
ARI Fancy Lightbox – Popup for WordPress Security & Risk Analysis
wordpress.org/plugins/ari-fancy-lightboxLightbox for WordPress with social and viral features. Show photos, gallery, PDF, videos, WooCommerce images, inline content, Google Maps links.
Is ARI Fancy Lightbox – Popup for WordPress Safe to Use in 2026?
Generally Safe
Score 97/100ARI Fancy Lightbox – Popup for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of ari-fancy-lightbox v1.4.1 reveals a generally good security posture regarding its attack surface and immediate code signals. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits potential entry points for attackers. Furthermore, all identified outputs are properly escaped, and there are no instances of dangerous functions, file operations, external HTTP requests, or vulnerabilities flagged by taint analysis. This indicates the developers have implemented some basic security best practices.
However, a notable concern arises from the SQL query handling. The single SQL query present is not using prepared statements, which is a significant vulnerability. This absence of prepared statements, especially in conjunction with the plugin's history of Cross-Site Scripting (XSS) vulnerabilities, raises alarms. The vulnerability history shows three medium-severity XSS vulnerabilities, with the last one being relatively recent (2025-09-05), even though none are currently unpatched. This pattern suggests a recurring weakness in input sanitization or output encoding related to how data is handled within SQL operations or how it's presented in the frontend.
In conclusion, while the plugin exhibits strengths in minimizing its direct attack surface and properly escaping output, the lack of prepared statements for its SQL query and its history of XSS vulnerabilities point to critical areas that require immediate attention. The absence of capability checks and nonce checks on entry points (though there are none in this version) would have been a significant concern if entry points existed, but the focus should now be on the SQL injection risk and the underlying causes of past XSS issues. The plugin has potential weaknesses that could be exploited if the SQL query is ever exposed to user-controlled input.
Key Concerns
- Raw SQL query without prepared statements
- History of XSS vulnerabilities
ARI Fancy Lightbox – Popup for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
ARI Fancy Lightbox <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
ARI Fancy Lightbox <= 1.3.17 - Authenticated (Author+) Stored Cross-Site Scripting
ARI Fancy Lightbox <= 1.3.8 - Reflected Cross-Site Scripting
ARI Fancy Lightbox – Popup for WordPress Code Analysis
SQL Query Safety
Output Escaping
ARI Fancy Lightbox – Popup for WordPress Attack Surface
WordPress Hooks 11
Maintenance & Trust
ARI Fancy Lightbox – Popup for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
ARI Fancy Lightbox – Popup for WordPress Alternatives
Video PopUp
video-popup
The ultimate Video Popup plugin for WordPress. Create unlimited and responsive popups for YouTube, Vimeo, MP4 & WebM videos on click or On-Page Load.
WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo
responsive-youtube-vimeo-popup
WP Video Popup lets you add a responsive YouTube, Rumble or Vimeo video lightbox to any page, post or custom post type of your website.
Easy Lightbox – Image, Gallery and Video Lightbox for WordPress
easy-lightbox-wp
Easy Lightbox is an Image, Gallery and Video Lightbox plugin for WordPress. This plugin will enable a smooth Lightbox in your WordPress website.
Image and Video Lightbox, Image PopUp
lightbox-popup
Image and Video Lightbox is an high customizable and responsive plugin for displaying images and videos in popup.
Post Featured Video
post-featured-video
Post Featured Video is a very nifty responsive video plugin that helps your users to see a YouTube or Vimeo video or Custom HTML MP4 video
ARI Fancy Lightbox – Popup for WordPress Developer Profile
4 plugins · 17K total installs
How We Detect ARI Fancy Lightbox – Popup for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ari-fancy-lightbox/css/lightbox.css/wp-content/plugins/ari-fancy-lightbox/css/skins/default.css/wp-content/plugins/ari-fancy-lightbox/js/jquery.mousewheel-3.0.6.pack.js/wp-content/plugins/ari-fancy-lightbox/js/jquery.fancybox.pack.js/wp-content/plugins/ari-fancy-lightbox/js/ari-fancybox.js/wp-content/plugins/ari-fancy-lightbox/js/purify.min.js/wp-content/plugins/ari-fancy-lightbox/js/jquery.mousewheel-3.0.6.pack.js/wp-content/plugins/ari-fancy-lightbox/js/jquery.fancybox.pack.js/wp-content/plugins/ari-fancy-lightbox/js/ari-fancybox.js/wp-content/plugins/ari-fancy-lightbox/js/purify.min.jsari-fancy-lightbox/css/lightbox.css?ver=ari-fancy-lightbox/css/skins/default.css?ver=ari-fancy-lightbox/js/jquery.mousewheel-3.0.6.pack.js?ver=ari-fancy-lightbox/js/jquery.fancybox.pack.js?ver=ari-fancy-lightbox/js/ari-fancybox.js?ver=ari-fancy-lightbox/js/purify.min.js?ver=HTML / DOM Fingerprints
ari-fancybox-wrapari-fancybox-skinari-fancybox-outerari-fancybox-innerari-fancybox-contentari-fancybox-titleari-fancybox-closeari-fancybox-prev+10 moredata-fancybox-groupARI_FANCYBOXARI_FANCYBOX_INIT_FUNC