
Oxyplug Image Security & Risk Analysis
wordpress.org/plugins/oxyplug-imageOxyplug Image is a WordPress.org plugin that optimize your site by compressing your images, creating 1X, 2X, 2.8X and 3x images and more...
Is Oxyplug Image Safe to Use in 2026?
Generally Safe
Score 100/100Oxyplug Image has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "oxyplug-image" v1.0.3 plugin demonstrates several strong security practices, particularly in its handling of SQL queries and output escaping, with high percentages of prepared statements and properly escaped outputs. The absence of known CVEs and a clean vulnerability history are significant strengths, indicating a generally well-maintained and secure plugin. However, the static analysis does reveal potential areas of concern. The presence of one flow with unsanitized paths in the taint analysis, even without critical severity, warrants attention as it could represent a vulnerability if exploited. Furthermore, the complete lack of nonce checks across all identified entry points (AJAX, REST API, shortcodes) is a significant security weakness. While the current attack surface without authentication checks is reported as zero, the absence of nonces on potential AJAX handlers (even if currently none exist) leaves a gap for future development or unforeseen configurations.
Despite these concerns, the plugin's strengths in SQL and output sanitization, coupled with its clean vulnerability history, suggest a generally positive security posture. The most critical takeaway is the need to address the unsanitized path flow and implement nonce checks for any future or existing AJAX/REST API endpoints. The current lack of identified vulnerabilities is reassuring, but proactive security measures, particularly around input validation and authorization for dynamic operations, should be prioritized to maintain this strong record.
Key Concerns
- Flow with unsanitized path detected
- No nonce checks on entry points
Oxyplug Image Security Vulnerabilities
Oxyplug Image Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Oxyplug Image Attack Surface
WordPress Hooks 24
Scheduled Events 2
Maintenance & Trust
Oxyplug Image Maintenance & Trust
Maintenance Signals
Community Trust
Oxyplug Image Alternatives
Oxyplug Preload
oxyplug-preload
Preload featured images to improve the Largest Contentful Paint (LCP) and to get a better Core Web Vital (CWV) score on Google's Lighthouse.
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
WP Performance Score Booster – Optimize Speed, Enable Cache & Page Preload
wp-performance-score-booster
Make website faster, speed up page load time and improve performance scores in tools like Google PageSpeed Insights, GTmetrix, Pingdom, and more.
JCH Optimize
jch-optimize
This plugin automatically performs several front end optimizations to your site to boost performance and increase PageSpeed scores.
Preload LCP Image
preload-lcp-image
Allows you to specify on individual pages or posts the Largest Contentful Paint (LCP) Image on that page to preload, making the page load quicker.
Oxyplug Image Developer Profile
5 plugins · 830 total installs
How We Detect Oxyplug Image
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oxyplug-image/OxyplugImage/App/assets/css/admin.css/wp-content/plugins/oxyplug-image/OxyplugImage/App/assets/js/admin.js/wp-content/plugins/oxyplug-image/OxyplugImage/App/assets/css/public.css/wp-content/plugins/oxyplug-image/OxyplugImage/App/assets/js/public.jsHTML / DOM Fingerprints
oxyplug-image-admin-settingsOxyplug Image
@package OxyplugOxyplug Image
@package Oxyplug Imagedata-oxyplug-image-idOxyplugImage/wp-json/oxyplug-image/api/v1/get-image-data/wp-json/oxyplug-image/api/v1/update-image/wp-json/oxyplug-image/api/v1/delete-image/wp-json/oxyplug-image/api/v1/upload-image/wp-json/oxyplug-image/api/v1/settings/wp-json/oxyplug-image/api/v1/sync-images/wp-json/oxyplug-image/api/v1/get-all-images[oxyplug_image]