Sky Remove Attached Files And Featured Images Automatically Security & Risk Analysis

wordpress.org/plugins/sky-remove-attached-files-and-featured-images-automatically

Automatically eliminate attached media from posts and featured images uploaded via Media button.

10 active installs v1.0.0 PHP + WP 3.3+ Updated Dec 30, 2015
autodelete-featured-imagesimagespostposts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sky Remove Attached Files And Featured Images Automatically Safe to Use in 2026?

Generally Safe

Score 85/100

Sky Remove Attached Files And Featured Images Automatically has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "sky-remove-attached-files-and-featured-images-automatically" plugin v1.0.0 exhibits a generally good security posture with no critical or high-risk findings. The absence of any recorded vulnerabilities or CVEs, coupled with the code signals indicating proper output escaping and no dangerous functions, suggests diligent development practices in these areas. The lack of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, and importantly, all identified entry points (though zero) would have been protected. This suggests a minimal exposure to common web vulnerabilities.

However, there are a few areas that warrant attention. The presence of SQL queries without prepared statements is a significant concern, as this can open the door to SQL injection vulnerabilities, especially if user input is incorporated into these queries. While the taint analysis shows no unsanitized paths, the potential for SQL injection exists with the un-prepared queries. Furthermore, the absence of nonce checks and capability checks on any potential entry points, though the static analysis reports zero, is a general good practice that is missing in the reported signals. This indicates a potential weakness if new entry points are added or if the static analysis did not cover all possible interaction vectors.

In conclusion, the plugin appears to be robust against common web attacks due to its limited attack surface and strong output escaping. The lack of historical vulnerabilities is a positive indicator. Nevertheless, the use of raw SQL queries without prepared statements presents a notable risk that should be addressed to further enhance the plugin's security. Implementing prepared statements for all SQL queries is the most critical next step for improving its security.

Key Concerns

  • SQL queries without prepared statements
Vulnerabilities
None known

Sky Remove Attached Files And Featured Images Automatically Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Sky Remove Attached Files And Featured Images Automatically Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared3 total queries
Attack Surface

Sky Remove Attached Files And Featured Images Automatically Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionbefore_delete_postsky-remove-attached-files-and-featured-images-automatically.php:27
actionbefore_delete_postsky-remove-attached-files-and-featured-images-automatically.php:28
Maintenance & Trust

Sky Remove Attached Files And Featured Images Automatically Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedDec 30, 2015
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Sky Remove Attached Files And Featured Images Automatically Developer Profile

KENT HDD

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sky Remove Attached Files And Featured Images Automatically

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Sky Remove Attached Files And Featured Images Automatically