Sage Auto Upload Images Security & Risk Analysis

wordpress.org/plugins/sage-auto-upload-images

Automatically detect and import external images to your WordPress media library. Bulk process existing posts and prevent broken links.

10 active installs v1.0.0 PHP 7.4+ WP 3.8+ Updated Nov 1, 2025
bulk-importexternal-imagesimage-importimage-seomedia-library
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sage Auto Upload Images Safe to Use in 2026?

Generally Safe

Score 100/100

Sage Auto Upload Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "sage-auto-upload-images" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of direct attack surface points like AJAX handlers, REST API routes, and shortcodes, coupled with the complete lack of detected dangerous functions and raw SQL queries, indicates a robust development approach regarding input validation and data handling. Furthermore, the perfect scores for output escaping and the presence of nonce and capability checks are significant strengths, suggesting good practices are followed to prevent common web vulnerabilities.

However, the presence of file operations and external HTTP requests, while not inherently problematic, are areas that always warrant careful scrutiny in security. The static analysis did not reveal any specific vulnerabilities within these operations, but they represent potential avenues for attack if not meticulously secured. The plugin's clean vulnerability history with zero recorded CVEs further bolsters its perceived security. Overall, the plugin appears to be developed with security in mind, with no immediate critical flaws identified in the static analysis. The focus should remain on the careful implementation and continued security of the file operations and external HTTP requests.

Despite the positive findings, it's important to acknowledge that static analysis is not exhaustive. The identified strengths, such as 100% proper output escaping and the use of prepared statements, contribute to a good overall security score. The plugin's lack of known vulnerabilities also adds to its credibility. The primary areas to remain vigilant about are the single file operation and single external HTTP request, as these can be vectors for vulnerabilities if not handled with utmost care in their implementation.

Key Concerns

  • File operations detected
  • External HTTP requests detected
Vulnerabilities
None known

Sage Auto Upload Images Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sage Auto Upload Images Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
44 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped44 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
sauimg_bulk_process_page (sage-auto-upload-images.php:466)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sage Auto Upload Images Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initsage-auto-upload-images.php:126
actionadmin_menusage-auto-upload-images.php:138
actionadmin_noticessage-auto-upload-images.php:162
actionsave_postsage-auto-upload-images.php:244
actionadmin_enqueue_scriptssage-auto-upload-images.php:366
Maintenance & Trust

Sage Auto Upload Images Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 1, 2025
PHP min version7.4
Downloads211

Community Trust

Rating50/100
Number of ratings2
Active installs10
Developer Profile

Sage Auto Upload Images Developer Profile

Joseph Adediji

5 plugins · 190 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sage Auto Upload Images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sage-auto-upload-images/css/style.css/wp-content/plugins/sage-auto-upload-images/js/script.js
Script Paths
/wp-content/plugins/sage-auto-upload-images/js/script.js
Version Parameters
sage-auto-upload-images/css/style.css?ver=sage-auto-upload-images/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
sauimg_settings_groupsauimg-settingssauimg_main_sectionsauimg_excludesauimg_auto_featured_imagesauimg_skip_duplicates
HTML Comments
<!-- Sage Auto Upload Images Settings -->
Data Attributes
name="sauimg_settings[excluded_post_types][]"name="sauimg_settings[excluded_domains]"name="sauimg_settings[base_url]"name="sauimg_settings[filename_pattern]"name="sauimg_settings[alt_pattern]"name="sauimg_settings[max_width]"+5 more
FAQ

Frequently Asked Questions about Sage Auto Upload Images