
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy Security & Risk Analysis
wordpress.org/plugins/instant-imagesOne-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
Is Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy Safe to Use in 2026?
Generally Safe
Score 98/100Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'instant-images' v7.1.0.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no apparent direct attack vectors through common entry points like AJAX handlers, REST API routes, or shortcodes without authentication. The code also demonstrates good practices by using prepared statements for all SQL queries and a relatively high percentage of output escaping. However, several concerning signals exist. The absence of nonce checks across the board is a significant oversight, especially when combined with two capability checks that might be insufficient on their own if not properly implemented. The plugin also makes three external HTTP requests, which, without further analysis, could potentially be exploited for SSRF or other network-related attacks. The vulnerability history is a major red flag. With three known CVEs, including one high and two medium severity vulnerabilities, and a recent one in January 2024, it suggests a pattern of security weaknesses. These past vulnerabilities, including Missing Authorization, SSRF, and XSS, indicate recurring issues that may not be fully addressed or might point to fundamental flaws in the development process.
Key Concerns
- No nonce checks detected
- External HTTP requests detected
- History of high severity vulnerabilities (1)
- History of medium severity vulnerabilities (2)
- Output escaping is not 100%
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Instant Images <= 6.1.0 - Authenticated (Author+) Arbitrary Options Update
Instant Images <= 5.1.0.1 - Authenticated (Author+) Server-Side Request Forgery via instant_images_download
Instant Images – One Click Unsplash, Pixabay and Pexels Uploads <= 4.4.0 - Authenticated Stored Cross-Site Scripting
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy Code Analysis
Output Escaping
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy Attack Surface
WordPress Hooks 15
Maintenance & Trust
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy Maintenance & Trust
Maintenance Signals
Community Trust
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy Alternatives
Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy)
ai-image
Search millions of stock photos, generate AI images with OpenAI & Gemini, browse GIFs, and import directly to your Media Library.
Image Hub – Free Images from Unsplash, Pixabay, Pexels, Openverse & Giphy
image-hub
Access and manage royalty-free images from Unsplash, Pixabay, Pexels, Openverse & Giphy without leaving your WordPress dashboard.
Dreamstime Stock Photos
dreamstime-stock-photos
Stock Photos by Dreamstime: Easily search and insert images into your posts and pages from Dreamstime's vast database of Free and Royalty-Free st …
Media Library Unsplash
media-library-unsplash
Easily add Unsplash photographs to your website instantly without ever leaving WordPress!
EB Openverse Block
eb-openverse-block
Easily search & use royalty free images, stock photos, CC-licensed images from Openverse for your website.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy Developer Profile
3 plugins · 200K total installs
How We Detect Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/instant-images/css/instant-images.css/wp-content/plugins/instant-images/js/instant-images.js/wp-content/plugins/instant-images/js/instant-images.jsinstant-images/css/instant-images.css?ver=instant-images/js/instant-images.js?ver=HTML / DOM Fingerprints
instant-images-downloadinstant-images-modalinstant-images-modal-contentinstant-images-modal-closeinstant-images-searchinstant-images-search-inputinstant-images-providerinstant-images-provider-logo+3 more<!-- Instant Images plugin --><!-- End Instant Images plugin -->data-instant-images-providerdata-instant-images-modal-triggerdata-instant-images-search-providerInstantImagesinstantImages/wp-json/instant-images/v1/search/wp-json/instant-images/v1/download/wp-json/instant-images/v1/settings/wp-json/instant-images/v1/license