Post Thumbnail Column Security & Risk Analysis

wordpress.org/plugins/post-thumbnail-column

Adds a new column to posts list for featured images.

10 active installs v1.0 PHP + WP 3.0+ Updated May 25, 2014
featuredimageimgthumbnailthumbnails
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Thumbnail Column Safe to Use in 2026?

Generally Safe

Score 85/100

Post Thumbnail Column has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

Based on the static analysis, the "post-thumbnail-column" plugin version 1.0 exhibits a strong security posture. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface that could be exploited. Furthermore, the code signals indicate a clean codebase with no dangerous functions, all SQL queries using prepared statements, and all outputs properly escaped. The absence of file operations, external HTTP requests, nonce checks, and capability checks (though noted as absent, this doesn't necessarily imply a weakness given the lack of entry points) further reinforces this positive assessment.

The taint analysis confirms these findings with zero analyzed flows, indicating no unsanitized data reaching sensitive sinks. The plugin's vulnerability history is also clean, with no recorded CVEs of any severity. This lack of historical vulnerabilities, combined with the clean static analysis, suggests a well-developed and secure plugin.

In conclusion, the "post-thumbnail-column" v1.0 appears to be a secure plugin. Its strengths lie in its minimal attack surface and adherence to secure coding practices like prepared statements and output escaping. The absence of any vulnerabilities, past or present, is a significant positive indicator. While the complete absence of nonce and capability checks could be a concern in plugins with a larger attack surface, in this case, with no entry points, it does not represent a current risk.

Vulnerabilities
None known

Post Thumbnail Column Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Post Thumbnail Column Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Post Thumbnail Column Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Post Thumbnail Column Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionplugins_loadedpost-thumbnail-column.php:41
filtermanage_posts_columnspost-thumbnail-column.php:57
actionmanage_posts_custom_columnpost-thumbnail-column.php:71
Maintenance & Trust

Post Thumbnail Column Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedMay 25, 2014
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Post Thumbnail Column Developer Profile

silver530

7 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post Thumbnail Column

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-thumbnail-column/post-thumbnail-column.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Post Thumbnail Column