Image Widget by Angie Makes Security & Risk Analysis

wordpress.org/plugins/wpc-image-widget

This plugin allows for the addition of a drag / drop image widget to the existing widgets in your Wordpress theme. Easily upload, and link images to t …

500 active installs v1.7 PHP + WP 4.2.4+ Updated May 12, 2017
imageimage-widgetphotopicturepicture-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Widget by Angie Makes Safe to Use in 2026?

Generally Safe

Score 85/100

Image Widget by Angie Makes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The wpc-image-widget v1.7 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the fact that all identified SQL queries utilize prepared statements is a positive indicator of secure database interaction. The lack of file operations and external HTTP requests also reduces potential vectors for exploitation.

However, a notable concern is the relatively low percentage of properly escaped output (41%). This suggests that a significant portion of data displayed by the plugin may not be adequately sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly into the output without proper escaping. The absence of nonce and capability checks on any potential entry points, though these are currently listed as zero, would be a critical oversight if any were present. The plugin's vulnerability history shows no recorded CVEs, which is a strong positive sign, suggesting a good track record for security in past versions.

In conclusion, while the plugin benefits from a minimal attack surface and secure database practices, the unescaped output is a clear area of concern that warrants attention. The lack of historical vulnerabilities is reassuring, but the static analysis reveals a specific weakness that could be exploited. Addressing the output escaping issue would significantly improve the plugin's overall security.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks observed
  • No capability checks observed
Vulnerabilities
None known

Image Widget by Angie Makes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Image Widget by Angie Makes Release Timeline

v1.7Current
v1.6
v1.5
v1.4
v1.3
v1.2
v1.1
Code Analysis
Analyzed Mar 16, 2026

Image Widget by Angie Makes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
41
29 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

41% escaped70 total outputs
Attack Surface

Image Widget by Angie Makes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_enqueue_scriptswpc-image-widget.php:32
actionwidgets_initwpc-image-widget.php:37
Maintenance & Trust

Image Widget by Angie Makes Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedMay 12, 2017
PHP min version
Downloads21K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

Image Widget by Angie Makes Developer Profile

Chris Baldelomar

5 plugins · 3K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image Widget by Angie Makes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpc-image-widget/css/admin.css/wp-content/plugins/wpc-image-widget/js/admin.js
Script Paths
/wp-content/plugins/wpc-image-widget/js/admin.js
Version Parameters
wpc-image-widget/css/admin.css?ver=wpc-image-widget/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpc-image-wrapperwpc-widgets-image-fieldwpc-widgets-preview-imagewpc-widgets-image-containerthumbnail-linkimage-hoversidebar-caption
Data Attributes
data-targetdata-previewdata-framedata-statedata-fetchdata-title+2 more
FAQ

Frequently Asked Questions about Image Widget by Angie Makes