Optimus – WordPress Image Optimizer Security & Risk Analysis

wordpress.org/plugins/optimus

Effective image compression and optimization during the upload process. Smart, automatic and reliable.

30K active installs v1.6.3 PHP 5.6+ WP 4.6+ Updated Mar 2, 2026
image-optimizerimagesoptimize-imagewebpwordpress-image-optimizer
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Optimus – WordPress Image Optimizer Safe to Use in 2026?

Generally Safe

Score 100/100

Optimus – WordPress Image Optimizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'optimus' v1.6.3 exhibits a mixed security posture. On the positive side, the code demonstrates good practices regarding SQL query handling, exclusively utilizing prepared statements, and includes a reasonable number of nonce and capability checks. The absence of known CVEs and recorded vulnerabilities is a strong indicator of historical security diligence and a generally well-maintained codebase.

However, a significant concern arises from the attack surface analysis, which reveals one unprotected AJAX handler. This represents a direct entry point for potential malicious interaction without proper authentication or authorization, increasing the risk of unauthorized actions or information disclosure. While the taint analysis shows no unsanitized paths, the existence of an unprotected AJAX endpoint alone creates a significant security gap that needs to be addressed. The low percentage of properly escaped output also suggests a potential for cross-site scripting (XSS) vulnerabilities, although the taint analysis did not flag any specific issues in this regard.

In conclusion, 'optimus' v1.6.3 has a generally robust security foundation, particularly in its database interactions and historical vulnerability record. Nevertheless, the single unprotected AJAX handler is a critical weakness that elevates the overall risk. Addressing this unprotected entry point should be the highest priority to improve the plugin's security significantly. The low output escaping rate also warrants further investigation to prevent potential XSS issues.

Key Concerns

  • Unprotected AJAX handler detected
  • Low percentage of properly escaped output
Vulnerabilities
None known

Optimus – WordPress Image Optimizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Optimus – WordPress Image Optimizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
20
2 escaped
Nonce Checks
4
Capability Checks
5
File Operations
4
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

9% escaped22 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
optimize_image (inc\optimus_request.class.php:36)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Optimus – WordPress Image Optimizer Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_optimus_optimize_imageoptimus.php:50
WordPress Hooks 17
filterwp_delete_fileinc\optimus.class.php:44
actionwr2x_retina_file_addedinc\optimus.class.php:53
actionadmin_enqueue_scriptsinc\optimus.class.php:74
filtermanage_media_columnsinc\optimus.class.php:81
actionmanage_media_custom_columninc\optimus.class.php:88
filterplugin_row_metainc\optimus.class.php:97
actionadmin_initinc\optimus.class.php:120
actionadmin_initinc\optimus.class.php:127
actionadmin_menuinc\optimus.class.php:135
actionadmin_menuinc\optimus.class.php:142
actionall_admin_noticesinc\optimus.class.php:151
actionall_admin_noticesinc\optimus.class.php:158
actioninitoptimus.php:44
actionadmin_action_optimus_bulk_optimizeroptimus.php:57
actionplugins_loadedoptimus.php:70
actioninitoptimus.php:83
actionwp_generate_attachment_metadataoptimus.php:119
Maintenance & Trust

Optimus – WordPress Image Optimizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 2, 2026
PHP min version5.6
Downloads694K

Community Trust

Rating84/100
Number of ratings68
Active installs30K
Developer Profile

Optimus – WordPress Image Optimizer Developer Profile

KeyCDN

3 plugins · 140K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Optimus – WordPress Image Optimizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/optimus/css/optimus.css/wp-content/plugins/optimus/js/optimus.js/wp-content/plugins/optimus/js/optimus-admin.js
Script Paths
/wp-content/plugins/optimus/js/optimus.js/wp-content/plugins/optimus/js/optimus-admin.js
Version Parameters
/wp-content/plugins/optimus/css/optimus.css?ver=/wp-content/plugins/optimus/js/optimus.js?ver=/wp-content/plugins/optimus/js/optimus-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
optimus-bulk-optimizer-wrap
HTML Comments
<!-- optimus_admin_notice -->
Data Attributes
data-optimus-bulk-optimizer
JS Globals
optimusoptimus_adminoptimus_bulk_optimizer
FAQ

Frequently Asked Questions about Optimus – WordPress Image Optimizer