
WP Image Size Limit Security & Risk Analysis
wordpress.org/plugins/wp-image-size-limitAdds a new setting under Settings -> Media where an admin can set a maximum upload file size for image files.
Is WP Image Size Limit Safe to Use in 2026?
Generally Safe
Score 85/100WP Image Size Limit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-image-size-limit' plugin v1.0.4 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL injection vulnerabilities due to prepared statements, file operations, and external HTTP requests is a significant positive. Furthermore, the plugin has no recorded vulnerability history, which suggests a track record of security consciousness. However, a key concern arises from the complete lack of nonce checks and capability checks. This means that potentially any user could trigger the plugin's functionalities if they were to exist, creating a significant risk of unauthorized actions or unexpected behavior. While the current attack surface is reported as zero, this could be a snapshot of current functionality and might not account for future additions or subtle interactions. The 50% rate of proper output escaping is also a point of concern, as it indicates that half of the plugin's outputs are not properly sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities. Despite the clean slate in terms of historical vulnerabilities and lack of critical code signals, the absence of essential security checks and the presence of unsanitized outputs present notable weaknesses.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Half of outputs not properly escaped
WP Image Size Limit Security Vulnerabilities
WP Image Size Limit Code Analysis
Output Escaping
WP Image Size Limit Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP Image Size Limit Maintenance & Trust
Maintenance Signals
Community Trust
WP Image Size Limit Alternatives
Disable Media Sizes
disable-media-sizes
Provides options to disable the extra images generated by WordPress.
AMW Clear Upload Folder
amw-clear-upload-folder
Removes unused files from the 'uploads' folder
Pro Uploads Cleaner
pro-uploads-cleaner
Scan and clean unused images from your WordPress uploads folder safely.
xpressium Image Limit
xpressium-image-limit
Adds a new setting under Settings -> Media where an admin can set a maximum upload file size for image files.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
WP Image Size Limit Developer Profile
2 plugins · 3K total installs
How We Detect WP Image Size Limit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
after-file-uploadupload-flash-bypass<!-- .Custom Max Upload Size --><!-- END Custom Max Upload Size -->