
Remove Broken Images Security & Risk Analysis
wordpress.org/plugins/remove-broken-imagesVery simply, uses JavaScript to remove broken images from page display.
Is Remove Broken Images Safe to Use in 2026?
Generally Safe
Score 92/100Remove Broken Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "remove-broken-images" plugin, version 1.5.0-beta-1, exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the analysis shows no dangerous functions, file operations, or external HTTP requests, and all SQL queries are handled with prepared statements. The presence of a nonce check is a positive sign of security consciousness.
However, a notable concern is the output escaping, where only 57% of outputs are properly escaped. This leaves a portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not handled correctly before being displayed. The lack of capability checks on any entry points (though there are none) could also be a point of concern in a more complex plugin, but in this case, it does not pose an immediate threat due to the limited attack surface.
The plugin's vulnerability history is pristine, with zero recorded CVEs. This indicates a history of responsible development and maintenance, or simply a lack of discovered vulnerabilities. Coupled with the clean taint analysis results, this suggests the plugin has historically been robust. Overall, the plugin is secure due to its minimal attack surface and robust internal practices, but the unescaped output is a specific area that warrants attention.
Key Concerns
- Output escaping not fully implemented
Remove Broken Images Security Vulnerabilities
Remove Broken Images Release Timeline
Remove Broken Images Code Analysis
Output Escaping
Remove Broken Images Attack Surface
WordPress Hooks 4
Maintenance & Trust
Remove Broken Images Maintenance & Trust
Maintenance Signals
Community Trust
Remove Broken Images Alternatives
PixRem – Unused Image Cleaner
pixrem
Find and delete unused images in your Media Library. Backup, restore, whitelist, and scan support for all major page builders.
Broken Image Fallback
broken-image-fallback
Automatically replace broken or missing images with a custom fallback image. Works with WordPress and WooCommerce.
Orphanix Media Cleanup
orphanix-media-cleanup
Smart WordPress media library cleanup. Detect unused, orphaned & broken media safely with advanced live scanning.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Enable Media Replace
enable-media-replace
Easily replace any attached image/file by simply uploading a new file in the Media Library edit view - a real time saver!
Remove Broken Images Developer Profile
10 plugins · 14K total installs
How We Detect Remove Broken Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/remove-broken-images/assets/admin-style-min.css/wp-content/plugins/remove-broken-images/assets/script.min.jsassets/script.min.jsremove-broken-images/assets/script.min.js?ver=HTML / DOM Fingerprints
r34rbir34rbi-admin-noticer34rbi_redirect_on_missing_image