TIO – The Image Optimizer – Smart Image Compression & Optimization, Built for the Web Security & Risk Analysis

wordpress.org/plugins/nerdcow-the-image-optimizer

Automatically compress and convert your images to modern formats (WebP, AVIF). Get a perfectly optimized image every time and speed up your website.

0 active installs v1.0.0 PHP 8.0+ WP 6.0+ Updated Mar 19, 2026
avifcompressionimage-optimizationmediawebp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TIO – The Image Optimizer – Smart Image Compression & Optimization, Built for the Web Safe to Use in 2026?

Generally Safe

Score 100/100

TIO – The Image Optimizer – Smart Image Compression & Optimization, Built for the Web has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "nerdcow-the-image-optimizer" plugin version 1.0.0 exhibits a generally strong security posture based on the provided static analysis. All identified AJAX entry points include nonce and capability checks, indicating good practice in preventing unauthorized access and cross-site request forgery. The plugin also demonstrates a commitment to secure database interactions, with 100% of SQL queries utilizing prepared statements, significantly reducing the risk of SQL injection. Furthermore, output escaping is nearly perfect, with 99% of outputs properly escaped, mitigating potential cross-site scripting vulnerabilities.

However, two flows with unsanitized paths were identified during taint analysis. While no critical or high severity issues were flagged by the taint analysis, these unsanitized paths represent a potential concern, as they could lead to directory traversal or other file system manipulation vulnerabilities if not handled with extreme care. The plugin's history of zero known CVEs is a positive indicator, suggesting a well-maintained codebase. Nonetheless, the presence of unsanitized paths, even without immediate critical severity, warrants attention and careful review.

In conclusion, the plugin has a strong foundation in secure coding practices, particularly concerning AJAX security, SQL injection prevention, and output escaping. The primary area of concern lies within the two identified unsanitized path flows, which, while not currently classified as critical, should be investigated and remediated to ensure the plugin's robust security. The absence of historical vulnerabilities is a significant strength, but the identified path issues mean vigilance is still required.

Key Concerns

  • Flows with unsanitized paths found
Vulnerabilities
None known

TIO – The Image Optimizer – Smart Image Compression & Optimization, Built for the Web Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TIO – The Image Optimizer – Smart Image Compression & Optimization, Built for the Web Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

TIO – The Image Optimizer – Smart Image Compression & Optimization, Built for the Web Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
91 escaped
Nonce Checks
7
Capability Checks
9
File Operations
4
External Requests
6
Bundled Libraries
0

Output Escaping

99% escaped92 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
nctio_ajax_activate_site (includes/admin-settings.php:478)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

TIO – The Image Optimizer – Smart Image Compression & Optimization, Built for the Web Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 7

authwp_ajax_nctio_test_connectionincludes/admin-settings.php:353
authwp_ajax_nctio_dismiss_low_creditincludes/admin-settings.php:461
authwp_ajax_nctio_activate_siteincludes/admin-settings.php:477
authwp_ajax_nctio_disconnect_siteincludes/admin-settings.php:514
authwp_ajax_nctio_save_auto_compressincludes/admin-settings.php:529
authwp_ajax_nctio_refundincludes/admin-settings.php:545
authwp_ajax_nctio_refund_infoincludes/admin-settings.php:637
WordPress Hooks 20
actionadmin_bar_menuincludes/admin-bar.php:19
actionadmin_enqueue_scriptsincludes/admin-bar.php:51
actionwp_enqueue_scriptsincludes/admin-bar.php:52
actionadmin_enqueue_scriptsincludes/admin-settings.php:16
actionadmin_enqueue_scriptsincludes/admin-settings.php:70
actionadmin_menuincludes/admin-settings.php:113
actionadmin_noticesincludes/admin-settings.php:384
actionadmin_noticesincludes/admin-settings.php:416
actionadmin_enqueue_scriptsincludes/admin-settings.php:703
actionenqueue_block_editor_assetsincludes/admin-settings.php:742
filterattachment_fields_to_editincludes/attachment-stats.php:100
filtermanage_media_columnsincludes/attachment-stats.php:172
actionmanage_media_custom_columnincludes/attachment-stats.php:184
filterwp_handle_uploadincludes/compress.php:283
filterbig_image_size_thresholdincludes/compress.php:294
filterwp_generate_attachment_metadataincludes/compress.php:313
actionshutdownincludes/compress.php:327
actionadd_attachmentincludes/compress.php:341
actionadmin_noticesincludes/compress.php:363
actionadmin_noticesnerdcow-the-image-optimizer.php:90
Maintenance & Trust

TIO – The Image Optimizer – Smart Image Compression & Optimization, Built for the Web Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 19, 2026
PHP min version8.0
Downloads180

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TIO – The Image Optimizer – Smart Image Compression & Optimization, Built for the Web Developer Profile

NerdCow

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TIO – The Image Optimizer – Smart Image Compression & Optimization, Built for the Web

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nerdcow-the-image-optimizer/assets/css/nctio-admin.css/wp-content/plugins/nerdcow-the-image-optimizer/assets/js/nctio-admin.js
Script Paths
/wp-content/plugins/nerdcow-the-image-optimizer/assets/js/nctio-admin.js
Version Parameters
nerdcow-the-image-optimizer/assets/css/nctio-admin.css?ver=nerdcow-the-image-optimizer/assets/js/nctio-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
nctio-credits-low
Data Attributes
data-nonce
JS Globals
nctioAdmin
FAQ

Frequently Asked Questions about TIO – The Image Optimizer – Smart Image Compression & Optimization, Built for the Web