WP-Choose-Thumb Security & Risk Analysis
wordpress.org/plugins/wp-choose-thumbA simple way to add a default thumbnail to your post.
Is WP-Choose-Thumb Safe to Use in 2026?
Generally Safe
Score 85/100WP-Choose-Thumb has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-choose-thumb v1.3.6 plugin exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerability history (CVEs). The absence of shortcodes, cron events, and REST API routes, along with a low attack surface count of AJAX handlers, suggests a limited external exposure. However, significant concerns arise from the static analysis. The presence of the `create_function` dangerous function is a critical red flag, as it can be exploited for code injection. Furthermore, a complete lack of output escaping (0% properly escaped) across 14 identified outputs is a serious vulnerability, opening the door to Cross-Site Scripting (XSS) attacks. The taint analysis revealing two flows with unsanitized paths, though not classified as critical or high, warrants investigation in conjunction with the unescaped outputs. The lack of nonce checks and capability checks also contributes to potential security weaknesses, especially if the identified unsanitized paths can be triggered by unauthenticated users.
Key Concerns
- Dangerous function: create_function
- Output escaping: 0% properly escaped
- Taint analysis: Unsanitized paths found
- Nonce checks: Missing
- Capability checks: Missing
WP-Choose-Thumb Security Vulnerabilities
WP-Choose-Thumb Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WP-Choose-Thumb Attack Surface
WordPress Hooks 7
Maintenance & Trust
WP-Choose-Thumb Maintenance & Trust
Maintenance Signals
Community Trust
WP-Choose-Thumb Alternatives
Fix Media Library
wow-media-library-fix
Fix Media Library inconsistency between database and wp-content/uploads folder contents. Unused image files, broken media library entries, missing att …
Recent Post Lazy Load
recent-post-lazy-load
Easy and fast load plugin to display in the sidebar a list of linked titles and thumbnails of the most recent postings through shortcodes etc.
Simple Thumbs
simple-thumbs
Create image thumbs from WP attachments, w/ option to crop & fit to wanted size & create IMG-tags w/ correct width & height attributes.
Regenerate Thumbnails
regenerate-thumbnails
Regenerate the thumbnails for one or more of your image uploads. Useful when changing their sizes or your theme.
Force Regenerate Thumbnails
force-regenerate-thumbnails
Delete and REALLY force thumbnail regeneration.
WP-Choose-Thumb Developer Profile
4 plugins · 6K total installs
How We Detect WP-Choose-Thumb
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-choose-thumb/resources/images/ajax-loader.gifHTML / DOM Fingerprints
wct_loadingwct_thumbswct_prevwct_nextwct_refreshWP-Choose-Thumb Javascript. http://daveligthart.comThumb loader.id="wct_loading"id="wct_thumbs"id="wct_prev"id="wct_next"id="wct_refresh"name="wct_thumb"+1 morewct_cur_offsetwct_offsetwct_load_thumb_nextwct_load_thumb_prevwct_loadwct_loading+3 more