ARI Fancy Lightbox – Popup for WordPress Security & Risk Analysis

wordpress.org/plugins/ari-fancy-lightbox

Lightbox for WordPress with social and viral features. Show photos, gallery, PDF, videos, WooCommerce images, inline content, Google Maps links.

10K active installs v1.4.1 PHP + WP 3.4+ Updated Sep 24, 2025
fancyboxfancybox3lightboxpopupvideo-lightbox
97
A · Safe
CVEs total3
Unpatched0
Last CVESep 5, 2025
Safety Verdict

Is ARI Fancy Lightbox – Popup for WordPress Safe to Use in 2026?

Generally Safe

Score 97/100

ARI Fancy Lightbox – Popup for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Sep 5, 2025Updated 6mo ago
Risk Assessment

The static analysis of ari-fancy-lightbox v1.4.1 reveals a generally good security posture regarding its attack surface and immediate code signals. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits potential entry points for attackers. Furthermore, all identified outputs are properly escaped, and there are no instances of dangerous functions, file operations, external HTTP requests, or vulnerabilities flagged by taint analysis. This indicates the developers have implemented some basic security best practices.

However, a notable concern arises from the SQL query handling. The single SQL query present is not using prepared statements, which is a significant vulnerability. This absence of prepared statements, especially in conjunction with the plugin's history of Cross-Site Scripting (XSS) vulnerabilities, raises alarms. The vulnerability history shows three medium-severity XSS vulnerabilities, with the last one being relatively recent (2025-09-05), even though none are currently unpatched. This pattern suggests a recurring weakness in input sanitization or output encoding related to how data is handled within SQL operations or how it's presented in the frontend.

In conclusion, while the plugin exhibits strengths in minimizing its direct attack surface and properly escaping output, the lack of prepared statements for its SQL query and its history of XSS vulnerabilities point to critical areas that require immediate attention. The absence of capability checks and nonce checks on entry points (though there are none in this version) would have been a significant concern if entry points existed, but the focus should now be on the SQL injection risk and the underlying causes of past XSS issues. The plugin has potential weaknesses that could be exploited if the SQL query is ever exposed to user-controlled input.

Key Concerns

  • Raw SQL query without prepared statements
  • History of XSS vulnerabilities
Vulnerabilities
3

ARI Fancy Lightbox – Popup for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-58784medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ARI Fancy Lightbox <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 5, 2025 Patched in 1.4.1 (21d)
CVE-2024-47310medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ARI Fancy Lightbox <= 1.3.17 - Authenticated (Author+) Stored Cross-Site Scripting

Sep 25, 2024 Patched in 1.3.18 (8d)
CVE-2022-0161medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ARI Fancy Lightbox <= 1.3.8 - Reflected Cross-Site Scripting

Feb 17, 2022 Patched in 1.3.9 (705d)
Code Analysis
Analyzed Mar 16, 2026

ARI Fancy Lightbox – Popup for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

100% escaped8 total outputs
Attack Surface

ARI Fancy Lightbox – Popup for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedari-fancy-lightbox.php:86
actionadmin_noticesari-fancy-lightbox.php:107
actionwp_enqueue_scriptsincludes\class-loader.php:18
actionadmin_enqueue_scriptsincludes\class-plugin.php:27
actionadmin_menuincludes\class-plugin.php:28
actionadmin_initincludes\class-plugin.php:29
actioninitincludes\class-plugin.php:33
actionwp_enqueue_scriptsincludes\class-plugin.php:34
filterpre_option_ari_fancy_lightbox_settingsincludes\class-plugin.php:52
filterfoogallery_gallery_template_field_lightboxesincludes\class-plugin.php:174
filterfoogallery_attachment_html_link_attributesincludes\class-plugin.php:180
Maintenance & Trust

ARI Fancy Lightbox – Popup for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 24, 2025
PHP min version
Downloads242K

Community Trust

Rating94/100
Number of ratings71
Active installs10K
Developer Profile

ARI Fancy Lightbox – Popup for WordPress Developer Profile

arisoft

4 plugins · 17K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
197 days
View full developer profile
Detection Fingerprints

How We Detect ARI Fancy Lightbox – Popup for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ari-fancy-lightbox/css/lightbox.css/wp-content/plugins/ari-fancy-lightbox/css/skins/default.css/wp-content/plugins/ari-fancy-lightbox/js/jquery.mousewheel-3.0.6.pack.js/wp-content/plugins/ari-fancy-lightbox/js/jquery.fancybox.pack.js/wp-content/plugins/ari-fancy-lightbox/js/ari-fancybox.js/wp-content/plugins/ari-fancy-lightbox/js/purify.min.js
Script Paths
/wp-content/plugins/ari-fancy-lightbox/js/jquery.mousewheel-3.0.6.pack.js/wp-content/plugins/ari-fancy-lightbox/js/jquery.fancybox.pack.js/wp-content/plugins/ari-fancy-lightbox/js/ari-fancybox.js/wp-content/plugins/ari-fancy-lightbox/js/purify.min.js
Version Parameters
ari-fancy-lightbox/css/lightbox.css?ver=ari-fancy-lightbox/css/skins/default.css?ver=ari-fancy-lightbox/js/jquery.mousewheel-3.0.6.pack.js?ver=ari-fancy-lightbox/js/jquery.fancybox.pack.js?ver=ari-fancy-lightbox/js/ari-fancybox.js?ver=ari-fancy-lightbox/js/purify.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
ari-fancybox-wrapari-fancybox-skinari-fancybox-outerari-fancybox-innerari-fancybox-contentari-fancybox-titleari-fancybox-closeari-fancybox-prev+10 more
Data Attributes
data-fancybox-group
JS Globals
ARI_FANCYBOXARI_FANCYBOX_INIT_FUNC
FAQ

Frequently Asked Questions about ARI Fancy Lightbox – Popup for WordPress