Theme Blvd Image Sizes Security & Risk Analysis

wordpress.org/plugins/theme-blvd-image-sizes

When using a theme with Theme Blvd Framework version 2.2+, this plugin allows you to change your theme's image sizes.

70 active installs v1.1.1 PHP + WP + Updated Sep 7, 2015
add_image_sizecropimagesthemeblvd
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Theme Blvd Image Sizes Safe to Use in 2026?

Generally Safe

Score 85/100

Theme Blvd Image Sizes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The static analysis of "theme-blvd-image-sizes" v1.1.1 reveals a seemingly strong security posture with no identified attack surface, dangerous functions, or external HTTP requests. The absence of SQL queries not using prepared statements and no taint flows with unsanitized paths are positive indicators. However, a significant concern arises from the complete lack of output escaping for the two identified outputs. This suggests that user-supplied data, if it were to reach these output points, could be rendered directly into the browser without sanitization, posing a Cross-Site Scripting (XSS) risk.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the lack of identified attack vectors in static analysis, might imply a generally secure codebase. Nevertheless, the unescaped outputs are a critical oversight that could be exploited. The total absence of nonce and capability checks, while not directly exploitable given the zero attack surface, indicates a lack of robust security best practices that could become a liability if the attack surface were to change in future versions or through other vulnerabilities.

In conclusion, while the plugin has a clean vulnerability record and a minimal attack surface, the unescaped output is a direct and concerning security flaw. The lack of authorization checks, though not immediately exploitable, points to potential weaknesses in future development. Prioritizing the fixing of unescaped outputs is crucial for immediate risk mitigation.

Key Concerns

  • Unescaped output detected
  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

Theme Blvd Image Sizes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Theme Blvd Image Sizes Release Timeline

v1.1.1Current
v1.1.0
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Theme Blvd Image Sizes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Theme Blvd Image Sizes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitthemeblvd-image-sizes.php:40
actionadmin_noticesthemeblvd-image-sizes.php:198
actionthemeblvd_admin_module_headerthemeblvd-image-sizes.php:218
actioninitthemeblvd-image-sizes.php:221
filterthemeblvd_image_sizesthemeblvd-image-sizes.php:352
Maintenance & Trust

Theme Blvd Image Sizes Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedSep 7, 2015
PHP min version
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Theme Blvd Image Sizes Developer Profile

Jason

23 plugins · 8K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
3363 days
View full developer profile
Detection Fingerprints

How We Detect Theme Blvd Image Sizes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/theme-blvd-image-sizes/css/theme-blvd-image-sizes.css/wp-content/plugins/theme-blvd-image-sizes/js/theme-blvd-image-sizes.js
Script Paths
/wp-content/plugins/theme-blvd-image-sizes/js/theme-blvd-image-sizes.js
Version Parameters
theme-blvd-image-sizes/css/theme-blvd-image-sizes.css?ver=theme-blvd-image-sizes/js/theme-blvd-image-sizes.js?ver=

HTML / DOM Fingerprints

CSS Classes
show-hide-toggletriggerhidereceiverreceiver-custom
HTML Comments
Copyright 2015 JASON BOBICHThis program is free software; you can redistribute it and/or modifyunder the terms of the GNU General Public License, version 2, aspublished by the Free Software Foundation.+10 more
Data Attributes
data-tb-id='tb_image_sizes'
JS Globals
window.Theme_Blvd_Options_Page
FAQ

Frequently Asked Questions about Theme Blvd Image Sizes