pixx.io Security & Risk Analysis

wordpress.org/plugins/pixx-io

Integrate pixx.io DAM Digital Asset Management into WordPress. Use files from your pixx.io media pool with WordPress easily and without any detour.

90 active installs v2.1.1 PHP 7.4+ WP 6.0+ Updated Nov 12, 2025
damdigital-asset-managementpixxpixxio
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is pixx.io Safe to Use in 2026?

Generally Safe

Score 100/100

pixx.io has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The pixx-io plugin v2.1.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the plugin's adherence to good coding practices, such as using prepared statements for all SQL queries and implementing nonce and capability checks, are significant strengths. The attack surface is minimal, with only one AJAX handler and no exposed REST API routes, shortcodes, or cron events. Furthermore, the taint analysis showing no unsanitized paths indicates a lack of common injection vulnerabilities. However, there are minor areas for improvement. The 16% of output that is not properly escaped (3 out of 19 outputs) could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped data is user-controlled or sensitive. Additionally, while the plugin performs file operations and makes external HTTP requests, the lack of detailed taint flow analysis for these operations leaves a slight ambiguity regarding potential risks if input sanitization were insufficient in these specific contexts. Overall, the plugin is well-secured, but a review of the unescaped output is recommended to achieve a fully robust security profile.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

pixx.io Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

pixx.io Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
16 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

84% escaped19 total outputs
Attack Surface

pixx.io Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_download_pixxio_imageincludes\pixxio-mediahandler.class.php:27
WordPress Hooks 10
actionadmin_enqueue_scriptsincludes\pixxio-admin.class.php:35
actionprint_media_templatesincludes\pixxio-admin.class.php:40
actionpre-plupload-upload-uiincludes\pixxio-admin.class.php:45
actionattachment_submitbox_misc_actionsincludes\pixxio-admin.class.php:50
actioninitincludes\pixxio-i18n.class.php:21
filterwp_prepare_attachment_for_jsincludes\pixxio-mediahandler.class.php:32
filterwp_get_attachment_image_attributesincludes\pixxio-mediahandler.class.php:39
filtermedia_row_actionsincludes\pixxio-mediahandler.class.php:46
actionhttp_api_curlincludes\pixxio-mediahandler.class.php:118
actionplugins_loadedpixx-io.php:97
Maintenance & Trust

pixx.io Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 12, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

pixx.io Developer Profile

pixx.io GmbH

1 plugin · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect pixx.io

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pixx-io/includes/pixxio-admin.css/wp-content/plugins/pixx-io/includes/pixxio-admin.js/wp-content/plugins/pixx-io/includes/pixxio-admin-editor.css/wp-content/plugins/pixx-io/includes/pixxio-admin-editor.js
Script Paths
/wp-content/plugins/pixx-io/includes/pixxio-admin.js/wp-content/plugins/pixx-io/includes/pixxio-admin-editor.js
Version Parameters
pixx-io/includes/pixxio-admin.css?ver=pixx-io/includes/pixxio-admin.js?ver=pixx-io/includes/pixxio-admin-editor.css?ver=pixx-io/includes/pixxio-admin-editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
pixxio-metamisc-pub-pixxio
Data Attributes
id="pixxio_sdk"id="pixxio-uploader"id="tmpl-pixxio-content"id="tmpl-pixxio-meta"
JS Globals
window.pixxio_nonce
FAQ

Frequently Asked Questions about pixx.io