Media Item URL Security & Risk Analysis

wordpress.org/plugins/media-item-url

Get the full attachment URL from the media row table without opening item.

100 active installs v1.0.1 PHP + WP 3.8+ Updated Aug 16, 2016
imagesmedia-gallery
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Media Item URL Safe to Use in 2026?

Generally Safe

Score 85/100

Media Item URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "media-item-url" plugin v1.0.1 exhibits a strong security posture. The code analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. Furthermore, there are no file operations or external HTTP requests, indicating a contained and safe implementation in these critical areas. The absence of any recorded CVEs, either past or present, is a significant positive indicator. The plugin also demonstrates a minimal attack surface with zero entry points identified, which is ideal from a security perspective.

However, the complete lack of nonces and capability checks, while not presenting an immediate risk in this specific analysis due to the zero attack surface, represents a potential weakness. If the plugin were to introduce any entry points in future versions, the absence of these fundamental security checks could become a significant concern. The data suggests the developers have followed good security practices for the current version.

In conclusion, the "media-item-url" plugin v1.0.1 appears to be very secure in its current state. The lack of vulnerabilities and robust coding practices like prepared statements and output escaping are commendable. The primary area for potential improvement and future consideration would be the implementation of nonces and capability checks should the attack surface expand.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Media Item URL Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Media Item URL Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Media Item URL Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedmedia-item-url.php:42
actionadmin_headmedia-item-url.php:43
actionadmin_enqueue_scriptsmedia-item-url.php:44
filtermedia_row_actionsmedia-item-url.php:45
Maintenance & Trust

Media Item URL Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.0
Last updatedAug 16, 2016
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings10
Active installs100
Developer Profile

Media Item URL Developer Profile

Andrew Norcross

18 plugins · 2K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Media Item URL

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/media-item-url/lib/js/rkvmr.admin.js/wp-content/plugins/media-item-url/lib/js/rkvmr.admin.min.js
Script Paths
/wp-content/plugins/media-item-url/lib/js/rkvmr.admin.js/wp-content/plugins/media-item-url/lib/js/rkvmr.admin.min.js
Version Parameters
media-item-url/lib/js/rkvmr.admin.js?ver=media-item-url/lib/js/rkvmr.admin.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
media-url-clickmedia-url-openmedia-url-boxmedia-url-field
Shortcode Output
<a class="media-url-click" href="#"><div class="media-url-box"><input type="url" class="widefat media-url-field" value="
FAQ

Frequently Asked Questions about Media Item URL