
KAPOW Image Recommendation Security & Risk Analysis
wordpress.org/plugins/kapow-image-recommendationKAPOW Image Recommendation plugin can analyse the text from your posts and pages and return relevant, freely usable images from unsplash.com.
Is KAPOW Image Recommendation Safe to Use in 2026?
Generally Safe
Score 85/100KAPOW Image Recommendation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kapow-image-recommendation" plugin v1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices regarding SQL queries and output escaping, with 100% of both being properly handled. The absence of known CVEs and a clean vulnerability history further suggests a historically well-maintained codebase.
However, significant security concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, and critically, both lack authentication checks. This presents a direct pathway for unauthenticated users to interact with sensitive plugin functionalities. Coupled with the taint analysis revealing two high-severity flows with unsanitized paths, these unauthenticated AJAX endpoints are prime targets for exploitation, potentially leading to unintended actions or data manipulation.
In conclusion, while the plugin's internal coding practices are commendable, the lack of authentication on its AJAX endpoints is a critical weakness that overshadows its strengths. The presence of high-severity taint flows in conjunction with these unprotected entry points necessitates immediate attention to secure these handlers. The clean vulnerability history is a positive indicator, but it does not mitigate the immediate risks identified in the current code analysis.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows
- Missing nonce checks on AJAX
KAPOW Image Recommendation Security Vulnerabilities
KAPOW Image Recommendation Release Timeline
KAPOW Image Recommendation Code Analysis
Output Escaping
Data Flow Analysis
KAPOW Image Recommendation Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
KAPOW Image Recommendation Maintenance & Trust
Maintenance Signals
Community Trust
KAPOW Image Recommendation Alternatives
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
Stock Images by Indietech
stock-images-by-indietech
Integrate stock photos directly into your WordPress Media Library. Search and import high-quality images from multiple sources.
WPJaipho Mobile Gallery
wpjaipho
WPJaipho extends native Wordpress image gallery, NextGEN 1.x and NextCellent Gallery with optimized support for mobile users
Photalika
photalika
Seamlessly integrate your WordPress website with Photalika, a powerful cloud platform for managing, storing, and showcasing your photos and media.
Pixplet Media Library
pixplet-media-library
Search free stock photos from Pixplet, import images to your Media Library, and set featured images directly inside WordPress.
KAPOW Image Recommendation Developer Profile
2 plugins · 20 total installs
How We Detect KAPOW Image Recommendation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kapow-image-recommendation/admin/css/kapow-admin.css/wp-content/plugins/kapow-image-recommendation/admin/js/kapow-admin.js/wp-content/plugins/kapow-image-recommendation/public/css/kapow-public.css/wp-content/plugins/kapow-image-recommendation/public/js/kapow-public.js/wp-content/plugins/kapow-image-recommendation/admin/js/kapow-admin.js/wp-content/plugins/kapow-image-recommendation/public/js/kapow-public.jskapow-image-recommendation/admin/css/kapow-admin.css?ver=kapow-image-recommendation/admin/js/kapow-admin.js?ver=kapow-image-recommendation/public/css/kapow-public.css?ver=kapow-image-recommendation/public/js/kapow-public.js?ver=HTML / DOM Fingerprints
kapow-api-keykapow-thresholdkapow-min-topic-scorekapow-img-per-tagkapow-settings-wrapkapow-setting-itemkapow-setting-labelkapow-setting-input+1 moreThe option key to store the user-defined KAPOW API access key.The option key to store the user-defined KAPOW model threshold parameter.The option key to store the user-defined KAPOW model minimum-topic-score parameter.The option key to store the user-defined KAPOW model number-of-images-per-page parameter.+8 moredata-option-namedata-mindata-maxdata-stepdata-clean-funcKAPOW_Admin/wp-json/kapow/v1/settings