WP Recreate Thumbnails Security & Risk Analysis
wordpress.org/plugins/wp-recreate-thumbnailsThis Plugin helps to create thumbnails of uploaded images
Is WP Recreate Thumbnails Safe to Use in 2026?
Generally Safe
Score 92/100WP Recreate Thumbnails has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-recreate-thumbnails plugin v1.2.0 exhibits significant security concerns due to its unprotected AJAX handlers. While the plugin demonstrates good practices in avoiding dangerous functions, raw SQL queries, and external HTTP requests, the presence of four AJAX handlers without any authentication or capability checks presents a substantial attack surface. This means any unauthenticated user could potentially trigger these actions, leading to unintended consequences. The taint analysis also indicates two flows with unsanitized paths, which, while not classified as critical or high severity in this instance, highlight potential pathways for attackers to manipulate data or file operations. The plugin's clean vulnerability history is a positive sign, suggesting no known historical exploits. However, the current static analysis findings, particularly the unprotected entry points, overshadow this positive history, requiring immediate attention to secure these handlers.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint analysis
- Output escaping concerns
- Lack of nonce checks
- Lack of capability checks
WP Recreate Thumbnails Security Vulnerabilities
WP Recreate Thumbnails Release Timeline
WP Recreate Thumbnails Code Analysis
Output Escaping
Data Flow Analysis
WP Recreate Thumbnails Attack Surface
AJAX Handlers 4
WordPress Hooks 3
Maintenance & Trust
WP Recreate Thumbnails Maintenance & Trust
Maintenance Signals
Community Trust
WP Recreate Thumbnails Alternatives
WP Image Sizes
wp-image-sizes
Select the only image sizes for post types you want to be generated. Eliminate unnecessary image sizes.
Custom Thumbnail Generator
custom-thumbnail-generator
Custom Thumbnail Generator manages image sizes via an AJAX interface. It decouples sizes from themes, ensuring they persist and remain functional.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
TinyPNG – JPEG, PNG & WebP image compression
tiny-compress-images
Speed up your website. Optimize your JPEG, PNG, and WebP images automatically with TinyPNG.
Auto Featured Image (Auto Post Thumbnail)
auto-post-thumbnail
Automatically generate, assign, and manage featured images in bulk so every post on your site has a featured image.
WP Recreate Thumbnails Developer Profile
15 plugins · 6K total installs
How We Detect WP Recreate Thumbnails
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-recreate-thumbnails/js/create_thumb.js/wp-content/plugins/wp-recreate-thumbnails/css/font-awesome.min.css/wp-content/plugins/wp-recreate-thumbnails/css/style.css/wp-content/plugins/wp-recreate-thumbnails/js/jquery.redirect.js/wp-content/plugins/wp-recreate-thumbnails/css/loader.gifjs/create_thumb.jsjs/jquery.redirect.jsHTML / DOM Fingerprints
btn_regensize-labelsize-textdata-idpassed_object/wp-json/yspl/v1/recreate-thumbnails