
Linked Media Without Import Security & Risk Analysis
wordpress.org/plugins/linked-media-without-importLink to media from other servers without importing them, saving your server's storage and improving performance.
Is Linked Media Without Import Safe to Use in 2026?
Generally Safe
Score 100/100Linked Media Without Import has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "linked-media-without-import" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. There are no identified critical or high severity taint flows, and all SQL queries are properly prepared, mitigating the risk of SQL injection. Furthermore, all output is correctly escaped, and file operations are absent, reducing the potential for cross-site scripting and unauthorized file access. The plugin also correctly utilizes capability checks for its single REST API endpoint, indicating a good understanding of WordPress security best practices.
Despite these strengths, the absence of nonce checks across all entry points is a notable concern. While the REST API has a permission callback, the lack of nonce verification leaves it potentially vulnerable to Cross-Site Request Forgery (CSRF) attacks if a malicious actor can trick a logged-in user into triggering an action. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this absence of history, combined with the lack of nonce checks, suggests a need for continued vigilance and testing as the plugin evolves. Overall, the plugin is well-secured in several key areas, but the missing nonce checks represent a specific, addressable risk.
Key Concerns
- Missing nonce checks on entry points
Linked Media Without Import Security Vulnerabilities
Linked Media Without Import Release Timeline
Linked Media Without Import Code Analysis
SQL Query Safety
Output Escaping
Linked Media Without Import Attack Surface
REST API Routes 1
WordPress Hooks 11
Maintenance & Trust
Linked Media Without Import Maintenance & Trust
Maintenance Signals
Community Trust
Linked Media Without Import Alternatives
Advanced Media Offloader
advanced-media-offloader
Save server space & speed up your site by automatically offloading media to Amazon S3, Cloudflare R2 & more.
Offload Media – Cloud Storage
offload-media-cloud-storage
Offload Media moves your WordPress files to cloud storage (AWS S3, DigitalOcean, Cloudflare R2, Google Cloud) to improve site performance.
MA Smart Image Cleaner
ma-smart-image-cleaner
Safely find and clean unused images in your WordPress Media Library without breaking your website.
Compressify | Image Optimizer | Convert WebP
compressify
Compress images on upload and in bulk to reduce file size and speed up sites.
ImgSmaller – Optimize Images | Compress Images | Convert WebP & AVIF
imgsmaller
Compress and optimize your WordPress media library images using the ImgSmaller API with automated backups and restore controls.
Linked Media Without Import Developer Profile
3 plugins · 30 total installs
How We Detect Linked Media Without Import
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/linked-media-without-import/build/admin.js/wp-content/plugins/linked-media-without-import/build/admin.css/wp-content/plugins/linked-media-without-import/build/index.jslinked-media-without-import/build/admin.js?ver=linked-media-without-import/build/admin.css?ver=linked-media-without-import/build/index.js?ver=HTML / DOM Fingerprints
lmwi-admin-app/wp-json/lmwi/v1/add-media