Really Simple Featured Image: Automatic Featured Images Security & Risk Analysis

wordpress.org/plugins/really-simple-featured-image

Automatically generate missing featured images from video or image inside content for Posts, Pages and CPTs.

0 active installs v1.0.4 PHP 8.0+ WP 6.0+ Updated Jan 10, 2026
auto-featured-imagefeatured-imagefeatured-image-from-videopost-thumbnailsthumbnails
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Really Simple Featured Image: Automatic Featured Images Safe to Use in 2026?

Generally Safe

Score 100/100

Really Simple Featured Image: Automatic Featured Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "really-simple-featured-image" plugin v1.0.4 exhibits a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, SQL injection vulnerabilities, or unescaped output is commendable. Furthermore, the fact that all SQL queries utilize prepared statements and the vast majority of output is properly escaped indicates good development practices aimed at preventing common web vulnerabilities. The plugin also demonstrates a low attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not properly secured.

The vulnerability history is also reassuring, showing zero known CVEs. This, combined with the clean taint analysis results showing no critical or high severity flows with unsanitized data, suggests a history of stable and secure code. The presence of nonce and capability checks, although limited in number, further contributes to its secure design. The bundled libraries, Select2 and Freemius, are standard components, and without further information on their specific versions, it's difficult to assess their individual risk.

Overall, this plugin appears to be well-developed from a security perspective. The lack of identified vulnerabilities and the use of secure coding practices are significant strengths. The primary area to monitor would be the external HTTP requests, as these can sometimes introduce indirect attack vectors if the external services are compromised. However, with the current data, the plugin's security is robust.

Vulnerabilities
None known

Really Simple Featured Image: Automatic Featured Images Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Really Simple Featured Image: Automatic Featured Images Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
428 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
5
Bundled Libraries
2

Bundled Libraries

Select2Freemius1.0

Output Escaping

99% escaped431 total outputs
Attack Surface

Really Simple Featured Image: Automatic Featured Images Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_menuincludes\Settings\class-register-settings.php:24
actionwp_loadedincludes\Settings\class-register-settings.php:27
actioninitincludes\Settings\class-register-settings.php:29
actionload-settings_page_rs-featured-image-settingsincludes\Settings\class-register-settings.php:31
actionadmin_enqueue_scriptsincludes\Settings\class-register-settings.php:55
filterrs_featured_image_settings_tabs_arrayincludes\Settings\class-settings-page.php:37
actionsave_postincludes\Sources\class-source-content.php:31
actiondeleted_post_metaincludes\Sources\class-source-content.php:32
actionrs_featured_image_setting_featured_image_from_contentincludes\Sources\class-source-content.php:33
actionsave_postincludes\Sources\class-source-video.php:35
actionrs_featured_image_setting_featured_image_from_content_videoincludes\Sources\class-source-video.php:38
actionplugins_loadedreally-simple-featured-image.php:85
Maintenance & Trust

Really Simple Featured Image: Automatic Featured Images Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 10, 2026
PHP min version8.0
Downloads130

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Really Simple Featured Image: Automatic Featured Images Developer Profile

JetixWP Plugins

4 plugins · 5K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Really Simple Featured Image: Automatic Featured Images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/really-simple-featured-image/assets/css/admin-settings.css/wp-content/plugins/really-simple-featured-image/assets/js/admin-settings.js/wp-content/plugins/really-simple-featured-image/assets/css/select2/select2.css/wp-content/plugins/really-simple-featured-image/assets/js/select2/select2.js
Script Paths
/wp-content/plugins/really-simple-featured-image/assets/js/select2/select2.js/wp-content/plugins/really-simple-featured-image/assets/js/admin-settings.js
Version Parameters
/wp-content/plugins/really-simple-featured-image/assets/css/select2/select2.css?ver=/wp-content/plugins/really-simple-featured-image/assets/css/admin-settings.css?ver=/wp-content/plugins/really-simple-featured-image/assets/js/select2/select2.js?ver=/wp-content/plugins/really-simple-featured-image/assets/js/admin-settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
rs_featured_image_settings_select2
Data Attributes
rs_featured_image_settings_data
JS Globals
rs_featured_image_settings_data
FAQ

Frequently Asked Questions about Really Simple Featured Image: Automatic Featured Images