Regen. Thumbs Security & Risk Analysis

wordpress.org/plugins/regen-thumbs

Regen. Thumbs - regenerate WordPress post thumbnails per post in one click!

400 active installs v1.1 PHP 7.0+ WP 4.9.5+ Updated Dec 8, 2018
thumbnails
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Regen. Thumbs Safe to Use in 2026?

Generally Safe

Score 85/100

Regen. Thumbs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'regen-thumbs' plugin v1.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin has a minimal attack surface, with all identified entry points (AJAX handlers) appearing to have authentication checks, which is a positive indicator. Furthermore, the code demonstrates good practices by exclusively using prepared statements for SQL queries, properly escaping all outputs, and avoiding dangerous functions. The absence of known CVEs and any recorded vulnerability history suggests a history of stable and secure development.

Despite these strengths, there are a couple of minor areas for consideration. The plugin lacks explicit capability checks for its AJAX handlers, relying solely on authentication. While this might be acceptable for certain functionalities, implementing capability checks would provide an additional layer of defense against privilege escalation if an authenticated user were to attempt to access functionalities beyond their intended role. The taint analysis shows no critical or high-severity flows, which is excellent, but the absence of any taint analysis flows analyzed at all might mean the tool couldn't analyze certain parts of the code or that the complexity was low, making it difficult to provide a definitive assessment of taint risks.

In conclusion, 'regen-thumbs' v1.1 appears to be a secure plugin with robust coding practices and no historical vulnerabilities. The primary area for potential improvement lies in reinforcing the security of its AJAX handlers with capability checks, adding a more granular layer of access control. The lack of observed taint flows warrants a note but doesn't necessarily indicate a flaw in the plugin itself, rather a potential limitation in the analysis scope.

Key Concerns

  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

Regen. Thumbs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Regen. Thumbs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Regen. Thumbs Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_regen_thumbsinc\class-regen-thumbs.php:12
authwp_ajax_regen_thumbsinc\class-regen-thumbs.php:13
WordPress Hooks 3
actionpost_submitbox_misc_actionsinc\class-regen-thumbs.php:10
actionadmin_enqueue_scriptsinc\class-regen-thumbs.php:11
actionplugins_loadedregen-thumbs.php:29
Maintenance & Trust

Regen. Thumbs Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 8, 2018
PHP min version7.0
Downloads13K

Community Trust

Rating100/100
Number of ratings2
Active installs400
Developer Profile

Regen. Thumbs Developer Profile

Alexandre Froger

11 plugins · 8K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
110 days
View full developer profile
Detection Fingerprints

How We Detect Regen. Thumbs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/regen-thumbs/js/main.js/wp-content/plugins/regen-thumbs/js/main.min.js
Script Paths
/wp-content/plugins/regen-thumbs/js/main.js/wp-content/plugins/regen-thumbs/js/main.min.js
Version Parameters
regen-thumbs/js/main.js?ver=regen-thumbs/js/main.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
regen-thumbs
Data Attributes
data-post_id
JS Globals
RegenThumbs
Shortcode Output
<div class="misc-pub-section" id="regen-thumbs"><a class="button" href="#" id="post-regen-thumbs" data-post_id=
FAQ

Frequently Asked Questions about Regen. Thumbs