Simple Thumbs Security & Risk Analysis

wordpress.org/plugins/simple-thumbs

Create image thumbs from WP attachments, w/ option to crop & fit to wanted size & create IMG-tags w/ correct width & height attributes.

10 active installs v0.4.1 PHP + WP 3.0+ Updated Unknown
gdimagephotosthumbnailsthumbs
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Thumbs Safe to Use in 2026?

Generally Safe

Score 100/100

Simple Thumbs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'simple-thumbs' plugin v0.4.1 exhibits a generally good security posture regarding its attack surface and SQL handling. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for attackers. Furthermore, all SQL queries are properly prepared, which is a strong defense against SQL injection vulnerabilities. The plugin also has no recorded vulnerabilities or CVEs, suggesting a history of stable and secure development.

Key Concerns

  • Zero output escaping
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Simple Thumbs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Thumbs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
7
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Simple Thumbs Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitindex.php:184
filterwpindex.php:185
filtergenerate_rewrite_rulesindex.php:186
filtertemplate_redirectindex.php:187
actionquery_varsindex.php:188
filterredirect_canonicalindex.php:189
filternocache_headersindex.php:190
filterimage_save_preindex.php:193
filteredit_attachmentindex.php:194
Maintenance & Trust

Simple Thumbs Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Simple Thumbs Developer Profile

Pär Thernström

11 plugins · 361K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
1680 days
View full developer profile
Detection Fingerprints

How We Detect Simple Thumbs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-thumbs/css/simple-thumbs.css/wp-content/plugins/simple-thumbs/js/simple-thumbs.js
Script Paths
/wp-content/plugins/simple-thumbs/js/simple-thumbs.js
Version Parameters
simple-thumbs/css/simple-thumbs.css?ver=simple-thumbs/js/simple-thumbs.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-simple-thumbs-auto-heightdata-simple-thumbs-auto-width
JS Globals
window.simple_thumbs_params
FAQ

Frequently Asked Questions about Simple Thumbs