
Webdoone Simple Image Widget Security & Risk Analysis
wordpress.org/plugins/webdoone-simple-image-widgetA simpe and easy way to place an image in your any widget area.
Is Webdoone Simple Image Widget Safe to Use in 2026?
Generally Safe
Score 85/100Webdoone Simple Image Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The webdoone-simple-image-widget plugin, version 1.1.2, exhibits a generally good security posture with no recorded vulnerabilities in its history and a low attack surface. The static analysis reveals a significant strength in its handling of SQL queries, with 100% using prepared statements, and a high rate of output escaping (94%). The absence of file operations and external HTTP requests further mitigates common attack vectors. However, a single instance of the `create_function` dangerous function is a notable concern, as it can be exploited for code injection if user input is not strictly controlled. The complete lack of nonce and capability checks, while not directly leading to exploitable flows in the taint analysis, represents a missed opportunity for robust authentication and authorization on potential entry points.
Despite the absence of known CVEs and a clean vulnerability history, the presence of `create_function` warrants attention. The zero taint flows are positive but could be a result of limited test coverage rather than inherent security. The lack of authentication checks on any potential entry points is a structural weakness that could become exploitable if new entry points are introduced or if the `create_function`'s usage is compromised by uncontrolled input. Overall, while the plugin is currently safe based on historical data and static analysis, the use of `create_function` and the absence of authorization mechanisms present minor but real risks.
Key Concerns
- Use of dangerous function 'create_function'
- No nonce checks on entry points
- No capability checks on entry points
- Low percentage of output escaping (94%)
Webdoone Simple Image Widget Security Vulnerabilities
Webdoone Simple Image Widget Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Webdoone Simple Image Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
Webdoone Simple Image Widget Maintenance & Trust
Maintenance Signals
Community Trust
Webdoone Simple Image Widget Alternatives
Simple Image Widget
simple-image-widget
A simple widget that makes it a breeze to add images to your sidebars.
Image Widget
image-widget-rb
Image Widget - most simple and fast way to create image widget to your sidebar
Swifty Image Widget
swifty-image-widget
Super simple but powerful widget that allows adding single or multiple images to your widget positions, using native media uploader.
Image Widget by Angie Makes
wpc-image-widget
This plugin allows for the addition of a drag / drop image widget to the existing widgets in your Wordpress theme. Easily upload, and link images to t …
The Image Widget
ci-image-widget
A simple image widget that allows you to display an image in any sidebar. The image can either link to another page or it can pop out in a lightbox.
Webdoone Simple Image Widget Developer Profile
1 plugin · 70 total installs
How We Detect Webdoone Simple Image Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webdoone-simple-image-widget/css/style.css/wp-content/plugins/webdoone-simple-image-widget/js/webdoone-simple-image-widget.js/wp-content/plugins/webdoone-simple-image-widget/css/webdoone-simple-image-widget.css/wp-content/plugins/webdoone-simple-image-widget/js/webdoone-simple-image-widget.jswebdoone-simple-image-widget/css/style.css?ver=webdoone-simple-image-widget/js/webdoone-simple-image-widget.js?ver=HTML / DOM Fingerprints
webdoonesimpleimage_widgetwebdoone-si-custom-media-imgwebdoone-si-custom-media-urlwebdoone-si-custom-media-uploadwebdoone-si-clear-fieldwebdoone-si-custom-media-imgwebdoone-si-custom-media-urlwebdoone-si-custom-media-uploadwebdoone-si-clear-field