
WP Rekogni Security & Risk Analysis
wordpress.org/plugins/wp-rekogniAssign Tags to Posts By Amazon Image Rekognition
Is WP Rekogni Safe to Use in 2026?
Generally Safe
Score 100/100WP Rekogni has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-rekogni" v1.0.2 plugin exhibits a generally strong security posture based on the provided static analysis. It boasts a zero attack surface for unauthenticated users and avoids dangerous functions entirely. All SQL queries are properly prepared, and the vast majority of output is correctly escaped, which are excellent security practices. The plugin also has no recorded vulnerabilities (CVEs), indicating a clean history and potentially well-maintained code.
However, there are a few areas that warrant attention. The presence of two unsanitized path flows in the taint analysis, even without critical or high severity, suggests a potential for directory traversal or insecure file handling if these flows are ever exposed to user input. Furthermore, the absence of any nonce checks or capability checks on any of its entry points, coupled with the single file operation detected, raises a concern. While the attack surface is currently zero, any future expansion or modification of functionality could introduce vulnerabilities if authorization and nonces are not implemented from the outset.
In conclusion, "wp-rekogni" v1.0.2 is a strong candidate for a secure plugin due to its clean vulnerability history and good coding practices in SQL and output escaping. The primary weaknesses lie in the potential for insecure file handling indicated by the taint analysis and the lack of robust authorization mechanisms, which could become issues as the plugin evolves. The bundled Guzzle library should also be monitored for security updates.
Key Concerns
- Unsanitized path flows detected
- No nonce checks on any entry points
- No capability checks on any entry points
- Bundled outdated library (Guzzle)
WP Rekogni Security Vulnerabilities
WP Rekogni Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
WP Rekogni Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP Rekogni Maintenance & Trust
Maintenance Signals
Community Trust
WP Rekogni Alternatives
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
Connect Polylang for Elementor
connect-polylang-elementor
Connect Polylang with Elementor: translated templates, language switcher widget, language visibility conditions and more
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
Enhanced Media Library
enhanced-media-library
This plugin would be handy for those who need to manage a lot of media files.
WP Rekogni Developer Profile
6 plugins · 920 total installs
How We Detect WP Rekogni
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-rekogni/css/style.css/wp-content/plugins/wp-rekogni/js/wp-rekogni.js/wp-content/plugins/wp-rekogni/js/wp-rekogni.jswp-rekogni/style.css?ver=wp-rekogni/wp-rekogni.js?ver=