
PhotoPress – Image Taxonomies Security & Risk Analysis
wordpress.org/plugins/photo-tools-image-taxonomiesThis plugin extracts EXIF and XMP meta-data of uploaded images for use in populating a variety of photo specific taxonomies.
Is PhotoPress – Image Taxonomies Safe to Use in 2026?
Generally Safe
Score 85/100PhotoPress – Image Taxonomies has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'photo-tools-image-taxonomies' version 1.9.8 presents a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and all its SQL queries are properly prepared, indicating good database security practices. Furthermore, the attack surface is relatively small, with only one shortcode and no AJAX handlers or REST API routes that are accessible without authentication. There are also no external HTTP requests or cron events, which can be common vectors for attacks.
However, significant concerns arise from the static analysis. The presence of dangerous functions like `unserialize` and `create_function` is a major red flag, as these can lead to Remote Code Execution (RCE) if not handled with extreme care, especially when processing user-supplied data. The complete lack of output escaping is also a critical vulnerability, exposing the site to Cross-Site Scripting (XSS) attacks. The absence of nonce checks and capability checks on the single entry point (the shortcode) means that any authenticated user could potentially trigger unintended actions, further increasing the risk.
Given the lack of historical vulnerabilities, it might suggest the plugin has been relatively secure in the past, or perhaps it hasn't been subjected to rigorous security audits or attacks. However, the current code analysis reveals clear and present dangers. The combination of dangerous functions and widespread lack of output escaping, coupled with insufficient authorization checks on its entry points, creates a high-risk profile. While the prepared statements and lack of external requests are strengths, they do not mitigate the severity of the identified code-level weaknesses.
Key Concerns
- Dangerous functions present (unserialize, create_function)
- Output escaping is missing (0% properly escaped)
- No nonce checks
- No capability checks
- Shortcode without auth checks
PhotoPress – Image Taxonomies Security Vulnerabilities
PhotoPress – Image Taxonomies Code Analysis
Dangerous Functions Found
Output Escaping
PhotoPress – Image Taxonomies Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
PhotoPress – Image Taxonomies Maintenance & Trust
Maintenance Signals
Community Trust
PhotoPress – Image Taxonomies Alternatives
PhotoPress – Gallery
photopress-gallery
Extends the [gallery] shortcode to be able to create galleries from image taxonomies or the featured images of specific Posts.
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
FancyBox for WordPress
fancybox-for-wordpress
Seamlessly integrates FancyBox lightbox into your WordPress blog: Upload, activate, and you're done. Additional configuration optional.
Lightbox with PhotoSwipe
lightbox-photoswipe
Integration of PhotoSwipe (http://photoswipe.com) for WordPress.
PhotoPress – Image Taxonomies Developer Profile
7 plugins · 350 total installs
How We Detect PhotoPress – Image Taxonomies
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/photo-tools-image-taxonomies/css/photo-tools.css/wp-content/plugins/photo-tools-image-taxonomies/js/photo-tools.js/wp-content/plugins/photo-tools-image-taxonomies/js/photo-tools.jsphoto-tools-image-taxonomies/css/photo-tools.css?ver=photo-tools-image-taxonomies/js/photo-tools.js?ver=HTML / DOM Fingerprints
photo-tools-wrapperphoto-tools-image-taxonomiesphotoToolsphotoToolsAjaxUrl