
Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Security & Risk Analysis
wordpress.org/plugins/aeroscroll-galleryWordpress Aeroscroll Gallery – A Infinite Scroll Image Gallery to create stunning photo galleries, Post Grids and News Scrollers
Is Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Safe to Use in 2026?
Mostly Safe
Score 78/100Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery is generally safe to use. 1 past CVE were resolved. Keep it updated.
The aeroscroll-gallery plugin exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and performing capability checks on a significant portion of its entry points. The absence of dangerous functions is also a good sign. However, several critical areas raise concerns. The presence of 4 REST API routes without permission callbacks exposes potential vulnerabilities for unauthenticated users. The taint analysis revealed 2 flows with unsanitized paths and one high-severity flow, indicating a risk of malicious input being processed in a way that could lead to unintended actions, potentially related to file system access given the plugin's file operation count.
The vulnerability history is particularly concerning, with one known medium-severity CVE, specifically a 'Path Traversal' vulnerability, which is still unpatched. This, combined with the taint analysis findings, strongly suggests a recurring pattern of issues related to handling user-supplied path information insecurely. While the plugin has strengths in database interaction and access control for many endpoints, the combination of unprotected REST API routes and identified path-related vulnerabilities presents a tangible risk that requires immediate attention. The unpatched CVE indicates a lack of timely security patching, further exacerbating the risk.
Key Concerns
- Unpatched CVE found
- High severity taint flow found
- REST API routes without permission callbacks
- Flows with unsanitized paths found
- 50% of output not properly escaped
- No nonce checks found
Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery <= 1.0.12 - Unauthenticated Directory Traversal
Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Attack Surface
REST API Routes 25
WordPress Hooks 12
Maintenance & Trust
Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Maintenance & Trust
Maintenance Signals
Community Trust
Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Alternatives
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
photo-gallery
Photo Gallery is a powerful image gallery plugin with a list of advanced options for creating responsive image galleries with beautiful lightbox.
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More
envira-gallery-lite
Envira Gallery is a fast, easy and powerful gallery builder with lightbox, masonry and grid layouts, albums, videos, and responsive displays and more
Gallery by FooGallery
foogallery
Photo Gallery, Image Gallery by FooGallery — fast, responsive, SEO-optimized, and packed with beautiful layouts.
Robo Gallery – Photo & Image Slider
robo-gallery
Robo Gallery is a powerful image gallery and photo gallery plugin with advanced features to create responsive galleries with a beautiful lightbox
Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Developer Profile
1 plugin · 10 total installs
How We Detect Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aeroscroll-gallery/dist/css/app.css/wp-content/plugins/aeroscroll-gallery/css/aeroscroll-gallery-admin.cssaeroscroll-gallery/css/aeroscroll-gallery-admin.css?v=dist/css/app.css?v=HTML / DOM Fingerprints
aeroscroll-gallery-wrap<!-- aeroscroll-gallery-wrap --><!-- aeroscroll-gallery-wrap end -->data-aeroscroll-iddata-aeroscroll-auto-playdata-aeroscroll-auto-play-delaydata-aeroscroll-loopdata-aeroscroll-speeddata-aeroscroll-gap+27 morewindow.aeroscrollGallerywindow.aeroscroll_gallery_object[aeroscroll_gallery