
Scissors and Watermark Security & Risk Analysis
wordpress.org/plugins/scissors-watermarkScissors and Watermark enhances WordPress' handling of images by introducing cropping, resizing, rotating, and watermarking functionality.
Is Scissors and Watermark Safe to Use in 2026?
Generally Safe
Score 85/100Scissors and Watermark has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "scissors-watermark" v3.2.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and does not make external HTTP requests. The absence of known vulnerabilities (CVEs) in its history is also a positive indicator of its historical stability. However, significant concerns arise from the static analysis. The plugin has four AJAX handlers, all of which lack authentication checks, creating a substantial attack surface that could be exploited by unauthenticated users. Furthermore, the taint analysis revealed one flow with unsanitized paths, categorized as high severity, which could potentially lead to code injection or other serious vulnerabilities. While the plugin uses nonces and capability checks on some entry points, the lack of these on the majority of its AJAX handlers is a critical oversight.
Considering the high number of unprotected AJAX entry points and the presence of a high-severity taint flow, the plugin's security is compromised. The lack of historical vulnerabilities might be due to the plugin's relatively simple functionality or perhaps a lack of rigorous security auditing in the past. Nevertheless, the identified weaknesses are immediate risks that require attention. The plugin has the potential to be a secure solution, but the current implementation of its AJAX handlers and the identified taint flow represent considerable security risks that must be addressed to improve its overall security posture.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized path taint flow
- Low percentage of properly escaped output
Scissors and Watermark Security Vulnerabilities
Scissors and Watermark Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Scissors and Watermark Attack Surface
AJAX Handlers 4
WordPress Hooks 17
Maintenance & Trust
Scissors and Watermark Maintenance & Trust
Maintenance Signals
Community Trust
Scissors and Watermark Alternatives
Polaroid Gallery
polaroid-gallery
Polaroid Gallery is a CSS3 & jQuery Image Gallery plugin for WordPress Media Library.
NextCellent Media Library Addon
nextcellent-gallery-media-addon
This plugin adds a feature to NextCellent Gallery to add an image from the WP Media Library.
QBank Connector
qbank-dam-connector
Gain access to all your files in QBank that you can publish directly from Wordpress without leaving their interface.
AWSOM Pixgallery
awsom-pixgallery
AWSOM Pixgallery is an Image Gallery/Archive plugin for Wordpress designed to make it easier for Artists or Webcomic creators to set up a portfolio of …
real.PostImages
real-postimages
Дополнительное поле записей (постов) для изображений. | English read below
Scissors and Watermark Developer Profile
2 plugins · 700 total installs
How We Detect Scissors and Watermark
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scissors-watermark/js/scissors.js/wp-content/plugins/scissors-watermark/css/scissors.css/wp-content/plugins/scissors-watermark/js/scissors.jsscissors-watermark/js/scissors.js?ver=scissors-watermark/css/scissors.css?ver=HTML / DOM Fingerprints
<!-- TinyMCE -->data-editor="tinymce"scissors