Show Featured Thumbnails Security & Risk Analysis
wordpress.org/plugins/show-featured-thumbnailsAdds a featured image thumbnail column to the Posts and Pages list screens, and allows assigning an image directly from the list if none exists.
Is Show Featured Thumbnails Safe to Use in 2026?
Generally Safe
Score 100/100Show Featured Thumbnails has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "show-featured-thumbnails" plugin version 1.0.0 exhibits a mixed security posture. On the positive side, the code demonstrates good practices by utilizing prepared statements for all SQL queries, having no recorded vulnerabilities (CVEs), and performing capability checks on one of its entry points. The absence of file operations, external HTTP requests, and bundled libraries further reduces potential attack vectors.
However, a significant concern arises from the presence of one AJAX handler that lacks authentication checks. This creates a direct entry point that any unauthenticated user could potentially exploit. While taint analysis and output escaping metrics are not fully detailed, the overall lack of critical or high-severity code signals is reassuring. The plugin's clean vulnerability history is a strong indicator of past security diligence.
In conclusion, while the plugin's foundation appears solid with secure SQL practices and a clean history, the unprotected AJAX handler represents a clear and present risk that requires immediate attention. Addressing this single unprotected entry point would significantly improve the plugin's security.
Key Concerns
- Unprotected AJAX handler
Show Featured Thumbnails Security Vulnerabilities
Show Featured Thumbnails Code Analysis
Output Escaping
Show Featured Thumbnails Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Show Featured Thumbnails Maintenance & Trust
Maintenance Signals
Community Trust
Show Featured Thumbnails Alternatives
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
Media Deduper
media-deduper
Save disk space and bring some order to the chaos of your media library by removing and preventing duplicate files.
Admin Taxonomy Filter
admin-taxonomy-filter
Filter posts or custom post types in the admin area by custom taxonomies.
WEN Featured Image
wen-featured-image
Add featured image column in listings. Add/change/remove featured image directly from the listing page
Post Lists View Custom
post-lists-view-custom
Customize the list of the post and page and the custom post type.
Show Featured Thumbnails Developer Profile
1 plugin · 0 total installs
How We Detect Show Featured Thumbnails
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/show-featured-thumbnails/css/admin-style.css/wp-content/plugins/show-featured-thumbnails/js/admin-script.js/wp-content/plugins/show-featured-thumbnails/js/admin-script.jsshow-featured-thumbnails/css/admin-style.css?ver=show-featured-thumbnails/js/admin-script.js?ver=HTML / DOM Fingerprints
showfeth-upload-featureddata-post-idshowfethData