Post Thumbnail Extras Security & Risk Analysis
wordpress.org/plugins/post-thumbnail-extrasMake using post thumbnails easier for everyday wordpressing.
Is Post Thumbnail Extras Safe to Use in 2026?
Generally Safe
Score 85/100Post Thumbnail Extras has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'post-thumbnail-extras' plugin version 6.0 exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no file operations or external HTTP requests. The absence of critical or high-severity taint flows and known vulnerabilities further contributes to this positive assessment. However, there are areas for improvement that introduce some level of risk.
The primary concern lies in the lack of capability checks and nonce checks across the plugin's entry points. While the attack surface is currently small, with only one shortcode identified, the absence of these security measures means that any user, regardless of their role or permissions, could potentially interact with this shortcode. Furthermore, the output escaping is only 50% effective, meaning half of the plugin's outputs are not properly sanitized, potentially exposing the site to cross-site scripting (XSS) vulnerabilities if the data processed by the shortcode is user-controlled.
In conclusion, while the plugin is free of known vulnerabilities and employs secure coding practices in key areas like SQL handling, the lack of authentication and sanitization on its inputs and outputs represents a significant weakness. The small attack surface mitigates the immediate impact, but this oversight could be exploited if the plugin's functionality evolves or if specific user-controlled data is passed through its limited entry points.
Key Concerns
- 50% output escaping is not properly done
- No nonce checks on entry points
- No capability checks on entry points
Post Thumbnail Extras Security Vulnerabilities
Post Thumbnail Extras Code Analysis
Output Escaping
Post Thumbnail Extras Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Post Thumbnail Extras Maintenance & Trust
Maintenance Signals
Community Trust
Post Thumbnail Extras Alternatives
Bulk-Select Featured Image
bulk-select-featured-image
Allows you to select Featured Image / post thumbnail for your posts directly from the media library view.
Auto Featured Image (Auto Post Thumbnail)
auto-post-thumbnail
Automatically generate, assign, and manage featured images in bulk so every post on your site has a featured image.
Crop-Thumbnails
crop-thumbnails
"Crop Thumbnails" made it easy to get exacly that specific image-detail you want to show in your featured image or gallery image.
Multiple Featured Images
multiple-featured-images
Enables multiple featured images for all post types (including custom post types and WooCommerce products). Comes with a widget and a handy shortcode …
Acme Fix Images – Regenerate Thumbnails
acme-fix-images
Fix image sizes after you have changed image sizes from Media Settings. Ensure your images display consistently across your website.
Post Thumbnail Extras Developer Profile
1 plugin · 200 total installs
How We Detect Post Thumbnail Extras
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-thumbnail-extras/js/media-shortcode.js/wp-content/plugins/post-thumbnail-extras/js/media-shortcode.jsHTML / DOM Fingerprints
pt-post-thumbnaildata-editorPTX_PLUGINURLPTX_DOMAIN[ptInsert Shortcode