
Album and Image Gallery Plus Lightbox Security & Risk Analysis
wordpress.org/plugins/album-and-image-gallery-plus-lightboxA quick, easy way to display responsive image gallery and image album in a grid or slider with light box. Also work with Gutenberg shortcode block.
Is Album and Image Gallery Plus Lightbox Safe to Use in 2026?
Generally Safe
Score 95/100Album and Image Gallery Plus Lightbox has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'album-and-image-gallery-plus-lightbox' plugin version 2.1.8 shows a mixed security posture. On the positive side, the static analysis indicates strong adherence to security best practices in several areas. All identified entry points, including AJAX handlers and shortcodes, appear to have authorization checks. SQL queries are exclusively handled via prepared statements, and a high percentage of output is properly escaped, minimizing risks of cross-site scripting. Nonce and capability checks are also present for most handlers. However, the presence of the `unserialize` function is a significant concern as it can lead to object injection vulnerabilities if not handled with extreme care and sanitization of the input data. Additionally, four out of five analyzed taint flows involved unsanitized paths, indicating potential for arbitrary file access or manipulation, even though no critical or high severity issues were flagged in the taint analysis.
The vulnerability history reveals a pattern of four medium-severity CVEs across various common types, including Cross-Site Scripting, Code Injection, CSRF, and Missing Authorization. While there are currently no unpatched vulnerabilities, the recurring nature of these issues suggests a potential for undiscovered or recurring flaws. The most recent vulnerability was recorded in early 2026, which is in the future, suggesting a potential data anomaly or an indication of past security improvements being tracked forward. The previous vulnerabilities, especially those related to code injection and missing authorization, are particularly concerning, even at a medium severity, as they can have significant impacts if exploited.
In conclusion, while the plugin demonstrates strengths in secure coding practices like prepared statements and output escaping, the use of `unserialize` and the history of diverse security vulnerabilities, particularly those involving code injection and authorization, present notable risks. The taint analysis also flags potential issues with unsanitized paths. Developers should prioritize auditing the usage of `unserialize` and thoroughly reviewing the code related to file operations and input handling to mitigate the risks identified. The plugin's past vulnerability record warrants careful monitoring and diligent patching.
Key Concerns
- Dangerous function 'unserialize' detected
- 4 taint flows with unsanitized paths
- History of 4 medium severity CVEs
- Vulnerabilities include Code Injection and Missing Authorization
- File operations detected
- External HTTP requests detected
Album and Image Gallery Plus Lightbox Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Album and Image Gallery Plus Lightbox <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin's Shortcode
Album and Image Gallery plus Lightbox <= 2.0 - Unauthenticated Arbitrary Shortcode Execution
Album and Image Gallery plus Lightbox <= 1.6.2 - Cross-Site Request Forgery
Album and Image Gallery plus Lightbox <= 1.6.2 - Missing Authorization
Album and Image Gallery Plus Lightbox Release Timeline
Album and Image Gallery Plus Lightbox Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Album and Image Gallery Plus Lightbox Attack Surface
AJAX Handlers 2
Shortcodes 4
WordPress Hooks 33
Scheduled Events 1
Maintenance & Trust
Album and Image Gallery Plus Lightbox Maintenance & Trust
Maintenance Signals
Community Trust
Album and Image Gallery Plus Lightbox Alternatives
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
photo-gallery
Photo Gallery is a powerful image gallery plugin with a list of advanced options for creating responsive image galleries with beautiful lightbox.
Gallery by FooGallery
foogallery
Photo Gallery, Image Gallery by FooGallery — fast, responsive, SEO-optimized, and packed with beautiful layouts.
Modula Image Gallery – Photo Grid & Video Gallery
modula-best-grid-gallery
Create responsive image galleries with drag-and-drop grid builder. Custom layouts, video support, AI optimization. Works with any theme.
Robo Gallery – Photo & Image Slider
robo-gallery
Robo Gallery is a powerful image gallery and photo gallery plugin with advanced features to create responsive galleries with a beautiful lightbox
Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery
pixel-gallery
Best Addon for Elementor WordPress Plugin with 60+ Most Popular Elements that need your everyday website page building.
Album and Image Gallery Plus Lightbox Developer Profile
33 plugins · 204K total installs
How We Detect Album and Image Gallery Plus Lightbox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/album-and-image-gallery-plus-lightbox/assets/css/aigpl-style.css/wp-content/plugins/album-and-image-gallery-plus-lightbox/assets/css/magnific-popup.css/wp-content/plugins/album-and-image-gallery-plus-lightbox/assets/css/owl.carousel.min.css/wp-content/plugins/album-and-image-gallery-plus-lightbox/assets/css/owl.theme.default.min.css/wp-content/plugins/album-and-image-gallery-plus-lightbox/assets/js/aigpl-public.js/wp-content/plugins/album-and-image-gallery-plus-lightbox/assets/js/jquery.magnific-popup.js/wp-content/plugins/album-and-image-gallery-plus-lightbox/assets/js/owl.carousel.min.js/wp-content/plugins/album-and-image-gallery-plus-lightbox/assets/js/aigpl-gutenberg-editor.js/wp-content/plugins/album-and-image-gallery-plus-lightbox/assets/js/aigpl-public.js/wp-content/plugins/album-and-image-gallery-plus-lightbox/assets/js/jquery.magnific-popup.js/wp-content/plugins/album-and-image-gallery-plus-lightbox/assets/js/owl.carousel.min.jsalbum-and-image-gallery-plus-lightbox/assets/css/aigpl-style.css?ver=album-and-image-gallery-plus-lightbox/assets/css/magnific-popup.css?ver=album-and-image-gallery-plus-lightbox/assets/css/owl.carousel.min.css?ver=album-and-image-gallery-plus-lightbox/assets/css/owl.theme.default.min.css?ver=album-and-image-gallery-plus-lightbox/assets/js/aigpl-public.js?ver=album-and-image-gallery-plus-lightbox/assets/js/jquery.magnific-popup.js?ver=album-and-image-gallery-plus-lightbox/assets/js/owl.carousel.min.js?ver=HTML / DOM Fingerprints
aigpl-gallery-wrapaigpl-album-wrapaigpl-gallery-slider-wrapaigpl-album-slider-wrapdata-aigpl-idaigpl_gallery_renderaigpl_slider_renderaigpl_album_renderaigpl_album_slider_renderaigpl_public_js_objectaigpl_admin_js_object[aigpl-gallery[aigpl-gallery-slider[aigpl-gallery-album[aigpl-gallery-album-slider