Wp-Thumbie – Related Posts with thumbnails for WordPress Security & Risk Analysis

wordpress.org/plugins/wp-thumbie

Show user defined number of related / similar posts with thumbnail image

90 active installs v0.1.9 PHP + WP 2.5+ Updated Apr 14, 2012
related-postsrelated-posts-with-thumbailssimilar-poststhumbnail-related-poststhumbnails
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wp-Thumbie – Related Posts with thumbnails for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Wp-Thumbie – Related Posts with thumbnails for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The wp-thumbie plugin, at version 0.1.9, exhibits a mixed security posture. On the positive side, its attack surface appears to be zero, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no known vulnerabilities (CVEs) associated with this plugin, suggesting a history of responsible development. However, significant concerns arise from the static code analysis. A substantial number of file operations (28) are present, which, combined with a complete lack of output escaping (0% properly escaped), presents a high risk of cross-site scripting (XSS) vulnerabilities if any of these file operations lead to user-controlled data being displayed without proper sanitization. The presence of 3 unsanitized path taint flows, while not categorized as critical or high in severity, directly points to potential path traversal or arbitrary file read/write vulnerabilities, especially when coupled with the extensive file operations. The absence of nonce checks and a single capability check also raise flags, suggesting potential authorization bypass issues depending on how these file operations are triggered and what data they process. The plugin also makes an external HTTP request, which could be a vector for server-side request forgery (SSRF) if the target URL is not properly validated.

Key Concerns

  • No output escaping detected
  • 3 unsanitized path taint flows
  • 0 nonce checks
  • 1 capability check on extensive file ops
  • External HTTP request without clear auth/sanitization
Vulnerabilities
None known

Wp-Thumbie – Related Posts with thumbnails for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wp-Thumbie – Related Posts with thumbnails for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
7 prepared
Unescaped Output
21
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
28
External Requests
1
Bundled Libraries
0

SQL Query Safety

64% prepared11 total queries

Output Escaping

0% escaped21 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
tryBrowserCache (timthumb.php:334)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Wp-Thumbie – Related Posts with thumbnails for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuadmin.inc.php:347
actioninitwp-thumbie.php:32
filterthe_contentwp-thumbie.php:160
filterplugin_row_metawp-thumbie.php:280
filterplugin_action_linkswp-thumbie.php:281
actionwp_headwp-thumbie.php:283
Maintenance & Trust

Wp-Thumbie – Related Posts with thumbnails for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedApr 14, 2012
PHP min version
Downloads67K

Community Trust

Rating20/100
Number of ratings3
Active installs90
Developer Profile

Wp-Thumbie – Related Posts with thumbnails for WordPress Developer Profile

blogsdna

1 plugin · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wp-Thumbie – Related Posts with thumbnails for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-thumbie/images/default.png

HTML / DOM Fingerprints

CSS Classes
wp_thumbie_ul_listwp_thumbie_liwp_thumbie_imagewp_thumbie_thumbwp_thumbie_titlewp_thumbie_rl1wp_thumbie_rl2
Data Attributes
id="wp_thumbie"id="wp_thumbie_rl1"class="wp_thumbie_ul_list"id="wp_thumbie_li"id="wp_thumbie_image"id="wp_thumbie_thumb"+4 more
JS Globals
window.ald_crp_initwindow.ald_crpwindow.ald_crp_contentwindow.wp_thumbiewindow.crp_read_optionswindow.crp_default_options
FAQ

Frequently Asked Questions about Wp-Thumbie – Related Posts with thumbnails for WordPress