
Import CDN-Remote Images Security & Risk Analysis
wordpress.org/plugins/import-cdn-remote-imagesAdd external images to the media library without importing, i.e. uploading them to your WordPress site.
Is Import CDN-Remote Images Safe to Use in 2026?
Generally Safe
Score 99/100Import CDN-Remote Images has a strong security track record. Known vulnerabilities have been patched promptly.
The 'import-cdn-remote-images' plugin version 2.1.3 exhibits a generally good security posture, with several positive indicators. The absence of dangerous functions, the use of prepared statements for all SQL queries, and the limited attack surface are commendable. Furthermore, the plugin correctly implements nonce and capability checks for its single AJAX entry point. The lack of critical or high-severity taint analysis findings is also a positive sign.
However, there are areas for improvement. While the majority of output is properly escaped, a significant portion (31%) is not, which could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is improperly handled. The plugin also makes three external HTTP requests, which, while not inherently insecure, represent potential vectors for man-in-the-middle attacks or other network-level issues if not implemented with care and secure protocols. The historical vulnerability data, while showing no currently unpatched issues, does indicate a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability, suggesting that thorough security practices are necessary.
In conclusion, the plugin has strengths in its foundational security practices like input sanitization for SQL and access control for its entry points. The primary concerns revolve around the potential for XSS due to unescaped output and the inherent risks associated with external HTTP requests. The past CSRF vulnerability reinforces the need for ongoing vigilance. Overall, the security is moderately strong, but not without potential weaknesses that warrant attention.
Key Concerns
- Unescaped output detected
- External HTTP requests detected
- Past medium severity CSRF vulnerability
Import CDN-Remote Images Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Import CDN-Remote Images <= 2.1.2 - Cross-Site Request Forgery
Import CDN-Remote Images Code Analysis
SQL Query Safety
Output Escaping
Import CDN-Remote Images Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Import CDN-Remote Images Maintenance & Trust
Maintenance Signals
Community Trust
Import CDN-Remote Images Alternatives
Auto Cloudinary
auto-cloudinary
Super simple Cloudinary auto-upload implementation for WordPress.
Auto Save Remote Image
auto-save-remote-images
This plugin automatically downloads the first remote image from a post and sets it as the featured image.
Archive Remote Images
archive-remote-images
Archive Remote Images allows you to scan a post to fetch remote images; then updates its content automatically.
Grab Image From Remote URL
grab-image-from-remote-url
Allows you to download image from Remote URL to save Wordpress Media Gallery.
LH Cache Remote Images
lh-cache-remote-images
LH Cache Remote Images allows you to scan a post to fetch remote images; then updates its content automatically.
Import CDN-Remote Images Developer Profile
10 plugins · 2K total installs
How We Detect Import CDN-Remote Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/import-cdn-remote-images/assets/css/aauicri.css/wp-content/plugins/import-cdn-remote-images/assets/js/aauicri.js/wp-content/plugins/import-cdn-remote-images/assets/js/aauicri.jsimport-cdn-remote-images/assets/css/aauicri.css?ver=import-cdn-remote-images/assets/js/aauicri.js?ver=HTML / DOM Fingerprints
aauicri_ajax