Web Image Optimization X

image-optimizer-x · by dalielsam · wordpress.org ↗ · SVN ↗
This plugin is closed on wordpress.org. Closed 2026-04-07.
Active installs
100
Current version
1.4.0
Added
2025-05-07
Last updated
2026-03-25 (1mo ago)
First seen by beacon
1mo ago
Total downloads

Audits (1)

Malicious Audit #26 baseline 1.0.8 → head 1.4.0 20d ago

Attacker-controlled side-channel update endpoint shipped under the cover of "license validation" — same operator (SiteGuarding) and same sibling-plugin pair as audit #25 (wp-advanced-math-captcha). Where the wp-advanced-math-captcha audit caught the delivery vehicle (forced-install primitive pushing this plugin), this audit catches the receiver: a permanent, attacker-controlled file-download primitive baked into every install of image-optimizer-x, fronted by a fake licensing UI.

Read full audit →

Alerts (0)

No open alerts.

Show 1 resolved alert
High manual_audit_seed Resolved · audit:malicious 2026-05-02 21:57:59 (20d ago)
Slugimage-optimizer-x
ReasonC2 sibling of wp-advanced-math-captcha audit #25 — CMSPlughubAPI_LicenseValidator.php ships side-channel update endpoint at api.cmsplughub.com (NS = NS1.SITEGUARDING.COM). Manually seeded for audit linkage.
Linked audit25
View raw JSON
{
    "slug": "image-optimizer-x",
    "reason": "C2 sibling of wp-advanced-math-captcha audit #25 \u2014 CMSPlughubAPI_LicenseValidator.php ships side-channel update endpoint at api.cmsplughub.com (NS = NS1.SITEGUARDING.COM). Manually seeded for audit linkage.",
    "linked_audit": 25
}

SVN committers (2)

Accounts with actual commit access to image-optimizer-x on plugins.svn.wordpress.org, reconstructed from svn log. This is the list that matters for ownership changes — not the readme contributors.

Committer Member since Commits First commit Latest commit
dalielsam 11 2025-05-07 · r3289027 2026-03-25 · r3490992
plugin-master 2007-03-09 1 2025-04-28 · r3283482 2025-04-28 · r3283482

Readme contributors (1)

Names the plugin's readme declares as contributors. A soft signal — anyone can be listed. The SVN access column is the ground-truth cross-reference: does this contributor actually commit code?

Contributor Member since SVN access Status
dalielsam 11 commits Active

Versions (4 most recent)

Version Released Download
1.4.0 2026-03-25 · 1mo ago
1.3.3 2026-01-06 · 4mo ago
1.3.2 2025-12-16 · 5mo ago
1.0.8 2025-11-15 · 6mo ago