RoundIt plugin Security & Risk Analysis

wordpress.org/plugins/roundit

With RoundIt plugin you can set special effects to your pictures that you add in pages or posts. You can make your images Round, set Round Corners, ad …

200 active installs v1.0 PHP + WP 3.0.1+ Updated Sep 25, 2013
image-borderimage-effectsimage-shadowround-imagesrounded-corners
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RoundIt plugin Safe to Use in 2026?

Generally Safe

Score 85/100

RoundIt plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "roundit" v1.0 plugin exhibits a remarkably clean static analysis report. The absence of any detected attack surface points, dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or nonce/capability checks is a strong indicator of well-written and secure code, at least from a static analysis perspective. The 100% prepared statement usage for SQL and 100% output escaping are particularly commendable practices.

Furthermore, the plugin's vulnerability history is entirely clear, with no known CVEs, past or present. This suggests either a very well-maintained and tested plugin or a lack of widespread use, making it a less attractive target for attackers. The lack of any detected taint flows also reinforces the impression of secure coding practices.

While the data overwhelmingly points to a secure plugin, it's important to note that static analysis has limitations and doesn't capture all potential vulnerabilities, especially those related to logic flaws or environment-specific issues. However, based on the provided data, "roundit" v1.0 appears to have a very strong security posture.

Vulnerabilities
None known

RoundIt plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RoundIt plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

RoundIt plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterattachment_fields_to_editroundit.php:78
actionedit_attachmentroundit.php:119
filterimage_send_to_editorroundit.php:145
Maintenance & Trust

RoundIt plugin Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedSep 25, 2013
PHP min version
Downloads10K

Community Trust

Rating96/100
Number of ratings4
Active installs200
Developer Profile

RoundIt plugin Developer Profile

AspireSolution

4 plugins · 240 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RoundIt plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
data-setting="location"data-setting="border"
Shortcode Output
<input style="background-color:#BDFFBD;" type="text" id="attachments-name="attachments[]["location"]"]["border"]"
FAQ

Frequently Asked Questions about RoundIt plugin