As Gallery Security & Risk Analysis

wordpress.org/plugins/as-gallery

As Gallery is a great plugin for adding image gallery for your site.

10 active installs v1.0 PHP + WP 3.5+ Updated Jun 2, 2016
add-albumadd-galleryadd-picturesadminas-gallery
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is As Gallery Safe to Use in 2026?

Generally Safe

Score 85/100

As Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'as-gallery' v1.0 plugin presents a generally good security posture based on the provided static analysis. The absence of any known vulnerabilities (CVEs) in its history is a significant positive indicator. Furthermore, the code analysis reveals good practices such as the use of prepared statements for all SQL queries and the presence of nonce and capability checks for its entry points. The attack surface appears limited and is described as unprotected entry points being zero.

However, a notable concern arises from the output escaping. With 40 total outputs analyzed, only 8% are properly escaped, indicating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This low rate of proper escaping means that user-supplied data or dynamically generated content could be injected and executed by a user's browser, potentially leading to session hijacking, defacement, or other malicious actions. The lack of any identified taint flows might be misleading if the analysis was not comprehensive, but the output escaping issue alone is a significant weakness that overshadows the otherwise positive findings.

In conclusion, while the plugin benefits from a clean vulnerability history and secure handling of database queries and authentication mechanisms, the severe deficiency in output escaping creates a critical security risk. This weakness requires immediate attention to prevent potential XSS attacks. The plugin's strengths lie in its backend security practices, but its frontend output handling is a significant vulnerability.

Key Concerns

  • Low output escaping (8%)
Vulnerabilities
None known

As Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

As Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
37
3 escaped
Nonce Checks
2
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

8% escaped40 total outputs
Attack Surface

As Gallery Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_as_gl_reset_optionsas_gallery.php:59

Shortcodes 1

[as_gallery] inc\as_shortcode.php:71
WordPress Hooks 11
actioninitinc\asglcustompost.php:33
actionadd_meta_boxesinc\asglcustompost.php:54
actionsave_postinc\asglcustompost.php:122
actionadmin_initinc\as_gl_options.php:118
actionadmin_menuinc\as_gl_options.php:318
actionwp_enqueue_scriptsinc\as_gl_script.php:13
actionwp_footerinc\as_gl_script.php:83
actionadmin_enqueue_scriptsinc\as_gl_script.php:106
actionwp_headinc\as_gl_script.php:294
filtermanage_asgallery_posts_columnsinc\as_post_column.php:10
actionmanage_asgallery_posts_custom_columninc\as_post_column.php:24
Maintenance & Trust

As Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJun 2, 2016
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

As Gallery Developer Profile

anuislam

5 plugins · 70 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect As Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/as-gallery/css/as_main.css/wp-content/plugins/as-gallery/js/lightbox.js/wp-content/plugins/as-gallery/js/as_admin_js.js/wp-content/plugins/as-gallery/css/as_admin_css.css
Script Paths
/wp-content/plugins/as-gallery/js/lightbox.js/wp-content/plugins/as-gallery/js/as_admin_js.js

HTML / DOM Fingerprints

CSS Classes
as_gallery_mainas_gallery_main_lias_gl_col_four
Data Attributes
as_gl_imageas_gl_image_columnas_gl_image_size
JS Globals
simpleLightbox
Shortcode Output
<ul id="as_gallery_main"><li id="a
FAQ

Frequently Asked Questions about As Gallery