
Resize Control – Compress and resize images after upload Security & Risk Analysis
wordpress.org/plugins/resize-controlAuto resize, optimize images; ensure compression for WP accounts to save time, speed, space, and bandwidth.
Is Resize Control – Compress and resize images after upload Safe to Use in 2026?
Generally Safe
Score 100/100Resize Control – Compress and resize images after upload has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "resize-control" plugin v1.0.91 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin demonstrates strong adherence to secure coding practices, with all SQL queries utilizing prepared statements and an overwhelming majority of outputs being properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. Furthermore, the lack of any known historical vulnerabilities, critical or otherwise, is a significant positive indicator. The attack surface, while present with two REST API routes, is secured by permission callbacks, and there are no unprotected entry points. The sole capability check indicates a conscious effort to restrict access to certain functionalities.
However, a notable concern is the complete absence of nonce checks across all entry points, including the REST API routes which lack explicit permission callbacks according to the 'Unprotected: 0' status. While the static analysis reports no unprotected entry points, the lack of documented nonce checks on these REST API routes presents a potential weakness. This could leave the plugin susceptible to Cross-Site Request Forgery (CSRF) attacks if the underlying operations performed by these routes are sensitive or can be exploited. The taint analysis showing zero flows with unsanitized paths is reassuring, but it doesn't mitigate the risk of CSRF if nonces are not implemented.
Key Concerns
- Missing nonce checks on REST API routes
Resize Control – Compress and resize images after upload Security Vulnerabilities
Resize Control – Compress and resize images after upload Code Analysis
Output Escaping
Resize Control – Compress and resize images after upload Attack Surface
REST API Routes 2
Maintenance & Trust
Resize Control – Compress and resize images after upload Maintenance & Trust
Maintenance Signals
Community Trust
Resize Control – Compress and resize images after upload Alternatives
Auto WebP & Alt Optimizer
auto-webp-alt-optimizer
Automatically convert uploaded images to WebP format using native GD library for maximum compatibility, and auto-fill image Alt text for better SEO.
Resizeer
resizeer
Optimize your images automatically and forget about resizing and compressing them manually before uploading to your WordPress site.
Toolszu Image Optimizer
toolszu-image-optimizer
Toolszu Image Optimizer is a lightweight WordPress image compression, resizing, and WebP conversion plugin designed for content writers, bloggers, and …
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
shortpixel-image-optimiser
Optimize images & PDFs smartly. Create and compress next-gen WebP and AVIF formats. Smart crop and resize.
Kraken.io Image Optimizer
kraken-image-optimizer
This plugin allows you to optimize your WordPress images through the Kraken.io API, the world's most advanced image optimization and resizing API.
Resize Control – Compress and resize images after upload Developer Profile
1 plugin · 20 total installs
How We Detect Resize Control – Compress and resize images after upload
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/resize-control/admin/css/reco-style.min.css/wp-content/plugins/resize-control/admin/js/browser-image-compression.js/wp-content/plugins/resize-control/admin/js/reco-image.js/wp-content/plugins/resize-control/admin/js/reco-script.js/wp-content/plugins/resize-control/admin/js/vendor/plupload.min.js/wp-content/plugins/resize-control/admin/js/browser-image-compression.js/wp-content/plugins/resize-control/admin/js/reco-image.js/wp-content/plugins/resize-control/admin/js/reco-script.js/wp-content/plugins/resize-control/admin/js/vendor/plupload.min.jsHTML / DOM Fingerprints
ajax_var/wp-json/reco-api/v1/settings/wp-json/reco-api/v1/license