Slug for attached posts by image galleries Security & Risk Analysis

wordpress.org/plugins/slug4apig

The Slug4apig plugin allows WP users to edit the SEO friendly URL (aka slug) for the autogenerated attachment posts created by the built WP gallery.

20 active installs v1.0 PHP + WP 2.5+ Updated Mar 17, 2011
friendly-urlseoslug
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Slug for attached posts by image galleries Safe to Use in 2026?

Generally Safe

Score 85/100

Slug for attached posts by image galleries has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The plugin 'slug4apig' v1.0 demonstrates an exceptionally strong security posture based on the provided static analysis. The complete absence of any identified attack surface points, such as unprotected AJAX handlers, REST API routes, shortcodes, or cron events, significantly minimizes the potential for unauthorized access or malicious manipulation. Furthermore, the code exhibits excellent security practices, with no dangerous functions detected, all SQL queries utilizing prepared statements, and 100% of outputs being properly escaped. The lack of file operations and external HTTP requests further reduces the plugin's attackable footprint. The vulnerability history is also clean, with no known CVEs or recorded past vulnerabilities, suggesting a proactive approach to security or a lack of prior exploitation. This plugin appears to be very secure. However, the complete lack of certain security checks, such as nonce and capability checks, while not a direct issue given the absence of an attack surface, could become a concern if the plugin's functionality were to expand in the future and introduce new entry points without corresponding security measures. Currently, this is not a risk, but a potential area for future vigilance.

Vulnerabilities
None known

Slug for attached posts by image galleries Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Slug for attached posts by image galleries Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Slug for attached posts by image galleries Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterattachment_fields_to_editSlug4apig.php:37
filterattachment_fields_to_saveSlug4apig.php:49
Maintenance & Trust

Slug for attached posts by image galleries Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedMar 17, 2011
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Slug for attached posts by image galleries Developer Profile

clapas

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Slug for attached posts by image galleries

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
[rt_carousel]
FAQ

Frequently Asked Questions about Slug for attached posts by image galleries