AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Security & Risk Analysis

wordpress.org/plugins/imghaste

Speed up your website using cutting edge Image Service. Service Worker, Client Hints, WebP, 100% white labeled. NO URL Rewrite required.

200 active installs v1.2.0 PHP 5.4+ WP 3.0.1+ Updated Nov 26, 2021
avifcdnclient-hintsservice-workerwebp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Safe to Use in 2026?

Generally Safe

Score 85/100

AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The imghaste v1.2.0 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points significantly limits the plugin's direct attack surface. Furthermore, all SQL queries utilize prepared statements, and the plugin demonstrates a reasonable level of output escaping. The single capability check suggests some access control is in place, though its scope is not detailed.

Despite these positives, there are notable concerns arising from the taint analysis. The high number of flows with unsanitized paths (11 out of 12) is a significant red flag, even though no critical or high severity vulnerabilities were identified in this specific scan. This indicates potential weaknesses where user-supplied data might be processed without proper sanitization, which could lead to vulnerabilities if exploited in conjunction with other factors or in different contexts not covered by this static scan. The lack of any recorded vulnerability history, while good, doesn't entirely negate the risks identified in the taint analysis, as new vulnerabilities can emerge.

In conclusion, imghaste v1.2.0 benefits from a limited attack surface and secure data handling for SQL queries. However, the high number of unsanitized paths in taint flows warrants caution and further investigation. The plugin's security could be further improved by addressing these unsanitized flows to prevent potential future vulnerabilities. The absence of nonce checks and the presence of file operations and external HTTP requests, while not explicitly flagged as issues, represent areas that often contribute to vulnerabilities if not implemented with extreme care.

Key Concerns

  • High number of unsanitized paths in taint flows
  • Lack of nonce checks
  • File operations present
  • External HTTP requests present
  • Only 1 capability check
Vulnerabilities
None known

AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
37
95 escaped
Nonce Checks
0
Capability Checks
1
File Operations
10
External Requests
3
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

72% escaped132 total outputs
Data Flows
11 unsanitized

Data Flow Analysis

12 flows11 with unsanitized paths
imghaste_field_cdn_url_cb (admin\partials\imghaste-admin-display.php:66)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 32
actionplugins_loadedclass-imghaste.php:175
actionadmin_enqueue_scriptsclass-imghaste.php:192
actionadmin_initclass-imghaste.php:194
actionadmin_menuclass-imghaste.php:196
actionadmin_noticesclass-imghaste.php:198
actioninitclass-imghaste.php:229
actionparse_requestclass-imghaste.php:232
actionparse_requestclass-imghaste.php:235
actionwp_enqueue_scriptsclass-imghaste.php:238
actionwp_headclass-imghaste.php:241
filterwp_get_attachment_urlclass-imghaste.php:272
filterwp_get_attachment_image_srcclass-imghaste.php:274
filterwp_calculate_image_srcsetclass-imghaste.php:276
filterthe_contentclass-imghaste.php:278
filtertemplate_redirectclass-imghaste.php:282
filtershutdownclass-imghaste.php:284
filtermax_srcset_image_widthclass-imghaste.php:291
filterintermediate_image_sizes_advancedclass-imghaste.php:292
actioninitclass-imghaste.php:306
actionparse_requestclass-imghaste.php:308
actionwp_headclass-imghaste.php:310
actionactivated_pluginimghaste.php:107
actionwp_headpublic\inc\class-imghaste-slimcss.php:158
actionwp_print_stylespublic\inc\class-imghaste-slimcss.php:160
actionwp_print_footer_scriptspublic\inc\class-imghaste-slimcss.php:162
filtertemplate_redirectpublic\inc\class-imghaste-slimcss.php:171
filtershutdownpublic\inc\class-imghaste-slimcss.php:172
actionwp_headpublic\slimcss\class-imghaste-slimcss.php:157
actionwp_print_stylespublic\slimcss\class-imghaste-slimcss.php:159
actionwp_print_footer_scriptspublic\slimcss\class-imghaste-slimcss.php:161
filtertemplate_redirectpublic\slimcss\class-imghaste-slimcss.php:163
filtershutdownpublic\slimcss\class-imghaste-slimcss.php:164
Maintenance & Trust

AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.0
Last updatedNov 26, 2021
PHP min version5.4
Downloads9K

Community Trust

Rating86/100
Number of ratings9
Active installs200
Developer Profile

AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One Developer Profile

ImgHaste

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/imghaste/admin/js/plugin-imghaste-settings.js/wp-content/plugins/imghaste/admin/js/plugin-imghaste-pwa-settings.js
Script Paths
/wp-content/plugins/imghaste/admin/js/plugin-imghaste-settings.js/wp-content/plugins/imghaste/admin/js/plugin-imghaste-pwa-settings.js
Version Parameters
plugin-imghaste-settings.js?ver=plugin-imghaste-pwa-settings.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Settings --><!-- General Settings --><!-- Settings for PWA --><!-- Health Check -->
Data Attributes
data-imghaste-url
JS Globals
ImghasteAdmin
FAQ

Frequently Asked Questions about AVIF, WebP, Image Optimization, CDN, Service Worker & Client Hints All in One