify
Optimize images in 1-click: compress images, convert to WebP & AVIF, resize, and boost your site with the easiest WordPress image optimization plugin!
AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Developer Profile
1 plugin · 200 total installs
How We Detect AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/imghaste/admin/js/plugin-imghaste-settings.js/wp-content/plugins/imghaste/admin/js/plugin-imghaste-pwa-settings.js/wp-content/plugins/imghaste/admin/js/plugin-imghaste-settings.js/wp-content/plugins/imghaste/admin/js/plugin-imghaste-pwa-settings.jsplugin-imghaste-settings.js?ver=plugin-imghaste-pwa-settings.js?ver=HTML / DOM Fingerprints
<!-- Settings --><!-- General Settings --><!-- Settings for PWA --><!-- Health Check -->data-imghaste-urlImghasteAdmin