Thumbnail Remover and Size Manager Security & Risk Analysis

wordpress.org/plugins/thumbnail-remover

Safely analyze, preview, trash, restore, regenerate, and manage WordPress thumbnails and image sizes.

50 active installs v2.0.0 PHP 7.4+ WP 5.0+ Updated Mar 14, 2026
cleanupimage-optimizationmedia-managementregenerate-thumbnailsthumbnails
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Thumbnail Remover and Size Manager Safe to Use in 2026?

Generally Safe

Score 100/100

Thumbnail Remover and Size Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 20d ago
Risk Assessment

The "thumbnail-remover" plugin v2.0.0 exhibits a strong security posture based on the provided static analysis. A notable strength is the complete absence of critical or high-severity vulnerabilities in its history, coupled with zero known CVEs. The code analysis reveals excellent security practices, including 100% utilization of prepared statements for all SQL queries, ensuring protection against SQL injection. All identified output operations are properly escaped, mitigating cross-site scripting (XSS) risks. Furthermore, the presence of nonce checks on all AJAX handlers and a capability check indicates a good understanding of WordPress security best practices for protecting against unauthorized actions. The plugin also demonstrates a clean approach by not bundling any third-party libraries and not making any external HTTP requests, reducing potential attack vectors. The taint analysis also found no unsanitized paths, reinforcing the confidence in the code's safety. The only area for slight improvement, though not a security risk in this specific analysis, is the presence of 9 file operations, which while not inherently dangerous, always represent a potential area for careful review in larger or more complex plugins to ensure they are absolutely necessary and handled securely. Overall, this plugin appears to be very well-developed from a security perspective, with no immediate or significant threats identified.

Vulnerabilities
None known

Thumbnail Remover and Size Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Thumbnail Remover and Size Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
0
45 escaped
Nonce Checks
10
Capability Checks
1
File Operations
9
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

100% escaped45 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
trpl_admin_page (thumbnail-remover.php:1316)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Thumbnail Remover and Size Manager Attack Surface

Entry Points9
Unprotected0

AJAX Handlers 9

authwp_ajax_trpl_preview_deletethumbnail-remover.php:951
authwp_ajax_trpl_start_analysisthumbnail-remover.php:967
authwp_ajax_trpl_process_analysisthumbnail-remover.php:999
authwp_ajax_trpl_start_deletethumbnail-remover.php:1017
authwp_ajax_trpl_process_deletethumbnail-remover.php:1048
authwp_ajax_trpl_restore_trashthumbnail-remover.php:1063
authwp_ajax_trpl_start_regeneratethumbnail-remover.php:1080
authwp_ajax_trpl_process_regeneratethumbnail-remover.php:1110
authwp_ajax_backup_imagesthumbnail-remover.php:1145
WordPress Hooks 6
actionadmin_enqueue_scriptsthumbnail-remover.php:37
actionadmin_enqueue_scriptsthumbnail-remover.php:72
actionplugins_loadedthumbnail-remover.php:77
actionadmin_menuthumbnail-remover.php:88
filterintermediate_image_sizes_advancedthumbnail-remover.php:894
filterintermediate_image_sizes_advancedthumbnail-remover.php:1194
Maintenance & Trust

Thumbnail Remover and Size Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Thumbnail Remover and Size Manager Developer Profile

Mehdi Rezaei

3 plugins · 60 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Thumbnail Remover and Size Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/thumbnail-remover/assets/css/style.css/wp-content/plugins/thumbnail-remover/assets/js/script.js
Version Parameters
thumbnail-remover/assets/css/style.css?ver=thumbnail-remover/assets/js/script.js?ver=

HTML / DOM Fingerprints

Data Attributes
thumbnailManager
JS Globals
thumbnailManager
FAQ

Frequently Asked Questions about Thumbnail Remover and Size Manager