
WPExifView Security & Risk Analysis
wordpress.org/plugins/wpexifviewImage EXIF information embedded within the body of the post.
Is WPExifView Safe to Use in 2026?
Generally Safe
Score 85/100WPExifView has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The WPEXIFVIEW v1.4.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and has no recorded vulnerabilities or CVEs. This suggests a generally well-maintained codebase with a history of security awareness. However, significant concerns arise from the static analysis. The plugin fails to properly escape any of its outputs, creating a strong risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the presence of the `create_function` dangerous function is a critical red flag, as it can be a vector for code injection if not handled with extreme care. The absence of nonce and capability checks across its entry points, despite a small attack surface, also leaves it vulnerable to CSRF attacks and unauthorized access to its limited functionality.
Key Concerns
- No output escaping
- Use of dangerous function: create_function
- No nonce checks
- No capability checks
WPExifView Security Vulnerabilities
WPExifView Release Timeline
WPExifView Code Analysis
Dangerous Functions Found
Output Escaping
WPExifView Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
WPExifView Maintenance & Trust
Maintenance Signals
Community Trust
WPExifView Alternatives
EXIF Remover
exif-remover
Remove EXIF data from images on upload.
MMWW
mmww
Media Metadata Workflow Wizard: Integrate your media metadata workflow with WordPress's Media Library
Remove exif and metadata
remove-exif-and-metadata
Automatically remove exif and metadata data after uploading. Just moment supported format: JPG and PNG. Using ImageMagick
Force use of ImageMagick image library
mhm-forceimagemagick
Forces WordPress to use the ImageMagick image library. This plugin is no longer maintained.
EXIF Viewer
exif-viewer
EXIF Viewer displays EXIF data in Edit Media Screen, appends EXIF data to JPEG media page content, enables media archives
WPExifView Developer Profile
2 plugins · 20 total installs
How We Detect WPExifView
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpexifview/wpexifview.css/wp-content/plugins/wpexifview/wpexifview.js/wp-content/plugins/wpexifview/wpexifview.jswpexifview/wpexifview.css?ver=wpexifview/wpexifview.js?ver=