WP Image Zoomify Security & Risk Analysis

wordpress.org/plugins/wp-image-zoomify

WP Image Zoomify is a simple image light box plugin with zoom effect.

90 active installs v0.1 PHP + WP 3.1+ Updated Jul 3, 2016
image-light-boximage-popupimage-zoomsmooth-image-popupzoomify
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Image Zoomify Safe to Use in 2026?

Generally Safe

Score 85/100

WP Image Zoomify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "wp-image-zoomify" plugin v0.1 exhibits a very strong security posture based on the provided static analysis data. The absence of any dangerous functions, SQL queries requiring sanitization, file operations, external HTTP requests, and the perfect output escaping all indicate a well-written and secure codebase. The plugin also demonstrates excellent security practices by not exposing any attack surface through AJAX handlers, REST API routes, shortcodes, or cron events without explicit authentication or permission checks, and the complete lack of taint flows with unsanitized paths further reinforces this. The vulnerability history is also clean, with no recorded CVEs, suggesting a lack of past security issues.

While the current analysis paints a picture of a highly secure plugin, the extremely low version number (0.1) suggests this is likely a very early, perhaps even pre-release, version. This might mean that the plugin's functionality is limited, and therefore, the attack surface is naturally small. More importantly, the lack of comprehensive testing and auditing that typically accompanies later, stable releases could mean that undiscovered vulnerabilities exist. The complete absence of nonce checks and capability checks is a significant concern if the plugin were to introduce any user-facing interactions in future versions, as these are fundamental WordPress security mechanisms.

Key Concerns

  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

WP Image Zoomify Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Image Zoomify Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP Image Zoomify Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptswp-image-zoomify.php:55
actionwp_footerwp-image-zoomify.php:56
Maintenance & Trust

WP Image Zoomify Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJul 3, 2016
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs90
Developer Profile

WP Image Zoomify Developer Profile

Sultan Nasir Uddin

3 plugins · 190 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Image Zoomify

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-image-zoomify/js/zoomify.min.js/wp-content/plugins/wp-image-zoomify/css/zoomify.min.css
Script Paths
/wp-content/plugins/wp-image-zoomify/js/zoomify.min.js
Version Parameters
wp-image-zoomify-js?ver=wp-image-zoomify-css?ver=

HTML / DOM Fingerprints

CSS Classes
zoomify
Data Attributes
rel="zoomify"
FAQ

Frequently Asked Questions about WP Image Zoomify