
WP Fake Image Replacer Security & Risk Analysis
wordpress.org/plugins/wp-fake-image-replacerWP Fake Image Replacer generates fake post thumbnail images. Useful in theme development process. Now works with ACF fields.
Is WP Fake Image Replacer Safe to Use in 2026?
Generally Safe
Score 85/100WP Fake Image Replacer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-fake-image-replacer plugin, version 1.5.1, exhibits a mixed security posture. On the positive side, it demonstrates excellent practices in handling SQL queries, exclusively using prepared statements, and its vulnerability history is clean, with no recorded CVEs. The absence of a significant attack surface with unprotected entry points is also a strong positive indicator. However, several areas raise significant concerns. The presence of two 'unserialize' calls is a critical risk, as unserialization of untrusted input can lead to Remote Code Execution (RCE) vulnerabilities. Coupled with this, the plugin lacks any nonce checks and capability checks, meaning that even if an attacker cannot directly reach an unserialize function through an entry point, they might be able to trigger it indirectly if other parts of the code are reachable without authentication. Furthermore, a very low percentage of output escaping (11%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis shows no identified unsanitized flows, this may be due to the limited nature of the static analysis or the absence of direct user input reaching critical functions. The combination of dangerous functions, lack of authentication checks, and poor output escaping creates a substantial risk profile for this plugin.
Key Concerns
- Dangerous functions used (unserialize)
- No nonce checks
- No capability checks
- Low output escaping percentage (11%)
WP Fake Image Replacer Security Vulnerabilities
WP Fake Image Replacer Code Analysis
Dangerous Functions Found
Output Escaping
WP Fake Image Replacer Attack Surface
WordPress Hooks 7
Maintenance & Trust
WP Fake Image Replacer Maintenance & Trust
Maintenance Signals
Community Trust
WP Fake Image Replacer Alternatives
Regenerate Thumbnails
regenerate-thumbnails
Regenerate the thumbnails for one or more of your image uploads. Useful when changing their sizes or your theme.
Auto Featured Image (Auto Post Thumbnail)
auto-post-thumbnail
Automatically generate, assign, and manage featured images in bulk so every post on your site has a featured image.
Crop-Thumbnails
crop-thumbnails
"Crop Thumbnails" made it easy to get exacly that specific image-detail you want to show in your featured image or gallery image.
Featured Image Admin Thumb
featured-image-admin-thumb-fiat
Adds inline thumbnail image to admin columns on Post/post types view (where supported). Click to easily set/change the featured image.
Multi Image Metabox
multi-image-metabox
Add a multi-image metabox to your posts, pages and custom post types
WP Fake Image Replacer Developer Profile
3 plugins · 110 total installs
How We Detect WP Fake Image Replacer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-fake-image-replacer/js/holder.js/wp-content/plugins/wp-fake-image-replacer/js/holder.jsHTML / DOM Fingerprints
Holder.add_themeHolder