Intrinsic Images for Woo Security & Risk Analysis

wordpress.org/plugins/intrinsic-images-for-woo

Add intrinsic image values to the HTML source code to ensure the correct size image is served

10 active installs v1.0.0 PHP 7.0+ WP 5.0+ Updated May 12, 2021
image-optimisationimage-optimizationimagesintrinsic-imageswoocommerce-images
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Intrinsic Images for Woo Safe to Use in 2026?

Generally Safe

Score 85/100

Intrinsic Images for Woo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "intrinsic-images-for-woo" v1.0.0 plugin exhibits a generally strong security posture based on the static analysis provided. The absence of detectable AJAX handlers, REST API routes, shortcodes, cron events, and external HTTP requests significantly limits its attack surface. Furthermore, the code signals indicate no dangerous functions, file operations, or bundled libraries, and all SQL queries are properly prepared. This suggests a development focus on secure coding practices regarding input validation and database interactions. The lack of any recorded vulnerabilities, past or present, also contributes to a positive security assessment, indicating a history of stable and secure code.

However, a notable concern arises from the output escaping. With 50% of outputs not being properly escaped, this presents a potential risk for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is reflected in the output without sanitization. While the absence of taint analysis results and known CVEs is positive, the incomplete output escaping remains a specific area that warrants attention. The plugin's current version seems secure against known threats and common attack vectors, but the potential for XSS due to insufficient output escaping is the primary weakness identified.

Key Concerns

  • Half of outputs are not properly escaped
Vulnerabilities
None known

Intrinsic Images for Woo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Intrinsic Images for Woo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface

Intrinsic Images for Woo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuincl\plugin-options.php:32
actionadmin_initincl\plugin-options.php:33
actionadmin_footerincl\plugin-options.php:34
actionadmin_enqueue_scriptsincl\plugin-options.php:35
actionrest_api_initincl\rest-api.php:21
actionrest_api_initincl\rest-api.php:22
actionrest_api_initincl\rest-api.php:24
actionrest_api_initincl\rest-api.php:25
Maintenance & Trust

Intrinsic Images for Woo Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 12, 2021
PHP min version7.0
Downloads963

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Intrinsic Images for Woo Developer Profile

johnc1979

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Intrinsic Images for Woo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/intrinsic-images-for-woo/assets/css/intrinsic-images-for-woo.css/wp-content/plugins/intrinsic-images-for-woo/assets/js/intrinsic-images-for-woo.js
Script Paths
/wp-content/plugins/intrinsic-images-for-woo/assets/js/intrinsic-images-for-woo.js
Version Parameters
intrinsic-images-for-woo/assets/css/intrinsic-images-for-woo.css?ver=intrinsic-images-for-woo/assets/js/intrinsic-images-for-woo.js?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/intrinsic-images-for-woo/v1
FAQ

Frequently Asked Questions about Intrinsic Images for Woo