
LH Add Media From Url Security & Risk Analysis
wordpress.org/plugins/lh-add-media-from-urlUpload files from an url to wordpress media library, either enter file urls in an onsite input box or click a bookmarklet.
Is LH Add Media From Url Safe to Use in 2026?
Generally Safe
Score 91/100LH Add Media From Url has a strong security track record. Known vulnerabilities have been patched promptly.
The "lh-add-media-from-url" plugin version 1.30 exhibits a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries, utilizing prepared statements exclusively, and includes a nonce check and capability checks for some operations. The static analysis found no critical or high severity taint flows, and the attack surface from AJAX handlers, REST API routes, shortcodes, and cron events is reported as zero, with none of these being unprotected. However, a significant concern is the low rate of proper output escaping, with only 29% of outputs being correctly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, which is further corroborated by its vulnerability history.
The plugin has a history of two medium severity vulnerabilities, both of which were Cross-Site Scripting (XSS) issues. The most recent vulnerability was reported on August 20, 2024, and the good news is that there are currently no unpatched vulnerabilities. Despite the absence of critical or high-severity taint flows in the static analysis and the zero reported unprotected entry points, the historical prevalence of XSS and the low output escaping rate are notable weaknesses. This suggests that while the plugin's core functionalities might be well-protected, user-supplied data might not be sufficiently sanitized before being rendered in the browser, posing a risk to users of the WordPress site.
Key Concerns
- Low output escaping rate (29%)
- History of medium severity XSS vulnerabilities
LH Add Media From Url Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
LH Add Media From Url <= 1.23 - Reflected Cross-Site Scripting
LH Add Media From Url <= 1.22 - Reflected Cross-Site Scripting
LH Add Media From Url Code Analysis
SQL Query Safety
Output Escaping
LH Add Media From Url Attack Surface
WordPress Hooks 3
Maintenance & Trust
LH Add Media From Url Maintenance & Trust
Maintenance Signals
Community Trust
LH Add Media From Url Alternatives
Add Media from URL
add-media-from-url
Let you add media files into your media library without having to upload them.
LH Browser Shots
lh-browser-shots
Add screenshots of remote wesbites directly to the wordpress media library, either enter the site url in an onsite input box or click a bookmarklet.
DX Delete Attached Media
dx-delete-attached-media
Automatically deletes attached media from posts and custom post types added via the Media button.
Autoremove Attachments
autoremove-attachments
Remove child attachments when parent post, page or custom post type is deleted.
Fix Media Library
wow-media-library-fix
Fix Media Library inconsistency between database and wp-content/uploads folder contents. Unused image files, broken media library entries, missing att …
LH Add Media From Url Developer Profile
77 plugins · 15K total installs
How We Detect LH Add Media From Url
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-add-media-from-url/css/main.css/wp-content/plugins/lh-add-media-from-url/js/main.js/wp-content/plugins/lh-add-media-from-url/js/main.jslh-add-media-from-url/css/main.css?ver=lh-add-media-from-url/js/main.js?ver=HTML / DOM Fingerprints
lh-add-media-from-url-upload-formdata-lh-add-media-from-url-nonceLH_add_media_from_url