
Phototools: media2post Security & Risk Analysis
wordpress.org/plugins/media2postQuickly create a post with the media item as featured image. Single or in batch. Part of the phototools plugins.
Is Phototools: media2post Safe to Use in 2026?
Generally Safe
Score 85/100Phototools: media2post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "media2post" plugin version 1.0 exhibits a generally strong security posture, as indicated by the static analysis. The plugin has a minimal attack surface, consisting of a single AJAX handler, and importantly, this entry point includes a nonce check. The absence of direct SQL queries and file operations further reduces potential risks. Taint analysis did not reveal any critical or high-severity unsanitized flows, suggesting that user-supplied data is likely handled securely within the analyzed code paths. Furthermore, the plugin has no recorded vulnerability history, indicating a track record of secure development and maintenance. The main area for improvement lies in output escaping, where a significant portion of outputs are not properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities. While the current data does not show active XSS vulnerabilities, this lack of robust output sanitization is a concerning weakness.
Key Concerns
- Low output escaping percentage
Phototools: media2post Security Vulnerabilities
Phototools: media2post Code Analysis
Output Escaping
Data Flow Analysis
Phototools: media2post Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
Phototools: media2post Maintenance & Trust
Maintenance Signals
Community Trust
Phototools: media2post Alternatives
Simple Menu Order Column
simple-menu-order-column
Expose menu order column on your dashboard listings.
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
Blog2Social: Social Media Auto Post & Scheduler
blog2social
Automatically share and schedule your WordPress content on top social platforms like Facebook, Instagram, LinkedIn, TikTok, and more.
Crop-Thumbnails
crop-thumbnails
"Crop Thumbnails" made it easy to get exacly that specific image-detail you want to show in your featured image or gallery image.
Reveal IDs
reveal-ids-for-wp-admin-25
What this plugin does is to reveal most removed IDs on admin pages, as it was in versions prior to 2.5.
Phototools: media2post Developer Profile
7 plugins · 50 total installs
How We Detect Phototools: media2post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media2post/media2post.css/wp-content/plugins/media2post/media2post.js/wp-content/plugins/media2post/media2post.jsmedia2post/media2post.css?ver=media2post/media2post.js?ver=HTML / DOM Fingerprints
data-post-idmedia2post