
Show Featured Image Size in Admin TopBar Security & Risk Analysis
wordpress.org/plugins/show-featured-image-size-in-admin-topbarThis plugin displays the image size for the featured image size in the admin top bar.
Is Show Featured Image Size in Admin TopBar Safe to Use in 2026?
Generally Safe
Score 85/100Show Featured Image Size in Admin TopBar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "show-featured-image-size-in-admin-topbar" version 1.2 exhibits a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that could serve as entry points, and critically, none of these potential entry points are unprotected. The code also avoids dangerous functions, performs file operations, and makes external HTTP requests, and all SQL queries utilize prepared statements. This indicates a deliberate effort to minimize the attack surface and adhere to secure coding practices.
However, a notable concern arises from the output escaping. With only 33% of output properly escaped, there's a significant risk of Cross-Site Scripting (XSS) vulnerabilities. If any of the unescaped outputs display user-supplied or dynamic data, an attacker could potentially inject malicious scripts. The absence of any identified taint flows, while seemingly positive, might also suggest that the taint analysis was not comprehensive or that the plugin's functionality is very limited, thus not exposing complex data flow paths.
The plugin's vulnerability history is clean, with no known CVEs. This, combined with the lack of identified vulnerabilities in the code analysis, paints a picture of a plugin that has historically been secure. However, the lack of explicit capability checks and nonce checks, coupled with the poor output escaping, means that future vulnerabilities could easily be introduced if the plugin's functionality expands or if the current limited functionality interacts with dynamic data in unexpected ways. Overall, while the plugin has a good foundation, the output escaping issue presents a tangible and immediate risk that should be addressed.
Key Concerns
- Poor output escaping (67% unescaped)
- No capability checks implemented
- No nonce checks implemented
Show Featured Image Size in Admin TopBar Security Vulnerabilities
Show Featured Image Size in Admin TopBar Release Timeline
Show Featured Image Size in Admin TopBar Code Analysis
Output Escaping
Show Featured Image Size in Admin TopBar Attack Surface
WordPress Hooks 5
Maintenance & Trust
Show Featured Image Size in Admin TopBar Maintenance & Trust
Maintenance Signals
Community Trust
Show Featured Image Size in Admin TopBar Alternatives
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
wp-maintenance-mode
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
Adminimize
adminimize
Adminimize that lets you hide 'unnecessary' items from the WordPress backend
Remove Dashboard Access
remove-dashboard-access-for-non-admins
Disable Dashboard access for users of a specific role or capability. Disallowed users are redirected to a chosen URL. Get set up in seconds.
Error Log Monitor
error-log-monitor
Adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send logged errors to email.
Automatic Domain Changer
automatic-domain-changer
Automatically detects a domain name change, and updates all the WordPress tables in the database to reflect this change.
Show Featured Image Size in Admin TopBar Developer Profile
28 plugins · 60K total installs
How We Detect Show Featured Image Size in Admin TopBar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
featured-image-size-admin-topbarid="sfisiat_featured_image_size"name="sfisiat_featured_image_size"