
Max Image Size Control Security & Risk Analysis
wordpress.org/plugins/max-image-size-controlThis plugin adds the functionality to change the max image size each category and post.
Is Max Image Size Control Safe to Use in 2026?
Generally Safe
Score 85/100Max Image Size Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "max-image-size-control" v0.2.7 plugin exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL queries by exclusively using prepared statements, and there are no reported vulnerabilities in its history, suggesting a generally stable and well-maintained codebase. Furthermore, the absence of external HTTP requests, file operations, and a clean taint analysis indicate a low risk of common web attack vectors like injection, remote code execution, or sensitive data exfiltration through these means.
However, significant concerns arise from the static analysis. The presence of 10 instances of the `create_function` construct is a critical red flag. This function is deprecated and considered a major security risk due to its ability to execute arbitrary code. Coupled with this, only 20% of output escaping is properly implemented, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks on its entry points further exacerbates these risks, allowing unauthenticated or unauthorized users to potentially trigger vulnerable code paths.
In conclusion, while the plugin avoids common pitfalls like raw SQL and external requests, the identified issues with `create_function` and inadequate output escaping present substantial security risks. The lack of historical vulnerabilities is a positive indicator, but the static analysis findings demand immediate attention to mitigate potential XSS and code execution vulnerabilities.
Key Concerns
- Use of deprecated and dangerous create_function
- Low percentage of properly escaped output (potential XSS)
- Missing nonce checks on entry points
- Missing capability checks on entry points
Max Image Size Control Security Vulnerabilities
Max Image Size Control Code Analysis
Dangerous Functions Found
Output Escaping
Max Image Size Control Attack Surface
WordPress Hooks 9
Maintenance & Trust
Max Image Size Control Maintenance & Trust
Maintenance Signals
Community Trust
Max Image Size Control Alternatives
Smart Image Resize – Make WooCommerce Images the Same Size
smart-image-resize
Automatically make WooCommerce product images the same size. Perfect for messy grids, works with existing photos, no cropping.
Sharpen Resized Images
sharpen-resized-images
Do you realize your resized images looks blur? This plugin fixing it. Sharpening resized jpg image uploads in your WordPress.
WPThumb
wp-thumb
An on-demand image generation replacement for WordPress' image resizing.
CropRefine
croprefine
Giving you greater control over how each of your media item sizes are cropped.
Image Hotspot
image-hotspot
Image hotspot helps you control how WordPress generates the various image size in your site.
Max Image Size Control Developer Profile
12 plugins · 43K total installs
How We Detect Max Image Size Control
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/max-image-size-control/js/max-image-size-control.jsHTML / DOM Fingerprints
max-image-size-controlautosaveLast