RICG Responsive Images Security & Risk Analysis

wordpress.org/plugins/ricg-responsive-images

Bringing automatic default responsive images to WordPress.

2K active installs v3.1.1 PHP + WP 4.0+ Updated Nov 28, 2017
imagespicturefillresponsiveresponsive-imagessrcset
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RICG Responsive Images Safe to Use in 2026?

Generally Safe

Score 85/100

RICG Responsive Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "ricg-responsive-images" v3.1.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified entry points such as AJAX handlers, REST API routes, or shortcodes significantly limits the potential attack surface. Furthermore, the code demonstrates excellent practices by utilizing prepared statements for all SQL queries and properly escaping all output, leaving no room for common injection vulnerabilities. The lack of file operations and external HTTP requests also contributes to its robustness.

The vulnerability history is equally impressive, with zero recorded CVEs of any severity. This suggests a consistently well-maintained and secure codebase over its development history. The taint analysis also shows no critical or high severity flows, reinforcing the confidence in the code's sanitization and security controls. While the plugin lacks explicit nonce and capability checks, this is mitigated by the minimal attack surface. The overall security is excellent, with no immediate or apparent risks identified within the provided data.

Vulnerabilities
None known

RICG Responsive Images Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RICG Responsive Images Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped14 total outputs
Attack Surface

RICG Responsive Images Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterthe_contentwp-tevko-core-functions.php:372
filterwp_get_attachment_image_attributeswp-tevko-core-functions.php:490
filterwp_calculate_image_sizeswp-tevko-deprecated-functions.php:317
filterthe_contentwp-tevko-deprecated-functions.php:381
filterwp_calculate_image_sizeswp-tevko-deprecated-functions.php:414
filterwp_image_editorswp-tevko-responsive-images.php:43
actionwp_enqueue_scriptswp-tevko-responsive-images.php:61
Maintenance & Trust

RICG Responsive Images Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedNov 28, 2017
PHP min version
Downloads155K

Community Trust

Rating94/100
Number of ratings20
Active installs2K
Developer Profile

RICG Responsive Images Developer Profile

tevko

1 plugin · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RICG Responsive Images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ricg-responsive-images/js/picturefill.min.js
Script Paths
js/picturefill.min.js
Version Parameters
picturefill.min.js?ver=/wp-content/plugins/ricg-responsive-images/js/picturefill.min.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Filter to add 'srcset' and 'sizes' attributes to post thumbnails and gallery images. --><!-- The filter is added to the hook in wp-tevko-core-functions.php because --><!-- it is only needed on a version of WordPress previous to 4.4. --><!-- WordPress Respimg Imagick Image Editor -->+9 more
FAQ

Frequently Asked Questions about RICG Responsive Images