
Image Quality Control | Still BE Security & Risk Analysis
wordpress.org/plugins/still-be-image-quality-controlBoost speed and Core Web Vitals with smart image optimization and auto WebP generation.
Is Image Quality Control | Still BE Safe to Use in 2026?
Generally Safe
Score 92/100Image Quality Control | Still BE has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'still-be-image-quality-control' v1.7.4 plugin presents a concerning security posture primarily due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in areas like SQL query sanitization using prepared statements and a lack of known vulnerabilities, the presence of six AJAX handlers, all of which lack authentication checks, represents a substantial attack surface. This means that any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure if the functionality within them is not robustly secured.
The static analysis shows no dangerous functions or critical taint flows, which is a positive indicator. However, the 57% rate of properly escaped output suggests that there might be instances where data displayed to users is not sufficiently sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities. The plugin also performs file operations and makes external HTTP requests, which, combined with unprotected AJAX endpoints, could be leveraged in more complex attack scenarios.
Given the absence of any recorded vulnerabilities or CVEs, it appears the plugin has a history of being secure. This could be attributed to diligent development or a low profile that hasn't attracted attackers. Nevertheless, the current static analysis highlights immediate risks related to the unprotected AJAX endpoints. The plugin's strengths lie in its SQL handling and historical security, but its weaknesses are glaringly apparent in its exposed AJAX functionality and potential for insufficient output escaping.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping rate
Image Quality Control | Still BE Security Vulnerabilities
Image Quality Control | Still BE Release Timeline
Image Quality Control | Still BE Code Analysis
Output Escaping
Image Quality Control | Still BE Attack Surface
AJAX Handlers 6
WordPress Hooks 72
Scheduled Events 2
Maintenance & Trust
Image Quality Control | Still BE Maintenance & Trust
Maintenance Signals
Community Trust
Image Quality Control | Still BE Alternatives
Imagify Image Optimization – Optimize Images | Compress Images | Convert WebP | Convert AVIF
imagify
Optimize images in 1‑click: compress, resize & convert to WebP/AVIF - free up to 20MB/month. Enjoy the easiest WordPress image optimizer to set up.
Smush – Image Optimization, Compression, Lazy Load, WebP & CDN
wp-smushit
Compress and optimize images, enable lazy load, serve WebP & AVIF, and speed up your site with a global image CDN.
Converter for Media – Optimize images | Convert WebP & AVIF
webp-converter-for-media
Speed up your website by using our WebP & AVIF Converter. Optimize images and serve WebP and AVIF images instead of standard formats!
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
shortpixel-image-optimiser
Optimize images & PDFs smartly. Create and compress next-gen WebP and AVIF formats. Smart crop and resize.
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
optimole-wp
Automatically optimize images: bulk compression, lazy loading, WebP/AVIF conversion. With CloudFront image CDN to boost Core Web Vitals & conversions!
Image Quality Control | Still BE Developer Profile
2 plugins · 1K total installs
How We Detect Image Quality Control | Still BE
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/still-be-image-quality-control/assets/css/style.css/wp-content/plugins/still-be-image-quality-control/assets/js/script.js/wp-content/plugins/still-be-image-quality-control/assets/js/script.jsstill-be-image-quality-control/assets/css/style.css?ver=still-be-image-quality-control/assets/js/script.js?ver=HTML / DOM Fingerprints
sb_imgq_params/wp-json/sb-imgq/v1/get-attachment-meta/wp-json/sb-imgq/v1/get-attachment-ids/wp-json/sb-imgq/v1/regenerate-images/wp-json/sb-imgq/v1/generate-test-image/wp-json/sb-imgq/v1/reset