ZI Hide Featured Image Security & Risk Analysis

wordpress.org/plugins/zi-hide-featured-image

This WP plugin hides the featured image on a single post or page.

700 active installs v1.0.0 PHP + WP 3.0.1+ Updated Jan 4, 2023
featured-imagegutenberghide-featured-imagepost-thumbnail
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ZI Hide Featured Image Safe to Use in 2026?

Generally Safe

Score 85/100

ZI Hide Featured Image has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "zi-hide-featured-image" v1.0.0 plugin exhibits a very strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), and all outputs are properly escaped. Crucially, there are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or capability checks. This indicates a well-secured plugin with a minimal attack surface. The vulnerability history is also clean, with zero recorded CVEs, suggesting a lack of previously discovered exploitable issues and indicating a history of secure development practices. The absence of taint analysis findings further reinforces the notion that there are no obvious vulnerabilities related to data flow. Overall, this plugin appears to be robustly built from a security perspective, adhering to best practices by minimizing its attack surface and implementing secure coding techniques. The primary weakness, if one can call it that given the current data, is the complete absence of nonces and capability checks, which, while not immediately exploitable due to the lack of entry points, might be a point of concern for future development if entry points are added without proper security. However, for its current state, the plugin is highly secure.

Vulnerabilities
None known

ZI Hide Featured Image Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ZI Hide Featured Image Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

ZI Hide Featured Image Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionenqueue_block_editor_assetszi-hide-featured-image.php:40
actioninitzi-hide-featured-image.php:63
filterpost_thumbnail_htmlzi-hide-featured-image.php:65
filteradmin_post_thumbnail_htmlzi-hide-featured-image.php:97
actionsave_postzi-hide-featured-image.php:106
filterpost_thumbnail_htmlzi-hide-featured-image.php:108
filterwoocommerce_single_product_image_thumbnail_htmlzi-hide-featured-image.php:122
Maintenance & Trust

ZI Hide Featured Image Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJan 4, 2023
PHP min version
Downloads9K

Community Trust

Rating60/100
Number of ratings6
Active installs700
Developer Profile

ZI Hide Featured Image Developer Profile

zeninvader

2 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ZI Hide Featured Image

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zi-hide-featured-image/js/zi-hide-featured-image.js
Script Paths
/wp-content/plugins/zi-hide-featured-image/js/zi-hide-featured-image.js
Version Parameters
zi-hide-featured-image/js/zi-hide-featured-image.js?ver=1.0.0

HTML / DOM Fingerprints

Data Attributes
id="ea_featured_image_display"name="ea_featured_image_display"
REST Endpoints
/wp-json/wp/v2/posts?meta=disable_featured_image
FAQ

Frequently Asked Questions about ZI Hide Featured Image