Local Avatars by Nocksoft Security & Risk Analysis
wordpress.org/plugins/local-avatars-by-nocksoftAdds support for local avatars as an alternative to Gravatar.
Is Local Avatars by Nocksoft Safe to Use in 2026?
Generally Safe
Score 92/100Local Avatars by Nocksoft has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The local-avatars-by-nocksoft plugin v1.0.1 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The complete absence of known CVEs and the use of prepared statements for all SQL queries are significant strengths. Furthermore, the static analysis found no critical or high-severity taint flows, indicating a lack of obvious pathways for malicious data to be processed insecurely. The plugin also demonstrates some security awareness by implementing capability checks.
However, there are areas for improvement and potential underlying risks. The most notable concern is the 50% rate of improperly escaped output. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted without proper sanitization. Additionally, the absence of nonce checks, particularly if there were any unprotected AJAX handlers (though reported as zero), is a potential vulnerability point. The limited number of capability checks (2) might suggest that some functionalities, if they exist and were missed by the analysis, could be accessible without proper authorization.
Overall, the plugin's clean vulnerability history is a positive indicator, suggesting either good development practices or a lack of targeted attacks. However, the identified output escaping issues are a tangible risk that should be addressed. A deeper audit focusing on the unescaped outputs and the overall attack surface, even if reported as zero entry points, would be prudent for a comprehensive security assessment.
Key Concerns
- 50% of outputs are not properly escaped
- No nonce checks implemented
- Limited capability checks (2)
Local Avatars by Nocksoft Security Vulnerabilities
Local Avatars by Nocksoft Code Analysis
Output Escaping
Local Avatars by Nocksoft Attack Surface
WordPress Hooks 12
Maintenance & Trust
Local Avatars by Nocksoft Maintenance & Trust
Maintenance Signals
Community Trust
Local Avatars by Nocksoft Alternatives
Custom Post Avatar
custom-post-avatar
Custom Post Avatar gives you the possibility to replace your default avatar by a custom image on each post individually.
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
Simple Local Avatars
simple-local-avatars
Adds an avatar upload field to user profiles. Generates requested sizes on demand just like Gravatar!
User Profile Picture
metronet-profile-picture
Set a custom profile image (avatar) for a user using the standard WordPress media upload tool.
Basic User Avatars
basic-user-avatars
Add an avatar upload field on frontend pages and Edit Profile screen so users can add a custom profile picture.
Local Avatars by Nocksoft Developer Profile
2 plugins · 300 total installs
How We Detect Local Avatars by Nocksoft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/local-avatars-by-nocksoft/js/imagepicker.js/wp-content/plugins/local-avatars-by-nocksoft/js/imagepicker.jsHTML / DOM Fingerprints
nstla_setting_localavatarnstla_setting_avatarurlnstla_avatarimgnstla_avatarinputnstla_setavatarnstla_deleteavatar+2 morenstla_imagepicker