NutsForPress Images and Media Security & Risk Analysis

wordpress.org/plugins/nutsforpress

NutsForPress Images and Media is an essential tool for having your images and your meta in perfect order.

30 active installs v1.7 PHP 7.0.0+ WP 5.3+ Updated Dec 6, 2025
imagenutsforpressrebuildresizethumbnail
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NutsForPress Images and Media Safe to Use in 2026?

Generally Safe

Score 100/100

NutsForPress Images and Media has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "nutsforpress" v1.7 plugin exhibits a generally good security posture with several positive indicators. The absence of dangerous functions, file operations, external HTTP requests, and the near-perfect output escaping (99%) suggest developers are adhering to secure coding practices. The plugin also demonstrates a commitment to security by including nonce checks and capability checks on its entry points, and 100% of its SQL queries utilize prepared statements, mitigating common database vulnerabilities.

However, a significant concern arises from the presence of two AJAX handlers that lack authentication checks. This creates a direct attack surface where unauthenticated users could potentially trigger these handlers, leading to unintended actions or information disclosure if the underlying logic is vulnerable. While the taint analysis did not reveal any unsanitized paths, the unprotected AJAX endpoints represent a potential gap that could be exploited. The plugin's clean vulnerability history is a positive sign, indicating a track record of security, but it does not negate the immediate risks presented by the unprotected AJAX handlers.

In conclusion, "nutsforpress" v1.7 is largely well-coded from a security perspective, but the two unprotected AJAX entry points introduce a notable risk. Addressing these unprotected handlers is crucial to further strengthen the plugin's security. The developers' adherence to prepared statements and output escaping is commendable, and the clean vulnerability history is reassuring.

Key Concerns

  • Unprotected AJAX handlers
  • Missing capability checks on AJAX
Vulnerabilities
None known

NutsForPress Images and Media Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

NutsForPress Images and Media Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
163 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped164 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
nfproot_save_settings (root\nfproot-save-settings.php:71)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

NutsForPress Images and Media Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_nfproot_save_settingsnuts-for-press-images-and-media.php:35
authwp_ajax_nfpmgm_thumbnails_rebuildnuts-for-press-images-and-media.php:79
WordPress Hooks 19
filterjpeg_qualityadmin\includes\nfpmgm-quality-actions.php:34
filterjpeg_qualityadmin\includes\nfpmgm-quality-actions.php:39
filterbig_image_size_thresholdadmin\includes\nfpmgm-size-actions-on-delete.php:19
filterbig_image_size_thresholdadmin\includes\nfpmgm-size-actions-on-delete.php:38
filterbig_image_size_thresholdadmin\includes\nfpmgm-size-actions.php:27
filterbig_image_size_thresholdadmin\includes\nfpmgm-size-actions.php:46
filterjpeg_qualityadmin\includes\nfpmgm-thumbnails-rebuild.php:112
filterjpeg_qualityadmin\includes\nfpmgm-thumbnails-rebuild.php:115
filterbig_image_size_thresholdadmin\includes\nfpmgm-thumbnails-rebuild.php:118
filterbig_image_size_thresholdadmin\includes\nfpmgm-thumbnails-rebuild.php:121
actionadmin_menunuts-for-press-images-and-media.php:31
actionplugins_loadednuts-for-press-images-and-media.php:39
actionadmin_enqueue_scriptsnuts-for-press-images-and-media.php:43
actionadmin_enqueue_scriptsnuts-for-press-images-and-media.php:65
actionadmin_menunuts-for-press-images-and-media.php:72
actionadd_attachmentnuts-for-press-images-and-media.php:83
actiondelete_attachmentnuts-for-press-images-and-media.php:87
actionadd_attachmentnuts-for-press-images-and-media.php:91
actionwpml_media_create_duplicate_attachmentnuts-for-press-images-and-media.php:95
Maintenance & Trust

NutsForPress Images and Media Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 6, 2025
PHP min version7.0.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

NutsForPress Images and Media Developer Profile

Christian Gatti

9 plugins · 460 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NutsForPress Images and Media

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nutsforpress/root/css/nfproot-style.css/wp-content/plugins/nutsforpress/root/js/nfproot-script.js/wp-content/plugins/nutsforpress/root/js/nfproot-save-settings.js/wp-content/plugins/nutsforpress/admin/includes/js/nfpmgm-thumbnails-rebuild.js
Script Paths
/wp-content/plugins/nutsforpress/root/js/nfproot-script.js/wp-content/plugins/nutsforpress/root/js/nfproot-save-settings.js/wp-content/plugins/nutsforpress/admin/includes/js/nfpmgm-thumbnails-rebuild.js

HTML / DOM Fingerprints

HTML Comments
<!--if this file is called directly, die.--><!--if this file is called directly, abort.--><!--NUTSFORPRESS ROOT CONTENT--><!--PLUGIN INCLUDES-->+2 more
JS Globals
nfpmgm_thumbnails_rebuild_objectnfproot_save_settings_object
FAQ

Frequently Asked Questions about NutsForPress Images and Media