SmallPict Security & Risk Analysis

wordpress.org/plugins/smallpict

Slow WordPress website? SmallPict automatically reduces image sizes to make your site faster — without complex settings.

0 active installs v1.1.7 PHP 7.4+ WP 5.8+ Updated Mar 4, 2026
avifcompressionimage-optimizationspeedwebp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SmallPict Safe to Use in 2026?

Generally Safe

Score 100/100

SmallPict has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of "smallpict" v1.1.7 reveals a generally strong security posture. The plugin demonstrates excellent practices by having no direct SQL queries, with all (0) queries using prepared statements, and all outputs being properly escaped. The absence of a large attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the potential for exploitation. File operations and external HTTP requests are present but are not inherently indicative of risk without further context on their implementation and sanitization.

Concerns arise from the lack of any detected nonce checks and only one capability check across all entry points, which are also absent. This means that if any entry points were to be introduced or discovered in the future, they would likely be unprotected, presenting a significant risk. The taint analysis showing zero flows, combined with no recorded CVEs, suggests a history of secure development or a lack of deep scrutiny. However, the absence of vulnerability history doesn't guarantee future security. The plugin's strengths lie in its clean handling of SQL and output, but the lack of robust authentication/authorization checks on potential future entry points is a notable weakness.

Key Concerns

  • No nonce checks detected
  • Only 1 capability check
Vulnerabilities
None known

SmallPict Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SmallPict Release Timeline

v1.1.7Current
v1.1.6
Code Analysis
Analyzed Mar 17, 2026

SmallPict Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
44 escaped
Nonce Checks
0
Capability Checks
1
File Operations
5
External Requests
5
Bundled Libraries
0

Output Escaping

100% escaped44 total outputs
Attack Surface

SmallPict Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionadmin_menuincludes\class-settings.php:9
actionadmin_initincludes\class-settings.php:10
actionadmin_enqueue_scriptsincludes\class-settings.php:11
actionadmin_menuincludes\class-smallpict-core.php:52
actionadmin_initincludes\class-smallpict-core.php:53
actionadmin_enqueue_scriptsincludes\class-smallpict-core.php:55
filterwp_handle_uploadincludes\class-smallpict-core.php:78
actionadmin_menusmallpict.php:158
actionadmin_initsmallpict.php:159
actionadmin_noticessmallpict.php:160
filterwp_prepare_attachment_for_jssmallpict.php:163
actionadmin_enqueue_scriptssmallpict.php:164
filterwp_generate_attachment_metadatasmallpict.php:167
actionadmin_initsmallpict.php:175
filterbig_image_size_thresholdsmallpict.php:268
filterupload_size_limitsmallpict.php:275
filterintermediate_image_sizes_advancedsmallpict.php:286
Maintenance & Trust

SmallPict Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.4
Downloads198

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SmallPict Developer Profile

c0redump

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SmallPict

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smallpict/assets/css/admin.css/wp-content/plugins/smallpict/assets/js/admin.js
Script Paths
/wp-content/plugins/smallpict/assets/js/admin.js
Version Parameters
smallpict/assets/css/admin.css?ver=smallpict/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
smallpict-ajax-notice
JS Globals
smallpict_ajax
FAQ

Frequently Asked Questions about SmallPict