Quick Featured Images Security & Risk Analysis

wordpress.org/plugins/quick-featured-images

The time-saving solution for managing tons of featured images within minutes: Set, replace and delete in bulk and set default images for future posts.

50K active installs v13.7.4 PHP 5.2+ WP 3.8+ Updated Nov 6, 2025
automaticbulk-setfeatured-imagefeatured-imagesthumbnails
96
A · Safe
CVEs total3
Unpatched0
Last CVENov 7, 2025
Safety Verdict

Is Quick Featured Images Safe to Use in 2026?

Generally Safe

Score 96/100

Quick Featured Images has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Nov 7, 2025Updated 4mo ago
Risk Assessment

The quick-featured-images plugin v13.7.4 exhibits a generally good security posture, with a notable lack of critical or high-severity code signals. The presence of nonces and capability checks on all identified entry points (AJAX handlers) is a positive indicator of secure development practices. Furthermore, the high percentage of SQL queries using prepared statements (93%) and the absence of dangerous functions or file operations suggest a solid foundation for preventing common web vulnerabilities. The taint analysis also shows no identified vulnerabilities with unsanitized paths, reinforcing the impression of robust input handling.

Despite these strengths, concerns arise from the vulnerability history. The plugin has had a total of 3 known CVEs, all categorized as medium severity. These historically included SQL injection, authorization bypass, and missing authorization vulnerabilities. While none are currently unpatched, this history indicates past weaknesses in how user input was handled and authorization was enforced. The last known vulnerability was relatively recent (2025-11-07), suggesting that even with ongoing development, new issues can emerge. The 55% proper output escaping, while not alarmingly low, still leaves room for potential cross-site scripting (XSS) vulnerabilities if not carefully managed in the remaining 45% of outputs.

In conclusion, quick-featured-images v13.7.4 is reasonably secure due to its architecture and adherence to common security best practices like prepared statements and entry point validation. However, its historical vulnerability record warrants cautious consideration, particularly concerning authorization and SQL injection. The moderate output escaping also presents a minor, albeit present, risk. Vigilance and prompt updates for any future vulnerabilities are advised.

Key Concerns

  • Medium severity CVEs in vulnerability history
  • Moderate output escaping (55% proper)
Vulnerabilities
3

Quick Featured Images Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-11980medium · 4.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Quick Featured Images <= 13.7.3 - Authenticated (Editor+) SQL Injection via delete_orphaned

Nov 7, 2025 Patched in 13.7.4 (1d)
CVE-2025-11176medium · 4.3Authorization Bypass Through User-Controlled Key

Quick Featured Images <= 13.7.2 - Insecure Direct Object Reference to Image Manipulation

Oct 14, 2025 Patched in 13.7.3 (1d)
CVE-2024-3664medium · 4.3Missing Authorization

Quick Featured Images <= 13.7.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Thumbnail Deletion/Setting

Apr 22, 2024 Patched in 13.7.1 (1d)
Code Analysis
Analyzed Mar 16, 2026

Quick Featured Images Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
14 prepared
Unescaped Output
171
210 escaped
Nonce Checks
12
Capability Checks
9
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

93% prepared15 total queries

Output Escaping

55% escaped381 total outputs
Data Flows
All sanitized

Data Flow Analysis

5 flows
set_thumbnail (admin\class-Quick_Featured_Images_Columns.php:507)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Quick Featured Images Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_qfi_set_thumbnailadmin\class-Quick_Featured_Images_Columns.php:223
authwp_ajax_qfi_delete_thumbnailadmin\class-Quick_Featured_Images_Columns.php:225
WordPress Hooks 33
actioninitadmin\class-Quick_Featured_Images_Admin.php:108
actionwpmu_new_blogadmin\class-Quick_Featured_Images_Admin.php:111
actionadmin_menuadmin\class-Quick_Featured_Images_Admin.php:114
actionadmin_enqueue_scriptsadmin\class-Quick_Featured_Images_Admin.php:117
actionadmin_noticesadmin\class-Quick_Featured_Images_Admin.php:127
actionmanage_media_columnsadmin\class-Quick_Featured_Images_Columns.php:161
actionmanage_media_custom_columnadmin\class-Quick_Featured_Images_Columns.php:163
actionadmin_headadmin\class-Quick_Featured_Images_Columns.php:165
actionadmin_initadmin\class-Quick_Featured_Images_Columns.php:213
actionadmin_enqueue_scriptsadmin\class-Quick_Featured_Images_Columns.php:215
actionadmin_enqueue_scriptsadmin\class-Quick_Featured_Images_Columns.php:217
actionadmin_headadmin\class-Quick_Featured_Images_Columns.php:219
filterpre_get_postsadmin\class-Quick_Featured_Images_Columns.php:221
actionadmin_enqueue_scriptsadmin\class-Quick_Featured_Images_Comparison.php:125
actionadmin_menuadmin\class-Quick_Featured_Images_Comparison.php:128
actionadmin_enqueue_scriptsadmin\class-Quick_Featured_Images_Defaults.php:201
actionadmin_enqueue_scriptsadmin\class-Quick_Featured_Images_Defaults.php:202
actionadmin_menuadmin\class-Quick_Featured_Images_Defaults.php:205
actionsave_postadmin\class-Quick_Featured_Images_Defaults.php:208
actiondelete_attachmentadmin\class-Quick_Featured_Images_Defaults.php:211
actionadmin_enqueue_scriptsadmin\class-Quick_Featured_Images_Settings.php:157
actionadmin_menuadmin\class-Quick_Featured_Images_Settings.php:160
actionadmin_initadmin\class-Quick_Featured_Images_Settings.php:170
actionadmin_enqueue_scriptsadmin\class-Quick_Featured_Images_Tools.php:391
actionadmin_enqueue_scriptsadmin\class-Quick_Featured_Images_Tools.php:392
actionadmin_menuadmin\class-Quick_Featured_Images_Tools.php:395
filtermedia_row_actionsadmin\class-Quick_Featured_Images_Tools.php:398
actionplugins_loadedquick-featured-images.php:41
actionplugins_loadedquick-featured-images.php:58
actionplugins_loadedquick-featured-images.php:66
actionplugins_loadedquick-featured-images.php:73
actionplugins_loadedquick-featured-images.php:78
actionplugins_loadedquick-featured-images.php:83
Maintenance & Trust

