
Simple Image Sizes Security & Risk Analysis
wordpress.org/plugins/simple-image-sizesThis plugin lets you create custom image sizes for your site. Override your theme sizes directly on the Media settings page, regenerate thumbnails, an …
Is Simple Image Sizes Safe to Use in 2026?
Generally Safe
Score 99/100Simple Image Sizes has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'simple-image-sizes' plugin version 3.2.4 exhibits a generally good security posture, with strong adherence to best practices in several key areas. The plugin demonstrates excellent output escaping, with 91% of outputs properly sanitized, and a low proportion of SQL queries using prepared statements (67%). Furthermore, the absence of file operations, external HTTP requests, and dangerous functions is a positive indicator. Taint analysis shows no critical or high severity flows with unsanitized paths, suggesting a low risk of immediate code execution vulnerabilities.
However, a significant concern arises from the presence of one unprotected AJAX handler. This creates a direct entry point for unauthenticated attackers, potentially leading to the exploitation of any vulnerabilities within that specific handler. While the plugin has a history of one medium severity CVE related to Cross-site Scripting, which was last seen in 2025, the fact that it's not marked as unpatched is reassuring. The history indicates that vulnerabilities of this type have been addressed in the past. The strengths lie in code sanitization and the absence of common web application attack vectors, but the unprotected AJAX handler represents a critical weakness that requires immediate attention.
Key Concerns
- Unprotected AJAX handler
Simple Image Sizes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Image Sizes <= 2.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Simple Image Sizes Release Timeline
Simple Image Sizes Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple Image Sizes Attack Surface
AJAX Handlers 7
WordPress Hooks 14
Maintenance & Trust
Simple Image Sizes Maintenance & Trust
Maintenance Signals
Community Trust
Simple Image Sizes Alternatives
WP Header Images
wp-header-images
A great WordPress plugin which helps you to choose a unique image for each menu page.
BF Advanced Images
bf-advanced-images
Create images on demand
custom blogger images
custom-blogger-images
Custom blogger images adds extra image sizes & golden ratio proportions to your Wordpress themes.
Imagify Image Optimization – Optimize Images | Compress Images | Convert WebP | Convert AVIF
imagify
Optimize images in 1‑click: compress, resize & convert to WebP/AVIF - free up to 20MB/month. Enjoy the easiest WordPress image optimizer to set up.
Smush – Image Optimization, Compression, Lazy Load, WebP & CDN
wp-smushit
Compress and optimize images, enable lazy load, serve WebP & AVIF, and speed up your site with a global image CDN.
Simple Image Sizes Developer Profile
5 plugins · 60K total installs
How We Detect Simple Image Sizes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-image-sizes/assets/dist/index.css/wp-content/plugins/simple-image-sizes/assets/dist/index.js/wp-content/plugins/simple-image-sizes/assets/dist/index.jssimple-image-sizes/assets/dist/index.css?ver=simple-image-sizes/assets/dist/index.js?ver=HTML / DOM Fingerprints
<!-- Javascript template for the admin media page -->sis