Multi Image Metabox Security & Risk Analysis

wordpress.org/plugins/multi-image-metabox

Add a multi-image metabox to your posts, pages and custom post types

7K active installs v1.3.5 PHP + WP 3.0+ Updated Nov 28, 2017
imagesmetaboxmultiplemultiple-post-thumbnailpictures
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Multi Image Metabox Safe to Use in 2026?

Generally Safe

Score 85/100

Multi Image Metabox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "multi-image-metabox" plugin v1.3.5 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface, and importantly, all identified entry points are protected. The code also demonstrates a strong commitment to secure practices by utilizing prepared statements for all SQL queries and including a nonce check. There are no recorded vulnerabilities (CVEs) for this plugin, which is a positive indicator of its development quality and ongoing maintenance.

However, there are areas for improvement that prevent a perfect security score. The most notable concern is the low percentage of properly escaped output (25%). This suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data or dynamic content is outputted without adequate sanitization. While no taint flows with unsanitized paths were identified in this specific analysis, the lack of comprehensive output escaping remains a critical weakness. Furthermore, the complete absence of capability checks is concerning, as it implies that any user, regardless of their WordPress role, could potentially interact with any part of the plugin's functionality if an entry point were discovered. This, combined with the potential for XSS, creates a risk that could be amplified.

In conclusion, the plugin has a strong foundation with a minimal attack surface and secure SQL handling. The lack of vulnerability history is encouraging. Nevertheless, the poor output escaping practices and the absence of capability checks are significant security weaknesses that require immediate attention. Addressing these issues would greatly enhance the plugin's overall security.

Key Concerns

  • Low output escaping rate
  • No capability checks implemented
Vulnerabilities
None known

Multi Image Metabox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Multi Image Metabox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
1 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped4 total outputs
Attack Surface

Multi Image Metabox Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_initmulti-image-metabox.php:41
actionsave_postmulti-image-metabox.php:51
Maintenance & Trust

Multi Image Metabox Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedNov 28, 2017
PHP min version
Downloads20K

Community Trust

Rating98/100
Number of ratings11
Active installs7K
Developer Profile

Multi Image Metabox Developer Profile

Willy Bahuaud

8 plugins · 9K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Multi Image Metabox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/multi-image-metabox/get-images.js
Script Paths
/wp-content/plugins/multi-image-metabox/get-images.js

HTML / DOM Fingerprints

CSS Classes
image-entryimg-previewget-imagedel-imageid_img
HTML Comments
<!-- ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥ ♥5. GLOBALS ↓HOOK FILTER+6 more
Data Attributes
data-num
FAQ

Frequently Asked Questions about Multi Image Metabox