Quick Media Inspect Security & Risk Analysis

wordpress.org/plugins/quick-media-inspect

Detect unused images across your entire WordPress site, clean up your Media Library safely, and generate alt text from filenames.

80 active installs v1.0.3 PHP 7.4+ WP 6.0+ Updated Oct 4, 2025
alt-textcleanupimages-usagemediaoptimization
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quick Media Inspect Safe to Use in 2026?

Generally Safe

Score 100/100

Quick Media Inspect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "quick-media-inspect" v1.0.3 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, critical or high severity vulnerabilities in the vulnerability history, and the plugin's reliance on prepared statements for almost all SQL queries (97%) are highly positive indicators. Furthermore, the code shows good practices in output escaping (90%) and includes a healthy number of nonce (6) and capability (10) checks, contributing to a secure foundation. The static analysis reveals no untrusted input reaching dangerous functions, no unsanitized paths in the taint analysis, and a complete lack of file operations or external HTTP requests, all of which significantly mitigate common attack vectors. The attack surface, though containing 3 AJAX handlers, is reported as having 0 unprotected entry points, suggesting robust authentication and authorization mechanisms are in place for these handlers. While the plugin demonstrates excellent security hygiene, it's always prudent to maintain vigilance. The fact that there's no vulnerability history at all could mean it's a very new or very niche plugin, or that its security has simply not been thoroughly tested externally. However, based solely on the provided data, this plugin appears to be well-developed from a security perspective.

Vulnerabilities
None known

Quick Media Inspect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Quick Media Inspect Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
34 prepared
Unescaped Output
10
92 escaped
Nonce Checks
6
Capability Checks
10
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

97% prepared35 total queries

Output Escaping

90% escaped102 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
<alt-generator> (admin\views\alt-generator.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Quick Media Inspect Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_tl_qmi_scan_imagesadmin\class-qmi-admin.php:13
authwp_ajax_tl_qmi_bulk_actionadmin\class-qmi-admin.php:14
authwp_ajax_tl_qmi_generate_alt_textadmin\class-qmi-admin.php:15
WordPress Hooks 5
actionadmin_menuadmin\class-qmi-admin.php:11
actionadmin_enqueue_scriptsadmin\class-qmi-admin.php:12
filterposts_whereincludes\helpers.php:86
filterposts_whereincludes\helpers.php:105
actionplugins_loadedquick-media-inspect.php:35
Maintenance & Trust

Quick Media Inspect Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 4, 2025
PHP min version7.4
Downloads499

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

Quick Media Inspect Developer Profile

Irfan Ahmed

1 plugin · 80 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quick Media Inspect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quick-media-inspect/assets/css/admin.css/wp-content/plugins/quick-media-inspect/assets/js/admin.js
Script Paths
/wp-content/plugins/quick-media-inspect/assets/js/admin.js
Version Parameters
quick-media-inspect/assets/css/admin.css?ver=quick-media-inspect/assets/js/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
tl_qmi_admin
REST Endpoints
/wp-json/quick-media-inspect/
FAQ

Frequently Asked Questions about Quick Media Inspect