
Lana Text to Image Security & Risk Analysis
wordpress.org/plugins/lana-text-to-imageEasy to use text to image shortcode
Is Lana Text to Image Safe to Use in 2026?
Generally Safe
Score 85/100Lana Text to Image has a strong security track record. Known vulnerabilities have been patched promptly.
The lana-text-to-image plugin v1.1.0 demonstrates several positive security practices, including the absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and proper output escaping. The static analysis also reveals a limited attack surface with no unprotected entry points and no identified taint flows of critical or high severity. However, the plugin's vulnerability history is a significant concern. It has a known CVE, although it is currently patched. The presence of a past medium-severity vulnerability, specifically Cross-site Scripting, indicates a potential weakness in input handling. The lack of nonce checks and capability checks in the provided static analysis data, despite the presence of shortcodes, also warrants attention as it could represent an indirect risk if not handled appropriately within the shortcode's implementation.
Key Concerns
- Known CVE in history
- Past medium vulnerability (XSS)
- Missing nonce checks
- Missing capability checks
Lana Text to Image Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Lana Text to Image <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Lana Text to Image Code Analysis
Output Escaping
Lana Text to Image Attack Surface
Shortcodes 2
WordPress Hooks 4
Maintenance & Trust
Lana Text to Image Maintenance & Trust
Maintenance Signals
Community Trust
Lana Text to Image Alternatives
My Private Site
jonradio-private-site
Make your WordPress site private with one click for family, projects, or teams. Protection for content, login, and registration.
Restricted Site Access
restricted-site-access
Limit access to visitors who are logged in or allowed by IP addresses. Includes many options for handling blocked visitors.
The GDPR Framework By Data443
gdpr-framework
Easy to use tools to help make your website GDPR-compliant. Fully documented, extendable and developer-friendly. Extensions to enterprise GDPR compli …
Logout Clear Cookies
logout-clear-cookies
Clears all domain cookies on logout. Because leaving a trail of cookies is bad.
WP Author Security
wp-author-security
Protect against user enumeration attacks on author pages and other places where valid user names can be obtained.
Lana Text to Image Developer Profile
13 plugins · 4K total installs
How We Detect Lana Text to Image
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lana-text-to-image/assets/css/lana-text-to-image-admin.css/wp-content/plugins/lana-text-to-image/assets/js/lana-text-to-image-shortcode.jslana-text-to-image/assets/css/lana-text-to-image-admin.css?ver=lana-text-to-image/assets/js/lana-text-to-image-shortcode.js?ver=HTML / DOM Fingerprints
lana-text-to-image<img src="data:image/png;base64,