
Import CDN-Remote Images Security & Risk Analysis
wordpress.org/plugins/import-cdn-remote-imagesAdd external images to the media library without importing, i.e. uploading them to your WordPress site.
Is Import CDN-Remote Images Safe to Use in 2026?
Generally Safe
Score 99/100Import CDN-Remote Images has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'import-cdn-remote-images' plugin version 2.1.3 exhibits a generally good security posture, with several positive indicators. The absence of dangerous functions, the use of prepared statements for all SQL queries, and the limited attack surface are commendable. Furthermore, the plugin correctly implements nonce and capability checks for its single AJAX entry point. The lack of critical or high-severity taint analysis findings is also a positive sign.
However, there are areas for improvement. While the majority of output is properly escaped, a significant portion (31%) is not, which could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is improperly handled. The plugin also makes three external HTTP requests, which, while not inherently insecure, represent potential vectors for man-in-the-middle attacks or other network-level issues if not implemented with care and secure protocols. The historical vulnerability data, while showing no currently unpatched issues, does indicate a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability, suggesting that thorough security practices are necessary.
In conclusion, the plugin has strengths in its foundational security practices like input sanitization for SQL and access control for its entry points. The primary concerns revolve around the potential for XSS due to unescaped output and the inherent risks associated with external HTTP requests. The past CSRF vulnerability reinforces the need for ongoing vigilance. Overall, the security is moderately strong, but not without potential weaknesses that warrant attention.
Key Concerns
- Unescaped output detected
- External HTTP requests detected
- Past medium severity CSRF vulnerability
Import CDN-Remote Images Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Import CDN-Remote Images <= 2.1.2 - Cross-Site Request Forgery
Import CDN-Remote Images Release Timeline
Import CDN-Remote Images Code Analysis
SQL Query Safety
Output Escaping
Import CDN-Remote Images Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Import CDN-Remote Images Maintenance & Trust
Maintenance Signals
Community Trust
Import CDN-Remote Images Alternatives
Auto Cloudinary
auto-cloudinary
Super simple Cloudinary auto-upload implementation for WordPress.
Dynamic Cloudinary
dynamic-cloudinary
Automatically serve all your images optimized from the cloud.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
Media Library Assistant
media-library-assistant
Enhances the Media Library; powerful gallery and list shortcodes, full taxonomy support, IPTC/EXIF/XMP/PDF processing, bulk/quick edit.
Quick Featured Images
quick-featured-images
The time-saving solution for managing tons of featured images within minutes: Set, replace and delete in bulk and set default images for future posts.
Import CDN-Remote Images Developer Profile
13 plugins · 2K total installs
How We Detect Import CDN-Remote Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/import-cdn-remote-images/assets/css/aauicri.css/wp-content/plugins/import-cdn-remote-images/assets/js/aauicri.js/wp-content/plugins/import-cdn-remote-images/assets/js/aauicri.jsimport-cdn-remote-images/assets/css/aauicri.css?ver=import-cdn-remote-images/assets/js/aauicri.js?ver=HTML / DOM Fingerprints
aauicri_ajax