Next Watermark Security & Risk Analysis

wordpress.org/plugins/next-watermark

Next Watermark helps you easily add automatically text or/and image watermarks on your images (GIF, JPEG, PNG and WEBP formats supported)! Backup/rest …

300 active installs v1.8 PHP 7.3+ WP 5.3+ Updated May 15, 2025
copyrightimagephotopicturewatermark
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Next Watermark Safe to Use in 2026?

Generally Safe

Score 100/100

Next Watermark has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "next-watermark" plugin version 1.8 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs and a clean taint analysis indicate a history of responsible development and a lack of known critical vulnerabilities. The code adheres to good security practices by exclusively using prepared statements for SQL queries and implementing nonce and capability checks, though the limited number of these checks suggests a potentially small attack surface or limited functionality that interacts with WordPress security features. The high rate of properly escaped output (82%) is a positive indicator, though the remaining 18% could still pose a risk depending on the context of the unescaped data.

While the plugin's current state appears secure, the lack of any identified entry points (AJAX, REST API, shortcodes, cron events) in the static analysis is unusual and might suggest the plugin has very limited functionality or relies on other mechanisms for user interaction. The presence of file operations without further context is a potential area to monitor, as it could be a vector for vulnerabilities if not handled carefully. Overall, the plugin is in a good state, with strengths in its lack of historical vulnerabilities and adherence to fundamental security practices. The primary areas for cautious observation are the unescaped outputs and the potential implications of the file operations.

Key Concerns

  • Some output not properly escaped
Vulnerabilities
None known

Next Watermark Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Next Watermark Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
81 escaped
Nonce Checks
1
Capability Checks
1
File Operations
10
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped99 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<nwm-acp-page> (includes\nwm-acp-page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Next Watermark Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_enqueue_scriptsincludes\nwm-functions.php:58
actionplugins_loadedincludes\nwm-functions.php:70
actionadmin_menuincludes\nwm-functions.php:88
actionadmin_initincludes\nwm-functions.php:104
actioninitincludes\nwm-functions.php:107
actionadmin_enqueue_scriptsincludes\nwm-functions.php:279
actionadmin_noticesincludes\nwm-functions.php:286
actionadmin_noticesincludes\nwm-functions.php:312
actionwp_footerincludes\nwm-functions.php:340
filterajax_query_attachments_argsincludes\nwm-functions.php:373
filterwp_generate_attachment_metadataincludes\nwm-functions.php:375
Maintenance & Trust

Next Watermark Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 15, 2025
PHP min version7.3
Downloads9K

Community Trust

Rating68/100
Number of ratings11
Active installs300
Developer Profile

Next Watermark Developer Profile

nxtweb

8 plugins · 320 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Next Watermark

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/next-watermark/css/style.css
Version Parameters
next-watermark/css/style.css?ver=

HTML / DOM Fingerprints

HTML Comments
Copyright 2023 F.Leroux
FAQ

Frequently Asked Questions about Next Watermark