
YD Recent Images Security & Risk Analysis
wordpress.org/plugins/yd-recent-imagesRecent images in a Widget
Is YD Recent Images Safe to Use in 2026?
Generally Safe
Score 85/100YD Recent Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yd-recent-images" plugin v0.2.1 exhibits a generally good security posture with no known vulnerabilities and a small attack surface. The code analysis indicates a conscientious effort towards security, with 100% of SQL queries utilizing prepared statements and the presence of nonce and capability checks. The absence of file operations and external HTTP requests further reduces potential attack vectors.
However, there are notable areas for improvement. The low percentage of properly escaped output (5%) suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis did not reveal critical or high severity unsanitized paths, the presence of one flow with an unsanitized path, even if of lower severity, warrants attention. The plugin's limited vulnerability history might indicate it hasn't been a target or extensively scrutinized, rather than an assurance of perfect security.
In conclusion, while the plugin demonstrates a strong foundation in preventing common web vulnerabilities like SQL injection and unauthorized access, the high rate of unescaped output represents a tangible and potentially exploitable risk. Addressing the output escaping concerns should be a priority to enhance its overall security.
Key Concerns
- Low percentage of properly escaped output
- Flows with unsanitized paths
YD Recent Images Security Vulnerabilities
YD Recent Images Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
YD Recent Images Attack Surface
WordPress Hooks 5
Scheduled Events 2
Maintenance & Trust
YD Recent Images Maintenance & Trust
Maintenance Signals
Community Trust
YD Recent Images Alternatives
YD FeedWordPress Content Filter
yd-feedwordpress-content-filter
This plugin is an add-on to the FeedWordPress RSS content syndication plugin.
Chip Get Image
chip-get-image
A flexible image script for adding thumbnails and feature images to the post.
Gif Controller
gif-controller
The GIF Controller is a simple and lightweight plugin for playing and stopping the GIF images.
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories
post-expirator
PublishPress Future can make scheduled changes to your content. You can unpublish posts, move posts to a new status, update the categories, and more.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
YD Recent Images Developer Profile
14 plugins · 180 total installs
How We Detect YD Recent Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yd-recent-images/css/yd_recent-images.cssyd-recent-images/css/yd_recent-images.css?ver=HTML / DOM Fingerprints
yd_riyd_riidata-yd_widget_id