PicDefense.io – Your Guard Against Image Copyright Infringement Security & Risk Analysis

wordpress.org/plugins/picdefense-io-image-copyright-risk-checker

Compile list of images on your Wordpress site and submit to PicDefense.io for copyright risk analysis.

100 active installs v1.1.4 PHP 7.3+ WP 6.0.2+ Updated Feb 3, 2025
copyrightimagespicdefensereplacementwatermark
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PicDefense.io – Your Guard Against Image Copyright Infringement Safe to Use in 2026?

Generally Safe

Score 92/100

PicDefense.io – Your Guard Against Image Copyright Infringement has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The picdefense-io-image-copyright-risk-checker plugin, in version 1.1.4, exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping the vast majority of its output. It also avoids using dangerous functions and has no known historical vulnerabilities, which suggests a generally stable codebase. However, significant security concerns arise from its attack surface. Two AJAX handlers are exposed without any authentication checks, presenting a direct pathway for attackers to interact with the plugin's functionality without proper authorization. Additionally, the absence of nonce checks across its entry points is a major weakness, making it susceptible to Cross-Site Request Forgery (CSRF) attacks. While taint analysis did not reveal critical or high severity issues, the presence of a flow with unsanitized paths indicates a potential, albeit unexploited or low-impact, vulnerability that warrants attention. The plugin's lack of historical vulnerabilities is a good sign, but the current unprotected entry points and missing nonce checks create an immediate and significant risk.

Key Concerns

  • AJAX handlers without authentication checks
  • No nonce checks on entry points
  • Flows with unsanitized paths detected
Vulnerabilities
None known

PicDefense.io – Your Guard Against Image Copyright Infringement Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PicDefense.io – Your Guard Against Image Copyright Infringement Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
18 prepared
Unescaped Output
2
74 escaped
Nonce Checks
0
Capability Checks
1
File Operations
8
External Requests
4
Bundled Libraries
0

SQL Query Safety

100% prepared18 total queries

Output Escaping

97% escaped76 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<picdefense-io-setting> (picdefense-io-setting.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

PicDefense.io – Your Guard Against Image Copyright Infringement Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_picdefense_dismiss_noticepicdefense.php:35
authwp_ajax_picdefense_scheduled_event_verifypicdefense.php:36

REST API Routes 1

POST/wp-json/auth-api/picdio-image-replace/picdefense.php:60
WordPress Hooks 8
actioninitpicdefense.php:30
actionrest_api_initpicdefense.php:31
actionadmin_noticespicdefense.php:32
actionpicdio_scheduled_images_scanpicdefense.php:33
actionpicdio_scheduled_images_job_submitpicdefense.php:34
filterintermediate_image_sizes_advancedpicdefense.php:37
actionadmin_menupicdefense.php:300
actionadmin_enqueue_scriptspicdefense.php:301

Scheduled Events 2

picdio_scheduled_images_scan
picdio_scheduled_images_job_submit
Maintenance & Trust

PicDefense.io – Your Guard Against Image Copyright Infringement Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 3, 2025
PHP min version7.3
Downloads3K

Community Trust

Rating54/100
Number of ratings3
Active installs100
Developer Profile

PicDefense.io – Your Guard Against Image Copyright Infringement Developer Profile

PicDefense.io

1 plugin · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PicDefense.io – Your Guard Against Image Copyright Infringement

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/picdefense-io-image-copyright-risk-checker/css/style.css/wp-content/plugins/picdefense-io-image-copyright-risk-checker/js/picdefense-io.js
Script Paths
/wp-content/plugins/picdefense-io-image-copyright-risk-checker/js/picdefense-io.js
Version Parameters
picdefense-io-image-copyright-risk-checker/style.css?ver=picdefense-io-image-copyright-risk-checker/js/picdefense-io.js?ver=

HTML / DOM Fingerprints

JS Globals
PicdefenseIO
REST Endpoints
/wp-json/auth-api/picdio-image-replace/
FAQ

Frequently Asked Questions about PicDefense.io – Your Guard Against Image Copyright Infringement