Schema Default Image Security & Risk Analysis

wordpress.org/plugins/schema-default-image

Add ability to set a default Featured image for schema.org markup, an extension for the Schema plugin.

800 active installs v1.2.3 PHP + WP 4.0+ Updated Nov 21, 2023
default-imagejsonjson-ldschemaschema-org
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Schema Default Image Safe to Use in 2026?

Generally Safe

Score 85/100

Schema Default Image has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'schema-default-image' plugin v1.2.3 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events, particularly those lacking authentication or permission checks, indicates a very limited attack surface. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions, no raw SQL queries (all use prepared statements), and all outputs being properly escaped. The lack of file operations, external HTTP requests, and the absence of taint analysis findings further reinforce this good security standing.

The plugin's vulnerability history is also a significant positive, with zero known CVEs recorded. This suggests a history of secure development and maintenance, or perhaps a lack of focus from attackers due to its limited functionality and attack surface. The strengths of this plugin lie in its apparent simplicity and adherence to secure coding practices as indicated by the static analysis. There are no immediate red flags or specific risks identified within the provided data.

However, the most notable concern is the complete absence of nonce checks and capability checks. While the attack surface is currently zero, this indicates that if any new entry points were to be introduced in future versions without proper security controls, they would be immediately vulnerable. The plugin's current security relies heavily on its limited functionality, and a lack of these fundamental security checks could be problematic for future expansion. Overall, it's a very secure plugin in its current state, but the lack of built-in security primitives is a potential weakness.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Schema Default Image Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Schema Default Image Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Schema Default Image Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_initincludes\functions.php:12
filterschema_wp_cpt_enabledincludes\functions.php:48
filterschema_outputincludes\functions.php:92
filterschema_output_blog_postincludes\functions.php:93
filterschema_output_category_postincludes\functions.php:94
actionplugins_loadedschema-default-image.php:34
actionplugins_loadedschema-default-image.php:70
Maintenance & Trust

Schema Default Image Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedNov 21, 2023
PHP min version
Downloads25K

Community Trust

Rating100/100
Number of ratings5
Active installs800
Developer Profile

Schema Default Image Developer Profile

Hesham Zebida

8 plugins · 41K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Schema Default Image

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
id="_schema_default_image_id"
FAQ

Frequently Asked Questions about Schema Default Image