WPThumb Security & Risk Analysis
wordpress.org/plugins/wp-thumbAn on-demand image generation replacement for WordPress' image resizing.
Is WPThumb Safe to Use in 2026?
Use With Caution
Score 63/100WPThumb has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-thumb v0.10 plugin exhibits a mixed security posture. While the static analysis shows no dangerous functions, all SQL queries using prepared statements, and a limited attack surface primarily through one shortcode, significant concerns arise from output escaping and the vulnerability history. The fact that 54% of outputs are not properly escaped presents a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is involved in these outputs. Furthermore, the presence of one unpatched medium severity CVE, specifically SSRF, dating from 2025, is a critical red flag. This indicates a known weakness that has not been addressed, leaving sites vulnerable to potentially serious attacks if an exploit becomes available. While the plugin has strengths in its handling of database queries and a small attack surface, the unaddressed CVE and poor output sanitization are significant weaknesses that elevate its risk profile.
Key Concerns
- Unpatched medium CVE
- High percentage of unescaped output
- Missing capability checks
- Missing nonce checks
WPThumb Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPThumb <= 0.10 - Authenticated (Contributor+) Server-Side Request Forgery
WPThumb Code Analysis
Output Escaping
WPThumb Attack Surface
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
WPThumb Maintenance & Trust
Maintenance Signals
Community Trust
WPThumb Alternatives
AutoThumb
autothumb
The plugin is actually just a port of a plugin/snippet I wrote for MODx a while ago (see here). It scans your content's source code for <img&g …
Crop and Resize Images
crop-and-resize-images
Crop and Resize Images Plugin allows you to easily modify WordPress uploaded images.
Manual Image Crop
manual-image-crop
Plugin allows you to manually crop all the image sizes registered in your WordPress theme (in particular featured image).
Acme Fix Images – Regenerate Thumbnails
acme-fix-images
Fix image sizes after you have changed image sizes from Media Settings. Ensure your images display consistently across your website.
WP SmartCrop
wp-smartcrop
WP SmartCrop will crop your images on-the-fly to match your CSS, keeping the main focal point in view.
WPThumb Developer Profile
4 plugins · 10K total installs
How We Detect WPThumb
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-thumb/wpthumb.watermark.php/wp-content/plugins/wp-thumb/wpthumb.background-fill.php/wp-content/plugins/wp-thumb/wpthumb.crop-from-position.php/wp-content/plugins/wp-thumb/wpthumb.shortcodes.phpHTML / DOM Fingerprints
[wpthumb]