Add LightBox & Title Security & Risk Analysis

wordpress.org/plugins/add-lightbox-title

This plugin for WordPress automatically add the rel="lightbox[ID-OF-THE-POST]" and recovers the image title.

300 active installs v1.5 PHP + WP 2.7.0+ Updated Mar 4, 2011
automaticimagesjavascriptslightboxshadowbox
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Add LightBox & Title Safe to Use in 2026?

Generally Safe

Score 85/100

Add LightBox & Title has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The static analysis of the "add-lightbox-title" v1.5 plugin reveals a remarkably clean codebase with no apparent vulnerabilities in terms of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or tainted data flows. The absence of entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly reduces the plugin's attack surface. Furthermore, the vulnerability history is clean, with no recorded CVEs, indicating a strong security track record.

However, the complete lack of nonce checks and capability checks, across all identified code signals, presents a significant concern. While the current version might not have exploitable entry points that necessitate these checks, the absence of these fundamental security mechanisms means that if any new entry points are introduced in future updates, or if an existing function is unexpectedly exposed, there would be no built-in protection against unauthorized access or manipulation. This oversight, coupled with the fact that 0% of AJAX handlers (if any were present) and 0% of REST API routes have authentication checks, points to a weakness in the plugin's overall security architecture. Despite the current clean state, this absence of basic security hygiene is a potential future risk.

In conclusion, "add-lightbox-title" v1.5 demonstrates excellent practices in secure coding for existing functionalities, with no immediate exploitable vulnerabilities identified. The plugin benefits from a minimal attack surface and a history free of security incidents. The primary weakness lies in the deliberate or accidental omission of essential security checks like nonces and capability checks, which leaves it vulnerable to potential future threats if the attack surface expands or existing functions are misused. A balanced perspective suggests that while the plugin is currently safe, future development must prioritize the implementation of these standard security measures to maintain its secure posture.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • No authentication on AJAX handlers (0 present)
  • No permission callbacks on REST API routes (0 present)
Vulnerabilities
None known

Add LightBox & Title Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Add LightBox & Title Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Add LightBox & Title Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterthe_contentadd-lightbox-title.php:14
filterthe_excerptadd-lightbox-title.php:15
filterget_comment_textadd-lightbox-title.php:16
Maintenance & Trust

Add LightBox & Title Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedMar 4, 2011
PHP min version
Downloads34K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

Add LightBox & Title Developer Profile

ppalli

2 plugins · 310 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add LightBox & Title

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
rel="lightbox
FAQ

Frequently Asked Questions about Add LightBox & Title