
ACF Galerie 4 Security & Risk Analysis
wordpress.org/plugins/acf-galerie-4Enhance your WordPress website with ACF Galerie 4, a powerful and customizable gallery plugin.
Is ACF Galerie 4 Safe to Use in 2026?
Generally Safe
Score 100/100ACF Galerie 4 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'acf-galerie-4' plugin v1.4.3 demonstrates a generally strong security posture with several good practices in place. The plugin has a very small attack surface, with only one AJAX handler and no shortcodes or cron events. Crucially, all identified entry points appear to have proper authentication and capability checks, indicating a mindful approach to access control. The code analysis reveals high levels of output escaping and the use of prepared statements for the vast majority of SQL queries, which are excellent indicators of secure coding. Furthermore, the complete absence of known CVEs and a clean vulnerability history suggest a history of well-maintained and secure code.
However, a single significant concern arises from the presence of the `unserialize()` function. While the static analysis doesn't detail the context of its usage or any identified taint flows, `unserialize()` is inherently dangerous if used with untrusted user input, as it can lead to remote code execution vulnerabilities. The lack of any taint analysis results that explicitly flag unsanitized paths is somewhat reassuring, but it does not entirely mitigate the inherent risk associated with `unserialize()`. The plugin's strengths lie in its limited attack surface and robust handling of most potential entry points, but the potential misuse of `unserialize()` represents a notable weakness that warrants further investigation or mitigation.
Key Concerns
- Presence of unserialize() function
ACF Galerie 4 Security Vulnerabilities
ACF Galerie 4 Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
ACF Galerie 4 Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
ACF Galerie 4 Maintenance & Trust
Maintenance Signals
Community Trust
ACF Galerie 4 Alternatives
Media Carousel ACF Field
media-carousel-acf-field
Displays images and videos in a carousel fetched from Advanced Custom Fields (ACF).
Polaroid Gallery
polaroid-gallery
Polaroid Gallery is a CSS3 & jQuery Image Gallery plugin for WordPress Media Library.
Scissors and Watermark
scissors-watermark
Scissors and Watermark enhances WordPress' handling of images by introducing cropping, resizing, rotating, and watermarking functionality.
Automatic Alternative Text
automatic-alternative-text
Automatically generate alt text for images with Microsoft's Cognitive Services Computer Vision API.
Full Screen Galleries
full-screen-galleries
Full Screen Galleries creates an automatic full-screen slideshow mode for image galleries in your content. Posts and pages with galleries are automati …
ACF Galerie 4 Developer Profile
4 plugins · 61K total installs
How We Detect ACF Galerie 4
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-galerie-4/assets/js/galerie-4-frontend.js/wp-content/plugins/acf-galerie-4/assets/css/galerie-4-frontend.css/wp-content/plugins/acf-galerie-4/assets/js/galerie-4-backend.js/wp-content/plugins/acf-galerie-4/assets/css/galerie-4-backend.css/wp-content/plugins/acf-galerie-4/assets/js/galerie-4-frontend.js/wp-content/plugins/acf-galerie-4/assets/js/galerie-4-backend.jsacf-galerie-4/assets/js/galerie-4-frontend.js?ver=acf-galerie-4/assets/css/galerie-4-frontend.css?ver=acf-galerie-4/assets/js/galerie-4-backend.js?ver=acf-galerie-4/assets/css/galerie-4-backend.css?ver=HTML / DOM Fingerprints
acf-galerie-4-containeracf-galerie-4-itemacf-galerie-4-caption<!-- acf-galerie-4 plugin --><!-- End acf-galerie-4 plugin --><!-- acf-galerie-4-frontend --><!-- acf-galerie-4-backend -->data-acf-galerie-4acf_galerie_4_settingsacf_galerie_4_frontend_params/wp-json/acf-galerie-4/v1/images[acf_galerie_4]