
Image Widget by Angie Makes Security & Risk Analysis
wordpress.org/plugins/wpc-image-widgetThis plugin allows for the addition of a drag / drop image widget to the existing widgets in your Wordpress theme. Easily upload, and link images to t …
Is Image Widget by Angie Makes Safe to Use in 2026?
Generally Safe
Score 85/100Image Widget by Angie Makes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wpc-image-widget v1.7 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the fact that all identified SQL queries utilize prepared statements is a positive indicator of secure database interaction. The lack of file operations and external HTTP requests also reduces potential vectors for exploitation.
However, a notable concern is the relatively low percentage of properly escaped output (41%). This suggests that a significant portion of data displayed by the plugin may not be adequately sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly into the output without proper escaping. The absence of nonce and capability checks on any potential entry points, though these are currently listed as zero, would be a critical oversight if any were present. The plugin's vulnerability history shows no recorded CVEs, which is a strong positive sign, suggesting a good track record for security in past versions.
In conclusion, while the plugin benefits from a minimal attack surface and secure database practices, the unescaped output is a clear area of concern that warrants attention. The lack of historical vulnerabilities is reassuring, but the static analysis reveals a specific weakness that could be exploited. Addressing the output escaping issue would significantly improve the plugin's overall security.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks observed
- No capability checks observed
Image Widget by Angie Makes Security Vulnerabilities
Image Widget by Angie Makes Release Timeline
Image Widget by Angie Makes Code Analysis
Output Escaping
Image Widget by Angie Makes Attack Surface
WordPress Hooks 2
Maintenance & Trust
Image Widget by Angie Makes Maintenance & Trust
Maintenance Signals
Community Trust
Image Widget by Angie Makes Alternatives
Easy Watermark
easy-watermark
Allows to add watermark to images automatically on upload or manually.
FancyBox for WordPress
fancybox-for-wordpress
Seamlessly integrates FancyBox lightbox into your WordPress blog: Upload, activate, and you're done. Additional configuration optional.
Social Photo Fetcher
facebook-photo-fetcher
Allows you to automatically create Wordpress photo galleries from Facebook albums. Simple to use and highly customizable.
JJ NextGen JQuery Slider
jj-nextgen-jquery-slider
Allows you to pick a gallery from the 'NextGen Gallery' plugin to use as a 'JQuery Nivo slider'.
Image Watermark WP
image-watermark-wp
Image Watermark WP that protects your photos quickly!
Image Widget by Angie Makes Developer Profile
5 plugins · 3K total installs
How We Detect Image Widget by Angie Makes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpc-image-widget/css/admin.css/wp-content/plugins/wpc-image-widget/js/admin.js/wp-content/plugins/wpc-image-widget/js/admin.jswpc-image-widget/css/admin.css?ver=wpc-image-widget/js/admin.js?ver=HTML / DOM Fingerprints
wpc-image-wrapperwpc-widgets-image-fieldwpc-widgets-preview-imagewpc-widgets-image-containerthumbnail-linkimage-hoversidebar-captiondata-targetdata-previewdata-framedata-statedata-fetchdata-title+2 more