
Media Picker for Immich Security & Risk Analysis
wordpress.org/plugins/media-picker-for-immichUse photos and videos from your Immich server in WordPress without copying files, or import them into the media library.
Is Media Picker for Immich Safe to Use in 2026?
Generally Safe
Score 100/100Media Picker for Immich has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The media-picker-for-immich plugin, version 0.1.0, exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in other areas, such as 100% prepared SQL statements and a high percentage of properly escaped output, the presence of 7 AJAX handlers without any authentication or capability checks presents a substantial attack surface. This means any user, regardless of their WordPress role, could potentially trigger these actions. The taint analysis, while not revealing critical or high-severity issues, did find 4 flows with unsanitized paths, which is a red flag even if no immediate critical exploit was identified. The lack of any recorded vulnerabilities in its history might suggest it hasn't been widely targeted or has been fortunate, rather than inherently secure, especially given the identified code weaknesses. Overall, the plugin has strengths in its handling of database queries and output escaping, but the unprotected AJAX endpoints are a critical weakness that demands immediate attention.
Key Concerns
- 7 AJAX handlers without auth checks
- 4 flows with unsanitized paths
Media Picker for Immich Security Vulnerabilities
Media Picker for Immich Release Timeline
Media Picker for Immich Code Analysis
Output Escaping
Data Flow Analysis
Media Picker for Immich Attack Surface
AJAX Handlers 7
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
Media Picker for Immich Maintenance & Trust
Maintenance Signals
Community Trust
Media Picker for Immich Alternatives
Gallery for Immich
gallery-for-immich
Display your Immich photo albums and galleries in WordPress using simple shortcodes.
WPJaipho Mobile Gallery
wpjaipho
WPJaipho extends native Wordpress image gallery, NextGEN 1.x and NextCellent Gallery with optimized support for mobile users
Photalika
photalika
Seamlessly integrate your WordPress website with Photalika, a powerful cloud platform for managing, storing, and showcasing your photos and media.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
Media Picker for Immich Developer Profile
13 plugins · 32K total installs
How We Detect Media Picker for Immich
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-picker-for-immich/build/index.css/wp-content/plugins/media-picker-for-immich/build/index.js/wp-content/plugins/media-picker-for-immich/build/immich-assets.js/wp-content/plugins/media-picker-for-immich/build/index.js/wp-content/plugins/media-picker-for-immich/build/immich-assets.jsmedia-picker-for-immich/build/index.css?ver=media-picker-for-immich/build/index.js?ver=media-picker-for-immich/build/immich-assets.js?ver=HTML / DOM Fingerprints
immich-media-picker-wrapperdata-immich-api-keydata-immich-api-urldata-immich-media-picker-optionsimmichMediaPickerConfigimmichAssets/wp-json/immich/v1/browse/wp-json/immich/v1/search/wp-json/immich/v1/people/wp-json/immich/v1/thumbnail/wp-json/immich/v1/import/wp-json/immich/v1/use/wp-json/immich/v1/used_assets