
Replace External Images Security & Risk Analysis
wordpress.org/plugins/replace-external-imagesEasily import externally hosted images found in post content into your media library and replace them with local copies.
Is Replace External Images Safe to Use in 2026?
Generally Safe
Score 100/100Replace External Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "replace-external-images" v1.2.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL query preparation and output escaping, with 100% of both being handled securely. The absence of any recorded vulnerabilities in its history is a strong indicator of a well-maintained and secure codebase. Furthermore, the presence of nonce and capability checks on some entry points suggests an awareness of WordPress security best practices.
However, the plugin does present significant concerns primarily related to its attack surface. With a total of 4 AJAX handlers, 3 of them lack any authentication checks. This creates a substantial risk of unauthorized access and execution of potentially harmful actions. While there are no identified critical or high-severity taint flows, and no dangerous functions are used, the unprotected AJAX handlers remain a primary vector for exploitation. The single file operation and external HTTP request also warrant careful consideration, although their context and potential impact are not detailed here.
Key Concerns
- Unprotected AJAX handlers
- Large attack surface without auth
Replace External Images Security Vulnerabilities
Replace External Images Code Analysis
Output Escaping
Data Flow Analysis
Replace External Images Attack Surface
AJAX Handlers 4
WordPress Hooks 8
Maintenance & Trust
Replace External Images Maintenance & Trust
Maintenance Signals
Community Trust
Replace External Images Alternatives
Smart Auto Upload Images – Import External Images
smart-auto-upload-images
Import external images automatically on save. Adds to media library and updates URLs. No manual downloads. Works with any post type.
GL Import External Images
gl-import-external-images
Import and insert images to WordPress Media Library from external URLs.
Sage Auto Upload Images
sage-auto-upload-images
Automatically detect and import external images to your WordPress media library. Bulk process existing posts and prevent broken links.
Archivarix External Images Importer
archivarix-external-images-importer
Import external images in posts and pages from external sources or Web Archive if original sources are not available anymore.
WP Image Importer
wp-image-importer
WP Image Importer plugin allows you to easily insert image into your wordpress post from facebook, flickr and pixabay
Replace External Images Developer Profile
2 plugins · 60 total installs
How We Detect Replace External Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/replace-external-images/assets/replexim-live.js/wp-content/plugins/replace-external-images/assets/replexim-live.jsreplace-external-images/assets/replexim-live.js?ver=HTML / DOM Fingerprints
replexim-global-addon-noticereplexim_dismiss_global_addon_noticereplexim_live_import/wp-json/replexim/v1/ping