My Eyes Are Up Here Security & Risk Analysis

wordpress.org/plugins/my-eyes-are-up-here

My Eyes Are Up Here helps you control how WordPress generates thumbnails.

3K active installs v1.1.11 PHP + WP 3.8.1+ Updated Sep 29, 2022
featured-imageimageimage-editingthumbnails
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is My Eyes Are Up Here Safe to Use in 2026?

Generally Safe

Score 85/100

My Eyes Are Up Here has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'my-eyes-are-up-here' plugin version 1.1.11 exhibits a strong security posture based on static analysis, with no detected attack surface points, dangerous functions, or unsanitized SQL queries. All observed output is properly escaped, and file operations, while present, are not flagged as inherently risky. The absence of external HTTP requests and the presence of nonce checks are positive indicators of secure coding practices.

However, a notable concern arises from the taint analysis, which identified two flows with unsanitized paths. While these are not classified as critical or high severity, any unsanitized path, even if not currently exploitable, represents a potential weakness that could be leveraged by attackers in the future or if other plugin/WordPress core functionalities change. The lack of capability checks on entry points is also a potential area for improvement, though in this specific case, with zero entry points, it does not immediately translate to a direct risk. The plugin's vulnerability history is clean, with no recorded CVEs, which is excellent, but this does not negate the risks identified in the static analysis.

In conclusion, the plugin demonstrates good security fundamentals by adhering to practices like prepared statements and output escaping. The primary area for improvement lies in addressing the identified unsanitized path flows to further harden the plugin against potential future vulnerabilities. The clean vulnerability history is a significant strength, suggesting a proactive approach to security by the developers so far.

Key Concerns

  • Flows with unsanitized paths
  • File operations detected
  • Capability checks are zero
Vulnerabilities
None known

My Eyes Are Up Here Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

My Eyes Are Up Here Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
2
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
save_image (includes\class-meauh-ajax.php:67)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

My Eyes Are Up Here Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_enqueue_scriptsincludes\class-meauh-admin.php:23
filterget_attached_fileincludes\class-meauh-attachment.php:38
filterupdate_attached_fileincludes\class-meauh-attachment.php:39
filterimage_resize_dimensionsincludes\class-meauh-attachment.php:42
filterattachment_fields_to_editincludes\class-meauh-attachment.php:45
actioninitmy-eyes-are-up-here.php:125
Maintenance & Trust

My Eyes Are Up Here Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 29, 2022
PHP min version
Downloads174K

Community Trust

Rating100/100
Number of ratings32
Active installs3K
Developer Profile

My Eyes Are Up Here Developer Profile

interconnectit

4 plugins · 4K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect My Eyes Are Up Here

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/my-eyes-are-up-here/assets/js/scripts.min.js/wp-content/plugins/my-eyes-are-up-here/assets/css/main.min.css
Script Paths
/wp-content/plugins/my-eyes-are-up-here/assets/js/scripts.min.js
Version Parameters
my-eyes-are-up-here/assets/js/scripts.min.js?ver=my-eyes-are-up-here/assets/css/main.min.css?ver=

HTML / DOM Fingerprints

JS Globals
meauh
REST Endpoints
/wp-json/meauh/v1/get_image/wp-json/meauh/v1/save_image
FAQ

Frequently Asked Questions about My Eyes Are Up Here