
Replace Content Image Size Security & Risk Analysis
wordpress.org/plugins/replace-content-image-sizeFind images displayed in posts content and change the format size, very useful when you change the blog theme.
Is Replace Content Image Size Safe to Use in 2026?
Generally Safe
Score 85/100Replace Content Image Size has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "replace-content-image-size" plugin, version 1.2.1, exhibits a mixed security posture. On one hand, it boasts a commendably small attack surface with no registered AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, zero unprotected entry points. This significantly reduces the opportunities for external attackers to directly interact with the plugin. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is a positive indicator of secure coding practices.
However, the static analysis reveals critical concerns. All three SQL queries are executed without prepared statements, a major vulnerability that could lead to SQL injection attacks. The taint analysis identified two high-severity flows with unsanitized paths, suggesting that user-supplied data might be used in a way that could compromise file system operations or other sensitive actions. The lack of any capability checks or nonce checks further exacerbates these risks, as these are fundamental WordPress security mechanisms designed to prevent unauthorized actions and cross-site request forgery.
The plugin's vulnerability history is currently clean, with no recorded CVEs. While this is a strong positive, it cannot entirely offset the significant code-level risks identified. The absence of past vulnerabilities might be due to the plugin's limited exposure or a recent clean state, but the current code analysis presents immediate and actionable security concerns that require attention. Overall, the plugin has strengths in its limited attack surface, but its reliance on raw SQL and the presence of high-severity unsanitized taint flows create substantial risks.
Key Concerns
- Raw SQL queries without prepared statements
- High severity taint flow (unsanitized path)
- High severity taint flow (unsanitized path)
- Missing capability checks
- Missing nonce checks
- Low percentage of properly escaped output
Replace Content Image Size Security Vulnerabilities
Replace Content Image Size Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Replace Content Image Size Attack Surface
WordPress Hooks 2
Maintenance & Trust
Replace Content Image Size Maintenance & Trust
Maintenance Signals
Community Trust
Replace Content Image Size Alternatives
ChoiceCuts Image Juggler
choicecuts-image-juggler
ChoiceCuts Image Juggler resizes images, generates thumbnails, adds lightboxes and enhances image presentation in WordPress.
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
shortpixel-image-optimiser
Optimize images & PDFs smartly. Create and compress next-gen WebP and AVIF formats. Smart crop and resize.
Imsanity
imsanity
Automatically resizes huge image uploads. Are contributors uploading huge photos? Tired of manually resizing your images? Imsanity to the rescue!
Enhanced Responsive Images
auto-sizes
Improvements for responsive images in WordPress.
QODE Optimizer
qode-optimizer
The QODE Optimizer plugin is developed to allow you to convert, compress and adjust file sizes for all the images found on your website.
Replace Content Image Size Developer Profile
8 plugins · 620 total installs
How We Detect Replace Content Image Size
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/replace-content-image-size/