
Resize images before upload Security & Risk Analysis
wordpress.org/plugins/resize-images-before-uploadAutomatically resizes your images right in your browser, before uploading.
Is Resize images before upload Safe to Use in 2026?
Generally Safe
Score 85/100Resize images before upload has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "resize-images-before-upload" v1.8 plugin exhibits a generally strong security posture in terms of its attack surface and vulnerability history. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for attackers. Furthermore, the plugin has no recorded CVEs, indicating a history of good security practices or diligent patching by its developers. The use of prepared statements for all SQL queries is also a positive sign, mitigating risks associated with SQL injection vulnerabilities.
However, the static analysis reveals a critical concern: the use of the `create_function` dangerous function. This function is known to be insecure and can lead to arbitrary code execution if not handled with extreme care, especially if user-supplied input can influence its behavior. The low percentage of properly escaped output (13%) is also a notable weakness, posing a risk of Cross-Site Scripting (XSS) vulnerabilities, particularly if any of the outputs are user-controlled or display dynamic data.
In conclusion, while the plugin benefits from a small attack surface and a clean vulnerability history, the identified `create_function` usage and poor output escaping practices introduce significant risks. Developers should prioritize addressing these issues to enhance the plugin's security. The lack of explicit capability checks and nonce checks, while not flagged as an immediate risk due to the limited attack surface, could become a concern if new entry points are introduced in future versions.
Key Concerns
- Use of dangerous function: create_function
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Resize images before upload Security Vulnerabilities
Resize images before upload Code Analysis
Dangerous Functions Found
Output Escaping
Resize images before upload Attack Surface
WordPress Hooks 8
Maintenance & Trust
Resize images before upload Maintenance & Trust
Maintenance Signals
Community Trust
Resize images before upload Alternatives
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
shortpixel-image-optimiser
Optimize images & PDFs smartly. Create and compress next-gen WebP and AVIF formats. Smart crop and resize.
QODE Optimizer
qode-optimizer
The QODE Optimizer plugin is developed to allow you to convert, compress and adjust file sizes for all the images found on your website.
Compress, Resize & Lazy Load Images – WPvivid Image Optimization
wpvivid-imgoptim
Optimize, compress and resize images in WordPress in bulk. Lazy load images. Auto resize and optimize images upon upload.
Adaptive Images for WordPress
adaptive-images
Adaptive images plugin transparently resizes your images, per device screen size, in order to reduce download times in mobile environments.
Image Optimization For SEO
seo-image-optimizer
Image Optimization For Seo is the wordPress plugin. This plugin Resize and Compress the images to boost your site speed. It's also replaces the t …
Resize images before upload Developer Profile
1 plugin · 1K total installs
How We Detect Resize images before upload
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/resize-images-before-upload/js/source/resize.js/wp-content/plugins/resize-images-before-upload/js/source/resize.jsresize-images-before-upload/js/source/resize.js?ver=HTML / DOM Fingerprints
uploader