
My Eyes Are Up Here Security & Risk Analysis
wordpress.org/plugins/my-eyes-are-up-hereMy Eyes Are Up Here helps you control how WordPress generates thumbnails.
Is My Eyes Are Up Here Safe to Use in 2026?
Generally Safe
Score 85/100My Eyes Are Up Here has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'my-eyes-are-up-here' plugin version 1.1.11 exhibits a strong security posture based on static analysis, with no detected attack surface points, dangerous functions, or unsanitized SQL queries. All observed output is properly escaped, and file operations, while present, are not flagged as inherently risky. The absence of external HTTP requests and the presence of nonce checks are positive indicators of secure coding practices.
However, a notable concern arises from the taint analysis, which identified two flows with unsanitized paths. While these are not classified as critical or high severity, any unsanitized path, even if not currently exploitable, represents a potential weakness that could be leveraged by attackers in the future or if other plugin/WordPress core functionalities change. The lack of capability checks on entry points is also a potential area for improvement, though in this specific case, with zero entry points, it does not immediately translate to a direct risk. The plugin's vulnerability history is clean, with no recorded CVEs, which is excellent, but this does not negate the risks identified in the static analysis.
In conclusion, the plugin demonstrates good security fundamentals by adhering to practices like prepared statements and output escaping. The primary area for improvement lies in addressing the identified unsanitized path flows to further harden the plugin against potential future vulnerabilities. The clean vulnerability history is a significant strength, suggesting a proactive approach to security by the developers so far.
Key Concerns
- Flows with unsanitized paths
- File operations detected
- Capability checks are zero
My Eyes Are Up Here Security Vulnerabilities
My Eyes Are Up Here Code Analysis
Output Escaping
Data Flow Analysis
My Eyes Are Up Here Attack Surface
WordPress Hooks 6
Maintenance & Trust
My Eyes Are Up Here Maintenance & Trust
Maintenance Signals
Community Trust
My Eyes Are Up Here Alternatives
Auto Featured Image (Auto Post Thumbnail)
auto-post-thumbnail
Automatically generate, assign, and manage featured images in bulk so every post on your site has a featured image.
Quick Featured Images
quick-featured-images
The time-saving solution for managing tons of featured images within minutes: Set, replace and delete in bulk and set default images for future posts.
Multiple Post Thumbnails
multiple-post-thumbnails
Adds multiple post thumbnails to a post type. If you've ever wanted more than one Featured Image on a post, this plugin is for you.
Easy Add Thumbnail
easy-add-thumbnail
Automatically sets the featured image to the first image uploaded into the post (any post type with thumbnail support). So easy like that...
Acme Fix Images – Regenerate Thumbnails
acme-fix-images
Fix image sizes after you have changed image sizes from Media Settings. Ensure your images display consistently across your website.
My Eyes Are Up Here Developer Profile
4 plugins · 4K total installs
How We Detect My Eyes Are Up Here
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-eyes-are-up-here/assets/js/scripts.min.js/wp-content/plugins/my-eyes-are-up-here/assets/css/main.min.css/wp-content/plugins/my-eyes-are-up-here/assets/js/scripts.min.jsmy-eyes-are-up-here/assets/js/scripts.min.js?ver=my-eyes-are-up-here/assets/css/main.min.css?ver=HTML / DOM Fingerprints
meauh/wp-json/meauh/v1/get_image/wp-json/meauh/v1/save_image