Quick Featured Images Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 6, 2025
PHP min version5.2
Downloads1.2M

Community Trust

Rating94/100
Number of ratings236
Active installs50K
Developer Profile

Quick Featured Images Developer Profile

Kybernetik Services

10 plugins · 167K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Quick Featured Images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quick-featured-images/css/admin/css/admin.css/wp-content/plugins/quick-featured-images/css/admin/css/bootstrap.css/wp-content/plugins/quick-featured-images/css/admin/css/bootstrap-theme.css/wp-content/plugins/quick-featured-images/css/admin/css/jquery-ui.css/wp-content/plugins/quick-featured-images/css/admin/css/select2.min.css/wp-content/plugins/quick-featured-images/css/admin/css/wp-jquery-ui-dialog.css/wp-content/plugins/quick-featured-images/css/admin/css/quick-featured-images.css/wp-content/plugins/quick-featured-images/css/admin/css/quick-featured-images-default.css+14 more
Script Paths
/wp-content/plugins/quick-featured-images/js/admin/js/qfi-admin.js/wp-content/plugins/quick-featured-images/js/admin/js/bootstrap.js/wp-content/plugins/quick-featured-images/js/admin/js/jquery-ui.js/wp-content/plugins/quick-featured-images/js/admin/js/jquery-ui-dialog.js/wp-content/plugins/quick-featured-images/js/admin/js/jquery-ui-tabs.js/wp-content/plugins/quick-featured-images/js/admin/js/jquery-ui-datepicker.js+8 more
Version Parameters
quick-featured-images/css/admin/css/admin.css?ver=quick-featured-images/css/admin/css/bootstrap.css?ver=quick-featured-images/css/admin/css/bootstrap-theme.css?ver=quick-featured-images/css/admin/css/jquery-ui.css?ver=quick-featured-images/css/admin/css/select2.min.css?ver=quick-featured-images/css/admin/css/wp-jquery-ui-dialog.css?ver=quick-featured-images/css/admin/css/quick-featured-images.css?ver=quick-featured-images/css/admin/css/quick-featured-images-default.css?ver=quick-featured-images/js/admin/js/qfi-admin.js?ver=quick-featured-images/js/admin/js/bootstrap.js?ver=quick-featured-images/js/admin/js/jquery-ui.js?ver=quick-featured-images/js/admin/js/jquery-ui-dialog.js?ver=quick-featured-images/js/admin/js/jquery-ui-tabs.js?ver=quick-featured-images/js/admin/js/jquery-ui-datepicker.js?ver=quick-featured-images/js/admin/js/select2.full.min.js?ver=quick-featured-images/js/admin/js/quick-featured-images.js?ver=quick-featured-images/js/admin/js/quick-featured-images-admin.js?ver=quick-featured-images/js/admin/js/quick-featured-images-tools.js?ver=quick-featured-images/js/admin/js/quick-featured-images-settings.js?ver=quick-featured-images/js/admin/js/quick-featured-images-columns.js?ver=quick-featured-images/js/admin/js/quick-featured-images-defaults.js?ver=quick-featured-images/js/admin/js/quick-featured-images-comparison.js?ver=

HTML / DOM Fingerprints

CSS Classes
qfi-flex-rowqfi-quick-set-featured-imageqfi-post-list-actionsqfi-bulk-actionsqfi-bulk-actionqfi-bulk-action-selectqfi-bulk-action-deleteqfi-bulk-action-replace+71 more
HTML Comments
<!-- Quick Featured Images Admin --><!-- Quick Featured Images Bulk Actions --><!-- Quick Featured Images Bulk Action Select --><!-- Quick Featured Images Bulk Action Delete -->+77 more
Data Attributes
data-qfi-bulk-action-typedata-qfi-image-iddata-qfi-post-iddata-qfi-actiondata-qfi-setting-namedata-qfi-setting-value+1 more
JS Globals
quick_featured_images_adminqfi_admin_paramsquick_featured_images_toolsqfi_tools_paramsquick_featured_images_settingsqfi_settings_params+6 more
FAQ

Frequently Asked Questions about Quick Featured Images