SpeedSize Image & Video AI-Optimizer Security & Risk Analysis

wordpress.org/plugins/speedsize-ai-image-optimizer

SpeedSize Image & Video AI-Optimizer plugin allows you to easily use SpeedSize's Neuroscience Media Optimization on your WP website.

400 active installs v1.6.0 PHP 7.0+ WP 5.0+ Updated Sep 7, 2025
image-compressionimage-optimizationmedia-optimizationsite-speed-optimizationvideo-optimization
99
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 17, 2025
Download
Safety Verdict

Is SpeedSize Image & Video AI-Optimizer Safe to Use in 2026?

Generally Safe

Score 99/100

SpeedSize Image & Video AI-Optimizer has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 17, 2025Updated 6mo ago
Risk Assessment

The speedsize-ai-image-optimizer plugin v1.6.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries use prepared statements, and there are no identified taint flows with unsanitized paths. The plugin also correctly implements nonce checks and capability checks for its identified entry points, and there are no known unpatched vulnerabilities. This indicates a decent effort in basic security practices.

However, there are notable areas of concern. The limited output escaping (47%) is a significant weakness, suggesting a risk of Cross-Site Scripting (XSS) vulnerabilities in parts of the plugin's output. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful scrutiny as they can be exploited if not properly secured and validated. The plugin's vulnerability history, specifically a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability, also suggests a need for continued vigilance, even though it is currently patched.

Overall, the plugin has some good security foundations, but the poor output escaping and the historical CSRF issue present real risks. While no critical or high severity issues are currently identified in the static analysis or known unpatched vulnerabilities, the potential for XSS and the history of CSRF mean that careful auditing and ongoing monitoring are recommended.

Key Concerns

  • Insufficient output escaping
  • Past medium severity CSRF vulnerability
Vulnerabilities
1

SpeedSize Image & Video AI-Optimizer Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-13438medium · 4.3Cross-Site Request Forgery (CSRF)

SpeedSize Image & Video AI-Optimizer <= 1.5.1 - Cross-Site Request Forgery to Clear Cache

Feb 17, 2025 Patched in 1.5.2 (1d)
Code Analysis
Analyzed Mar 16, 2026

SpeedSize Image & Video AI-Optimizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
7 escaped
Nonce Checks
1
Capability Checks
2
File Operations
6
External Requests
3
Bundled Libraries
0

Output Escaping

47% escaped15 total outputs
Attack Surface

SpeedSize Image & Video AI-Optimizer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
filterwp_get_attachment_urlincludes\Processor.php:35
filterwp_get_attachment_image_srcincludes\Processor.php:36
filterwp_calculate_image_srcsetincludes\Processor.php:37
actionadmin_post_speedsize_clear_css_cacheincludes\Settings.php:183
actionplugins_loadedspeedsize.php:35
filterspeedsize_prefix_url_excludedspeedsize.php:101
actionadmin_initspeedsize.php:104
actionadmin_menuspeedsize.php:105
actionspeedsize_cron_clear_expired_css_cachespeedsize.php:107
actionwp_headersspeedsize.php:115
actionwp_headspeedsize.php:116
actionwp_footerspeedsize.php:120

Scheduled Events 2

speedsize_cron_clear_expired_css_cache
speedsize_cron_refresh_client_settings
Maintenance & Trust

SpeedSize Image & Video AI-Optimizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 7, 2025
PHP min version7.0
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs400
Developer Profile

SpeedSize Image & Video AI-Optimizer Developer Profile

speedsize

1 plugin · 400 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect SpeedSize Image & Video AI-Optimizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/speedsize-ai-image-optimizer/assets/css/speedsize.css/wp-content/plugins/speedsize-ai-image-optimizer/assets/js/speedsize.js
Script Paths
/wp-content/plugins/speedsize-ai-image-optimizer/assets/js/speedsize.js
Version Parameters
/wp-content/plugins/speedsize-ai-image-optimizer/assets/css/speedsize.css?ver=/wp-content/plugins/speedsize-ai-image-optimizer/assets/js/speedsize.js?ver=

HTML / DOM Fingerprints

CSS Classes
speedsize-main-wrapper
HTML Comments
SpeedSize Image & Video AI-Optimizer
Data Attributes
data-speedsize-plugin
JS Globals
speedsize_vars
FAQ

Frequently Asked Questions about SpeedSize Image & Video AI-Optimizer