
WAJ Image Security & Risk Analysis
wordpress.org/plugins/waj-imageSimple classes & shortcodes for easy image HTML generation from common image directories.
Is WAJ Image Safe to Use in 2026?
Generally Safe
Score 85/100WAJ Image has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "waj-image" v3.0.0 plugin exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and unescaped output are significant strengths. Furthermore, the lack of external HTTP requests and file operations reduces the potential for certain types of remote code execution or data leakage. The vulnerability history shows no known CVEs, which is a positive indicator of the plugin's stability.
However, a notable concern is the complete absence of nonce checks and capability checks. While the current attack surface (shortcodes) doesn't immediately expose unprotected entry points, this fundamental lack of security controls means that any future addition of AJAX handlers, REST API routes, or modifications to shortcode functionality could introduce severe vulnerabilities if not carefully secured. The taint analysis showing zero flows, while good, might also be a result of limited complexity or a small attack surface being analyzed, rather than a guarantee of perfect sanitization in all contexts.
In conclusion, "waj-image" v3.0.0 has a solid foundation with good coding practices in place for SQL and output sanitization. The absence of past vulnerabilities is also encouraging. The primary weakness lies in the omission of essential WordPress security mechanisms like nonces and capability checks, which represent a latent risk that should be addressed proactively, especially if the plugin's functionality or attack surface expands in the future.
Key Concerns
- Missing nonce checks
- Missing capability checks
WAJ Image Security Vulnerabilities
WAJ Image Release Timeline
WAJ Image Code Analysis
Output Escaping
WAJ Image Attack Surface
Shortcodes 7
Maintenance & Trust
WAJ Image Maintenance & Trust
Maintenance Signals
Community Trust
WAJ Image Alternatives
WAJ Image Slider
waj-image-slider
Plugin that creates shortcode for easy creation o' image sliders.
Image Uploader for Welcart
image-uploader-for-welcart
Create metabox with image uploader for ‘Welcart e-Commerce’. It allows user to upload and sort images directory from each edit page.
Delete Unscaled Images
delete-unscaled-images
Deletes original image files if they have been resized
My Upload Images
my-upload-images
Create metabox with media uploader. It allows to upload and sort images in any post_type.
Dynamic Image Resizer
dynamic-image-resizer
Make your images change sizes dynamically.
WAJ Image Developer Profile
6 plugins · 20 total installs
How We Detect WAJ Image
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- WAJ: No fallback info to give, so just return nothing. --><!-- WAJ: Since shortcodes should be mo’ user-friendly, we don’t want any website-breaking exceptions getting through. -->data-waj-image-srcdata-waj-image-extdata-waj-image-sizesdata-waj-picture-srcdata-waj-picture-extdata-waj-picture-sizes[thumbnail][theme-image][upload-image][image]