
reSmush.it : The original free image compressor and optimizer plugin Security & Risk Analysis
wordpress.org/plugins/resmushit-image-optimizerreSmush.it is the FREE image compressor and optimizer plugin - use it to optimize your images and improve the SEO and performance of your website.
Is reSmush.it : The original free image compressor and optimizer plugin Safe to Use in 2026?
Generally Safe
Score 98/100reSmush.it : The original free image compressor and optimizer plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The resmushit-image-optimizer plugin v1.0.4 exhibits a mixed security posture. On the positive side, the static analysis reveals good practices in several areas, including 100% of SQL queries using prepared statements, a high percentage (92%) of properly escaped output, and robust enforcement of nonce and capability checks on its eight AJAX handlers. Furthermore, the absence of critical or high severity taint analysis findings and the fact that there are currently no unpatched CVEs are encouraging indicators. However, the presence of the `unserialize` dangerous function is a significant concern, as it can be a vector for remote code execution if used with untrusted input. The plugin's vulnerability history, with three past CVEs including two high and one medium severity, highlights a pattern of past security weaknesses. These historical issues, particularly those involving CSRF, XSS, and missing authorization, suggest a need for ongoing vigilance in code review and security testing. While the current version shows improvements, the historical context and the presence of `unserialize` warrant a cautious approach.
Key Concerns
- Presence of dangerous function: unserialize
- 3 total known CVEs in vulnerability history
- 2 high severity CVEs in vulnerability history
- 1 medium severity CVE in vulnerability history
reSmush.it : The original free image compressor and optimizer plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
reSmush.it Image Optimizer <= 0.4.6 - Cross-Site Request Forgery
reSmush.it Image Optimizer <= 0.4.5 - Authenticated (Administrator+) Cross-Site Scripting
reSmush.it <= 0.4.3 - Missing Authorization
reSmush.it : The original free image compressor and optimizer plugin Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
reSmush.it : The original free image compressor and optimizer plugin Attack Surface
AJAX Handlers 8
WordPress Hooks 16
Scheduled Events 1
Maintenance & Trust
reSmush.it : The original free image compressor and optimizer plugin Maintenance & Trust
Maintenance Signals
Community Trust
reSmush.it : The original free image compressor and optimizer plugin Alternatives
ImagePilot – Save Money, Disk Space, and Bandwidth with Image Optimization
imagepilot
Optimize images automatically with zero quality loss. Optimize images, resize images, regenerate thumbnails, and much more.
Optimole – Optimize Images in Real Time
optimole-wp
Automatically optimize images: bulk compression, lazy loading, WebP/AVIF conversion. With CloudFront image CDN to boost Core Web Vitals & conversions!
Disable Bulk Smush Limit of Smush Image Optimization
wp-nonstop-smushit
Disable the bulk smush limit and unlock the premium bulk optimization feature of Smush Image Optimization — completely FREE! 🚀
WP Compress for MainWP
wp-compress-mainwp
Install, activate and connect WP Compress across all of your MainWP Child Sites.
Opti MozJpeg Guetzli WebP
opti-mozjpeg-guetzli-webp
WordPress Opti MozJpeg Guetzli WebP - is the FREE plugin for high quality image optimization in WordPress website. It was created to meet latest requi …
reSmush.it : The original free image compressor and optimizer plugin Developer Profile
8 plugins · 1.2M total installs
How We Detect reSmush.it : The original free image compressor and optimizer plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/resmushit-image-optimizer/resmushit.css/wp-content/plugins/resmushit-image-optimizer/resmushit.js/wp-content/plugins/resmushit-image-optimizer/resmushit.jsresmushit/style.css?ver=resmushit/script.js?ver=HTML / DOM Fingerprints
rsmt-notice<!-- Everything to do with AdminActions / WordPress -->data-csrfdata-dismissibledata-noticeRESMUSHIT_BASE_URL