
JS Crop Security & Risk Analysis
wordpress.org/plugins/js-cropPlugin which enables user to crop image and upload it which can be access with media page,
Is JS Crop Safe to Use in 2026?
Generally Safe
Score 100/100JS Crop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The js-crop plugin version 3.1.0 exhibits a concerning security posture, primarily due to its unprotected entry points. The static analysis reveals two AJAX handlers that lack any authentication or capability checks, creating a significant attack surface. Furthermore, the taint analysis indicates two flows with unsanitized paths, suggesting a potential for unexpected behavior or vulnerabilities if these paths are user-controlled. While the plugin shows strengths in avoiding dangerous functions, using prepared statements for SQL, and having no recorded vulnerability history, these positive aspects are overshadowed by the critical flaws in its input validation and access control for AJAX requests. The absence of nonce checks and capability checks on these handlers is a major concern, as it could allow unauthenticated users to trigger potentially harmful operations within the plugin.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
- Low output escaping coverage
JS Crop Security Vulnerabilities
JS Crop Code Analysis
Output Escaping
Data Flow Analysis
JS Crop Attack Surface
AJAX Handlers 2
WordPress Hooks 1
Maintenance & Trust
JS Crop Maintenance & Trust
Maintenance Signals
Community Trust
JS Crop Alternatives
Pic Tag
pic-tag
Tag object in image using Deep learning
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
JS Crop Developer Profile
17 plugins · 2K total installs
How We Detect JS Crop
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/js-crop/build/index.js/wp-content/plugins/js-crop/build/style-index.css/wp-content/plugins/js-crop/build/index.jsjs-crop/build/index.js?ver=js-crop/build/style-index.css?ver=HTML / DOM Fingerprints
data-ajax-url<div id="image-load"<input id="upload-img" type="file"<p><a id="browse-image" href="javascript:void(0)">Browse</a> or Drop image here</p>