Media Library Helper — Bulk edit image ALT, caption & description Security & Risk Analysis

wordpress.org/plugins/media-library-helper

Add or edit or bulk edit image ALT tag, caption & description with one click straight from the WordPress media library to improve your SEO score.

10K active installs v1.3.2 PHP 5.6.39+ WP 4.8+ Updated Dec 3, 2025
alt-tagbulk-editimage-captionmedia-libraryseo
100
A · Safe
CVEs total1
Unpatched0
Last CVEJul 5, 2023
Safety Verdict

Is Media Library Helper — Bulk edit image ALT, caption & description Safe to Use in 2026?

Generally Safe

Score 100/100

Media Library Helper — Bulk edit image ALT, caption & description has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jul 5, 2023Updated 4mo ago
Risk Assessment

The media-library-helper plugin v1.3.2 exhibits a generally good security posture based on the static analysis provided. The absence of any identified attack surface entry points like AJAX handlers, REST API routes, or shortcodes, and the strong presence of nonce and capability checks, indicate a proactive approach to securing these common plugin vulnerabilities. The high percentage of properly escaped output further reinforces this positive assessment. However, a single SQL query that is not prepared, while not critical on its own, represents a potential weakness. The vulnerability history reveals one medium-severity CVE related to CSRF, which was patched. This suggests that while the plugin has had a past vulnerability, it was addressed, and there are no currently unpatched issues. The overall risk is low, but the unresolved SQL query warrants attention for future development to maintain a robust security profile.

Key Concerns

  • SQL queries not using prepared statements
Vulnerabilities
1

Media Library Helper — Bulk edit image ALT, caption & description Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-37386medium · 4.3Cross-Site Request Forgery (CSRF)

Media Library Helper by Codexin <= 1.2.0 - Cross-Site Request Forgery via rate_the_plugin_action

Jul 5, 2023 Patched in 1.3.0 (202d)
Code Analysis
Analyzed Mar 16, 2026

Media Library Helper — Bulk edit image ALT, caption & description Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
2
35 escaped
Nonce Checks
2
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

95% escaped37 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<extended-upload> (templates\extended-upload.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Media Library Helper — Bulk edit image ALT, caption & description Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Media Library Helper — Bulk edit image ALT, caption & description Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 3, 2025
PHP min version5.6.39
Downloads150K

Community Trust

Rating98/100
Number of ratings55
Active installs10K
Developer Profile

Media Library Helper — Bulk edit image ALT, caption & description Developer Profile

Codexin Technologies

2 plugins · 10K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
202 days
View full developer profile
Detection Fingerprints

How We Detect Media Library Helper — Bulk edit image ALT, caption & description

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/media-library-helper/assets/css/admin.css/wp-content/plugins/media-library-helper/assets/js/admin.js
Script Paths
/wp-content/plugins/media-library-helper/assets/js/admin.js
Version Parameters
media-library-helper/assets/css/admin.css?ver=media-library-helper/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
cdxn-mlh-btncdxn-mlh-btn-primarycdxn-mlh-btn-secondarycdxn-mlh-btn-danger
Data Attributes
data-cdxn-mlh-plugin-url
JS Globals
CDXN_MLH_PREFIXCDXN_MLH_FILECDXN_MLH_PATH
FAQ

Frequently Asked Questions about Media Library Helper — Bulk edit image ALT, caption & description