Advanced Custom Fields: NextGEN Gallery Field add-on Security & Risk Analysis

wordpress.org/plugins/advanced-custom-fields-nextgen-gallery-field-add-on

Adds a NextGEN Gallery Field to Advanced Custom Fields. Select one or more NextGEN Galleries and assign them to the post.

500 active installs v2.1 PHP + WP 3.0+ Updated Jan 4, 2015
acfacf-add-oncustom-fieldnextgen-gallerynextgen-gallery-field
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced Custom Fields: NextGEN Gallery Field add-on Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced Custom Fields: NextGEN Gallery Field add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The static analysis for "advanced-custom-fields-nextgen-gallery-field-add-on" v2.1 reveals an exceptionally small attack surface with zero identified entry points. This, combined with the absence of known vulnerabilities in its history, suggests a strong security posture for this version. The code signals also show a positive trend with 100% of SQL queries utilizing prepared statements, and no dangerous functions or file operations detected. However, a significant concern arises from the very low percentage (6%) of properly escaped output. This could leave the plugin susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly on the page without adequate sanitization.

While the lack of identified vulnerabilities and a clean history are commendable, the output escaping issue cannot be overlooked. The plugin's strength lies in its minimal attack surface and adherence to safe SQL practices. The weakness, however, is the potential for XSS due to insufficient output escaping. This suggests that while the plugin may not have been historically targeted or exploited, a proactive approach to fixing the output escaping is crucial to maintain its security.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Advanced Custom Fields: NextGEN Gallery Field add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Advanced Custom Fields: NextGEN Gallery Field add-on Release Timeline

v2.1Current
v2.0
v1.2
v1.1.2
v1.1.1
v1.1
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Advanced Custom Fields: NextGEN Gallery Field add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
49
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

6% escaped52 total outputs
Attack Surface

Advanced Custom Fields: NextGEN Gallery Field add-on Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_print_scriptsacf-ngg-v3.php:71
actionadmin_print_stylesacf-ngg-v3.php:72
actioninitacf-ngg-v3.php:386
actioninitacf-ngg-v3.php:387
actionacf/register_fieldsacf-ngg-v4.php:26
actionadmin_enqueue_scriptsacf-ngg-v5.php:45
actionacf/include_field_typesacf-ngg.php:29
actionacf/register_fieldsacf-ngg.php:40
actioninitacf-ngg.php:52
Maintenance & Trust

Advanced Custom Fields: NextGEN Gallery Field add-on Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.0
Last updatedJan 4, 2015
PHP min version
Downloads42K

Community Trust

Rating42/100
Number of ratings7
Active installs500
Developer Profile

Advanced Custom Fields: NextGEN Gallery Field add-on Developer Profile

Apollo139

2 plugins · 700 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Custom Fields: NextGEN Gallery Field add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-custom-fields-nextgen-gallery-field-add-on/nggallery-field.css/wp-content/plugins/advanced-custom-fields-nextgen-gallery-field-add-on/nggallery-field.js
Version Parameters
advanced-custom-fields-nextgen-gallery-field-add-on/nggallery-field.css?ver=advanced-custom-fields-nextgen-gallery-field-add-on/nggallery-field.js?ver=

HTML / DOM Fingerprints

CSS Classes
acf-nggallery-field
HTML Comments
<!-- NextGEN Gallery plugin is not installed or activated! -->
JS Globals
ACF_NGGallery_Field
FAQ

Frequently Asked Questions about Advanced Custom Fields: NextGEN Gallery Field add-on