
LH Copy Media File Security & Risk Analysis
wordpress.org/plugins/lh-copy-media-fileAllows you to create duplicate images in the media library.
Is LH Copy Media File Safe to Use in 2026?
Generally Safe
Score 91/100LH Copy Media File has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the "lh-copy-media-file" plugin version 1.11 reveals a generally strong security posture, with no identified dangerous functions, all SQL queries using prepared statements, and all output properly escaped. Furthermore, the plugin exhibits a limited attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events. This indicates good development practices in minimizing potential entry points. The presence of one external HTTP request and one nonce check suggests some interaction with external resources or internal WordPress security mechanisms, which is generally acceptable. Taint analysis shows no critical or high severity issues, reinforcing the internal code safety.
However, the plugin's vulnerability history presents a significant concern. A single known CVE exists, and while it is currently patched, its past occurrence and classification as improper neutralization of input during web page generation (Cross-site Scripting) is a notable pattern. While the current version may be secure, this historical incident suggests a potential for vulnerabilities of this type, especially if future updates introduce new features or modifications without rigorous security testing. The plugin's strengths lie in its clean code practices and minimal attack surface, but the historical XSS vulnerability warrants continued vigilance. Overall, the current version appears safe based on the static analysis, but the past vulnerability history should not be overlooked.
Key Concerns
- Known CVE in history
LH Copy Media File Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
LH Copy Media File <= 1.08 - Reflected Cross-Site Scripting
LH Copy Media File Code Analysis
Output Escaping
LH Copy Media File Attack Surface
WordPress Hooks 3
Maintenance & Trust
LH Copy Media File Maintenance & Trust
Maintenance Signals
Community Trust
LH Copy Media File Alternatives
Media Deduper
media-deduper
Save disk space and bring some order to the chaos of your media library by removing and preventing duplicate files.
Bulk Change Media Author
bulk-change-media-author
Bulk change author for multiple media files, using the default WP Media Library.
LH Add Media From Url
lh-add-media-from-url
Upload files from an url to wordpress media library, either enter file urls in an onsite input box or click a bookmarklet.
Custom Post Type Attachment
custom-post-type-pdf-attachment
This plugin will allow you to upload files to your post or pages or any other custom post types.
Media Vault
media-vault
Protect attachment files from direct access using powerful and flexible restrictions. Offer safe download links for any file in your uploads folder.
LH Copy Media File Developer Profile
77 plugins · 15K total installs
How We Detect LH Copy Media File
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
lh_copy_media_file_linkdata-lh-copy-media-file-hander-postid