LH Copy Media File Security & Risk Analysis

wordpress.org/plugins/lh-copy-media-file

Allows you to create duplicate images in the media library.

800 active installs v1.11 PHP + WP 4.1+ Updated Oct 1, 2024
attachmentdownloadmediamedia-managerupload
91
A · Safe
CVEs total1
Unpatched0
Last CVESep 30, 2024
Safety Verdict

Is LH Copy Media File Safe to Use in 2026?

Generally Safe

Score 91/100

LH Copy Media File has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Sep 30, 2024Updated 1yr ago
Risk Assessment

The static analysis of the "lh-copy-media-file" plugin version 1.11 reveals a generally strong security posture, with no identified dangerous functions, all SQL queries using prepared statements, and all output properly escaped. Furthermore, the plugin exhibits a limited attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events. This indicates good development practices in minimizing potential entry points. The presence of one external HTTP request and one nonce check suggests some interaction with external resources or internal WordPress security mechanisms, which is generally acceptable. Taint analysis shows no critical or high severity issues, reinforcing the internal code safety.

However, the plugin's vulnerability history presents a significant concern. A single known CVE exists, and while it is currently patched, its past occurrence and classification as improper neutralization of input during web page generation (Cross-site Scripting) is a notable pattern. While the current version may be secure, this historical incident suggests a potential for vulnerabilities of this type, especially if future updates introduce new features or modifications without rigorous security testing. The plugin's strengths lie in its clean code practices and minimal attack surface, but the historical XSS vulnerability warrants continued vigilance. Overall, the current version appears safe based on the static analysis, but the past vulnerability history should not be overlooked.

Key Concerns

  • Known CVE in history
Vulnerabilities
1 published

LH Copy Media File Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-9220medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

LH Copy Media File <= 1.08 - Reflected Cross-Site Scripting

Sep 30, 2024 Patched in 1.09 (4d)
Version History

LH Copy Media File Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

LH Copy Media File Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

LH Copy Media File Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtermedia_row_actionslh-copy-media-file.php:138
actionadmin_initlh-copy-media-file.php:139
actionplugins_loadedlh-copy-media-file.php:164
Maintenance & Trust

LH Copy Media File Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 1, 2024
PHP min version
Downloads15K

Community Trust

Rating80/100
Number of ratings7
Active installs800
Developer Profile

LH Copy Media File Developer Profile

shawfactor

89 plugins · 15K total installs

90
trust score
Avg Security Score
85/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH Copy Media File

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
lh_copy_media_file_link
Data Attributes
data-lh-copy-media-file-hander-postid
FAQ

Frequently Asked Questions about LH Copy Media File