Logo or Image Replace by mycore.global Security & Risk Analysis

wordpress.org/plugins/logo-or-image-replace

Wordpress plugin to replace logo or any image per page. Useful to choose a new company logo per page.

500 active installs v1.1.7 PHP 5.6+ WP 4.6+ Updated Dec 17, 2025
ai-imageblur-imagedifferent-logoimage-replacereplace-logo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Logo or Image Replace by mycore.global Safe to Use in 2026?

Generally Safe

Score 100/100

Logo or Image Replace by mycore.global has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The plugin "logo-or-image-replace" v1.1.7 exhibits a strong security posture based on the provided static analysis. There are no identified entry points (AJAX, REST API, shortcodes, cron events) which significantly limits the attack surface. The code further demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output. The presence of nonce and capability checks, even with a limited attack surface, indicates awareness of WordPress security fundamentals.

Concerns are minimal, with the taint analysis showing no critical or high severity flows, suggesting no obvious injection vulnerabilities are being introduced. The complete absence of known CVEs and historical vulnerabilities further reinforces its current stable security status. While the plugin's minimal entry points are a significant strength, the limited scope of the static analysis (0 flows analyzed) means potential, undiscovered taint issues cannot be definitively ruled out.

Overall, "logo-or-image-replace" v1.1.7 appears to be a securely developed plugin with no immediate, glaring security flaws. Its strengths lie in its limited attack surface and adherence to secure coding practices for the code that was analyzed. The lack of historical vulnerabilities is a positive indicator, though a comprehensive code review would provide greater assurance.

Key Concerns

  • Taint analysis scope is limited
Vulnerabilities
None known

Logo or Image Replace by mycore.global Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Logo or Image Replace by mycore.global Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
18 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped20 total outputs
Attack Surface

Logo or Image Replace by mycore.global Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_headclass-free-upgrade-notice.php:34
actionplugin_row_metaclass-free-upgrade-notice.php:115
actionadmin_menuclass-free-upgrade-notice.php:157
actionadmin_enqueue_scriptsimage-replace-by-mycore.php:46
actionwp_enqueue_scriptsimage-replace-by-mycore.php:79
actionadd_meta_boxesimage-replace-by-mycore.php:93
actionsave_postimage-replace-by-mycore.php:176
actionupgrader_process_completeimage-replace-by-mycore.php:194
actionadmin_menuincludes\admin-menu.php:31
filtercustom_menu_orderincludes\admin-menu.php:43
actionadmin_initincludes\settings-page.php:2
Maintenance & Trust

Logo or Image Replace by mycore.global Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 17, 2025
PHP min version5.6
Downloads9K

Community Trust

Rating94/100
Number of ratings3
Active installs500
Developer Profile

Logo or Image Replace by mycore.global Developer Profile

QuantumCloud

29 plugins · 26K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
255 days
View full developer profile
Detection Fingerprints

How We Detect Logo or Image Replace by mycore.global

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/logo-or-image-replace/assets/js/admin-script.js/wp-content/plugins/logo-or-image-replace/assets/css/admin-style.css/wp-content/plugins/logo-or-image-replace/assets/js/front-script.js
Script Paths
media-uploadthickbox
Version Parameters
logo-or-image-replace/assets/js/admin-script.js?ver=logo-or-image-replace/assets/css/admin-style.css?ver=logo-or-image-replace/assets/js/front-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
qc-review-text
HTML Comments
The actual field that will hold the URL for our fileThe `data-media-uploader-target` value should match the ID/unique selector of your field.We'll use this value to dynamically inject the file URL of our uploaded media asset into your field once successful (in the myplugin-media.js file)
Data Attributes
data-media-uploader-target="#qc_lpp_replacing_image_url"
JS Globals
meta_imageqc_lpp_js_vars
FAQ

Frequently Asked Questions about Logo or Image Replace by mycore.global