Web Screenshort Security & Risk Analysis

wordpress.org/plugins/web-screenshort

This plugin allows any WordPress user to easily add thumbnail previews This plugin using webthumbnail.org api

10 active installs v1.0 PHP + WP 3.9+ Updated Aug 7, 2014
mshotspagepixshrink-the-websnapshotstw
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Web Screenshort Safe to Use in 2026?

Generally Safe

Score 85/100

Web Screenshort has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'web-screenshort' v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates adherence to secure coding practices by avoiding the use of dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerability history. The absence of external HTTP requests and file operations also reduces its attack surface. However, a significant concern lies in the lack of output escaping for all identified outputs. This means that data displayed to users might not be properly sanitized, potentially opening the door to cross-site scripting (XSS) vulnerabilities if user-controlled data is ever rendered directly. The lack of nonce and capability checks, while currently not presenting an immediate threat due to the minimal entry points, is a concerning omission for robust security.

Key Concerns

  • All outputs are unescaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Web Screenshort Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Web Screenshort Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Web Screenshort Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Web Screenshort Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[web-screenshort] wp-screenshort.php:31
WordPress Hooks 5
actionadmin_headwp-screenshort.php:34
filtermce_external_pluginswp-screenshort.php:42
filtermce_buttonswp-screenshort.php:44
actionadmin_enqueue_scriptswp-screenshort.php:71
actionadmin_menuwp-screenshort.php:85
Maintenance & Trust

Web Screenshort Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedAug 7, 2014
PHP min version
Downloads2K

Community Trust

Rating54/100
Number of ratings3
Active installs10
Developer Profile

Web Screenshort Developer Profile

aijazsiddique

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Web Screenshort

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/web-screenshort/js/plugin.js/wp-content/plugins/web-screenshort/css/web-screenshort-icon.css/wp-content/plugins/web-screenshort/css/web-screenshort.css
Script Paths
/wp-content/plugins/web-screenshort/js/plugin.js

HTML / DOM Fingerprints

HTML Comments
<!-- Aijaz an exprience Wordpress Developer -->
Shortcode Output
<img src="http://api.webthumbnail.org?width=
FAQ

Frequently Asked Questions about Web Screenshort