Pixieshot Gallery – Widgets for Elementor Security & Risk Analysis

wordpress.org/plugins/advanced-gallery

Pixieshot Gallery is a powerful gallery plugin built for creating beautiful and mobile-responsive galleries in minutes.

200 active installs v1.0.4 PHP 7.4+ WP 5.1+ Updated Nov 21, 2024
elementorgalleryphoto-galleryresponsive-gallerywordpress-gallery-plugin
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pixieshot Gallery – Widgets for Elementor Safe to Use in 2026?

Generally Safe

Score 92/100

Pixieshot Gallery – Widgets for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The advanced-gallery plugin version 1.0.4 demonstrates a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals no dangerous functions, file operations, or external HTTP requests, all of which are positive indicators. The use of prepared statements for all SQL queries and a high percentage of properly escaped output further bolster its security.

Despite these strengths, a critical concern arises from the complete lack of nonce checks and capability checks. This means that even if there are no direct entry points that are immediately exploitable, any function that *does* exist within the plugin and is triggered through a direct call or a method that bypasses WordPress's built-in security mechanisms could potentially be executed without proper authorization or verification. The taint analysis showing zero flows with unsanitized paths is reassuring, but the absence of these fundamental WordPress security checks creates a potential for privilege escalation or unauthorized actions if an attacker can find a way to trigger these functions.

The vulnerability history, with zero known CVEs and no recorded vulnerabilities, is exceptionally positive and suggests a history of secure development. However, this positive history should not overshadow the identified lack of nonce and capability checks. The plugin's strengths lie in its minimal attack surface and secure data handling practices for its current functionalities, but its weaknesses lie in the fundamental absence of WordPress's built-in authorization and integrity checks, which could become a significant risk if new functionalities are added or if unforeseen interaction vectors are discovered.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Pixieshot Gallery – Widgets for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Pixieshot Gallery – Widgets for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
37 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped43 total outputs
Attack Surface

Pixieshot Gallery – Widgets for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedadvanced-gallery.php:55
actionelementor/widgets/registerincludes\classes\class-widgets.php:36
actionelementor/elements/categories_registeredincludes\classes\class-widgets.php:37
actionelementor/common/after_register_scriptsincludes\classes\class-widgets.php:38
actioninitincludes\classes\class-widgets.php:39
actionadmin_noticessrc\Advanced_Gallery.php:76
actionelementor/frontend/after_register_scriptssrc\Advanced_Gallery.php:145
actionelementor/frontend/after_register_stylessrc\Advanced_Gallery.php:146
actionadmin_noticessrc\Advanced_Gallery.php:367
actionadmin_noticessrc\Advanced_Gallery.php:373
actionadmin_noticessrc\Advanced_Gallery.php:379
Maintenance & Trust

Pixieshot Gallery – Widgets for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 21, 2024
PHP min version7.4
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Pixieshot Gallery – Widgets for Elementor Developer Profile

Kraft Plugins

5 plugins · 23K total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Pixieshot Gallery – Widgets for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-gallery/includes/css/adv-gal-icons.css/wp-content/plugins/advanced-gallery/assets/css/advanced-gallery.css/wp-content/plugins/advanced-gallery/assets/js/advanced-gallery-frontend.js/wp-content/plugins/advanced-gallery/assets/js/elementor-frontend.js
Version Parameters
advanced-gallery/assets/css/advanced-gallery.css?ver=advanced-gallery/assets/js/advanced-gallery-frontend.js?ver=advanced-gallery/assets/js/elementor-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
adv-gal-image-grid__wrapadv-masonry-galleryadv-filterable-galleryadv-justified-galleryelementor-widget-advanced-gallery
Data Attributes
data-adv-gal-widget-id
JS Globals
window.AdvGalFrontendwindow.elementorFrontendwindow.elementor
Shortcode Output
[advanced_gallery[advanced_gallery_carousel
FAQ

Frequently Asked Questions about Pixieshot Gallery – Widgets for Elementor