
Resize Image After Upload Security & Risk Analysis
wordpress.org/plugins/resize-image-after-uploadAutomatically resize your images after uploading using this plugin. Specify height&width, the plugin will do the rest quickly and transparently.
Is Resize Image After Upload Safe to Use in 2026?
Generally Safe
Score 99/100Resize Image After Upload has a strong security track record. Known vulnerabilities have been patched promptly.
The 'resize-image-after-upload' plugin version 1.8.6 presents a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed. Furthermore, all SQL queries are properly prepared, and there are no external HTTP requests or bundled libraries to worry about. The presence of nonce and capability checks, albeit limited, is a good practice.
However, concerns arise from the output escaping, where only 36% of outputs are properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is not adequately sanitized before being displayed. The taint analysis also shows one flow with an unsanitized path, indicating a possible information disclosure or other security risk, though it's not rated as critical or high severity. The plugin's vulnerability history, with one past high-severity CVE related to CSRF, further emphasizes the need for careful review of its security implementation. While the current version appears to have no unpatched vulnerabilities, the historical pattern of a high-severity issue warrants caution.
In conclusion, while the plugin has made strides in reducing its attack surface and employing secure database practices, the insufficient output escaping and the presence of an unsanitized path in the taint analysis are significant weaknesses. The past CSRF vulnerability, though patched, highlights a historical tendency that requires ongoing vigilance. Users should be aware of the potential for XSS and other data handling issues. It's crucial for developers to address the output escaping and taint flow concerns to improve the overall security of this plugin.
Key Concerns
- Unsanitized path in taint analysis
- Low percentage of properly escaped output
- Past high severity vulnerability (CSRF)
Resize Image After Upload Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Resize Image After Upload <= 1.8.5 - Cross-Site Request Forgery
Resize Image After Upload Code Analysis
Output Escaping
Data Flow Analysis
Resize Image After Upload Attack Surface
WordPress Hooks 2
Maintenance & Trust
Resize Image After Upload Maintenance & Trust
Maintenance Signals
Community Trust
Resize Image After Upload Alternatives
EWWW Image Optimizer
ewww-image-optimizer
Comprehensive image optimization that doesn't require a rocket science degree. Optimize images automatically for Faster Sites and Happy Visitors.
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
shortpixel-image-optimiser
Optimize images & PDFs smartly. Create and compress next-gen WebP and AVIF formats. Smart crop and resize.
Imsanity
imsanity
Automatically resizes huge image uploads. Are contributors uploading huge photos? Tired of manually resizing your images? Imsanity to the rescue!
Advanced iFrame
advanced-iframe
Include content the way YOU like in an iframe that can hide and modify elements, does auto-height, forward parameters and does many, many more...
QODE Optimizer
qode-optimizer
The QODE Optimizer plugin is developed to allow you to convert, compress and adjust file sizes for all the images found on your website.
Resize Image After Upload Developer Profile
8 plugins · 1.2M total installs
How We Detect Resize Image After Upload
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/resize-image-after-upload/js/dismiss_notices.js/wp-content/plugins/resize-image-after-upload/js/dismiss_notices.jsresize-image-after-upload/js/dismiss_notices.js?ver=resize-image-after-upload/css/style.css?ver=HTML / DOM Fingerprints
resizeimage-button<!-- Plugin Name: Resize Image After Upload --><!-- Plugin URI: https://wordpress.org/plugins/resize-image-after-upload/ --><!-- Description: Automatically resize uploaded images to within specified maximum width and height. Also has option to force recompression of JPEGs. Configuration options found under <a href="options-general.php?page=resize-after-upload">Settings > Resize Image Upload</a> --><!-- Author: ShortPixel -->+1 morejr_options_updatejr_resizeupload_widthjr_resizeupload_heightjr_resizeupload_qualityjr_resizeupload_resize_yesnojr_resizeupload_recompress_yesno+10 morejrResizeuploadDismissNewsjr_settings_page