
List Images Security & Risk Analysis
wordpress.org/plugins/list-imagesEasy way to view and manage all images.
Is List Images Safe to Use in 2026?
Generally Safe
Score 85/100List Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "list-images" v1.0.4 plugin demonstrates several positive security practices, including the exclusive use of prepared statements for all SQL queries and a very high percentage of properly escaped output. The limited attack surface, with no directly exploitable unprotected entry points and the presence of nonce checks on its AJAX handlers, further contributes to a generally good security posture. The absence of any recorded past vulnerabilities or CVEs suggests a mature and well-maintained codebase.
However, the taint analysis reveals two flows with unsanitized paths, flagged as high severity. While the static analysis indicates no critical issues and the vulnerability history is clean, these taint flows represent a potential risk that could be exploited if not properly handled. The lack of capability checks on its two AJAX handlers is also a concern, as it means any authenticated user could potentially trigger these functions, increasing the risk if the unsanitized paths can be manipulated. Overall, the plugin is strong in its handling of data and code execution but has specific areas requiring attention regarding input sanitization and access control on its entry points.
Key Concerns
- High severity taint flows with unsanitized paths
- Lack of capability checks on AJAX handlers
List Images Security Vulnerabilities
List Images Release Timeline
List Images Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
List Images Attack Surface
AJAX Handlers 2
WordPress Hooks 2
Maintenance & Trust
List Images Maintenance & Trust
Maintenance Signals
Community Trust
List Images Alternatives
Interactive Image Map Plugin – Draw Attention
draw-attention
Create interactive images with clickable hotspots, using modern image maps for WordPress. Perfect for floor plans, infographics, maps, and more.
Vision – Interactive Image Map Builder
vision
Empower your site with interactive visuals! Our plugin seamlessly transforms static images into engaging media, enabling publishers and bloggers.
Interactive Image – Real Estate Visualizer & Image Map
interactive-real-estate
⚡ Create interactive images with clickable zones on svg. Display floor plans, image maps, property details and 2D/3D photos. No coding required.
PicPoints
picpoints
Create interactive images with clickable hotspots for WordPress.
List Images Developer Profile
1 plugin · 10 total installs
How We Detect List Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/list-images/admin/css/app.css/wp-content/plugins/list-images/admin/js/app.js/wp-content/plugins/list-images/libraries/datatable/css/dataTables.jqueryui.css/wp-content/plugins/list-images/libraries/datatable/js/buttons.html5.min.js/wp-content/plugins/list-images/libraries/datatable/js/dataTables.buttons.min.js/wp-content/plugins/list-images/libraries/datatable/js/dataTables.jqueryui.css/wp-content/plugins/list-images/libraries/datatable/js/jquery.dataTables.min.js/wp-content/plugins/list-images/libraries/swal2/sweetalert2.min.css+1 more/wp-content/plugins/list-images/admin/js/app.jsHTML / DOM Fingerprints
il-thumbnail-imageeditable-celleditable-textet-filenameil-inputil-editableil-editable-filenamesize+10 moredata-idclassvaluesrcaltil_params