
My Upload Images Security & Risk Analysis
wordpress.org/plugins/my-upload-imagesCreate metabox with media uploader. It allows to upload and sort images in any post_type.
Is My Upload Images Safe to Use in 2026?
Generally Safe
Score 85/100My Upload Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "my-upload-images" v1.4.1 exhibits a generally strong security posture based on the static analysis. The absence of identified attack surface points like unprotected AJAX handlers, REST API routes, shortcodes, or cron events is a significant positive. Furthermore, the code adheres to good practices regarding SQL queries, utilizing prepared statements exclusively, and the presence of nonce and capability checks indicates an effort to secure critical operations. Taint analysis also shows no critical or high severity unsanitized flows, which is reassuring.
However, a notable concern arises from the output escaping. With only 15% of the 27 identified outputs being properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While no specific XSS vulnerabilities were flagged in the taint analysis, this high percentage of unescaped output represents a substantial potential attack vector that could be exploited if user-supplied data is not handled carefully in the remaining outputs. The lack of any recorded vulnerabilities in its history is positive, suggesting a history of stable security, but this should not overshadow the identified output escaping issues.
In conclusion, while the plugin has strengths in its limited attack surface and secure data handling for SQL, the widespread issue with output escaping presents a tangible risk that requires immediate attention. Addressing these unescaped outputs is crucial to prevent potential XSS attacks, even in the absence of historical vulnerability reports.
Key Concerns
- Low percentage of properly escaped output (15%)
My Upload Images Security Vulnerabilities
My Upload Images Code Analysis
Output Escaping
Data Flow Analysis
My Upload Images Attack Surface
WordPress Hooks 7
Maintenance & Trust
My Upload Images Maintenance & Trust
Maintenance Signals
Community Trust
My Upload Images Alternatives
Image Uploader for Welcart
image-uploader-for-welcart
Create metabox with image uploader for ‘Welcart e-Commerce’. It allows user to upload and sort images directory from each edit page.
Delete Unscaled Images
delete-unscaled-images
Deletes original image files if they have been resized
QBank Connector
qbank-dam-connector
Gain access to all your files in QBank that you can publish directly from Wordpress without leaving their interface.
Image Photoroll Creator For Photographers
image-photoroll-creator-for-photographers
Plugin adds aditional buttons to media upload module allowing of faster images edit and add to post.
Additional Featured Images and Media Uploader Anywhere
additional-featured-images-and-media-uploader-anywhere
Add additional featured images to any post type and display using either a built in image gallery/slideshow shortcode or by using a single image short …
My Upload Images Developer Profile
2 plugins · 3K total installs
How We Detect My Upload Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-upload-images/css/mui-style.css/wp-content/plugins/my-upload-images/js/mui-script.js/wp-content/plugins/my-upload-images/js/mui-script.jsmy-upload-images/css/mui-style.css?ver=my-upload-images/js/mui-script.js?ver=HTML / DOM Fingerprints
id="mui_images"mui_options