Bilych Gallery Security & Risk Analysis

wordpress.org/plugins/bilych-gallery

This plugin replace default Wordpress gallery.

10 active installs v1.0.0 PHP + WP 3.7+ Updated Feb 20, 2015
galleryimageimageslightboxslideshow
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bilych Gallery Safe to Use in 2026?

Generally Safe

Score 85/100

Bilych Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The bilych-gallery plugin version 1.0.0 exhibits a strong foundation in terms of SQL query security and a limited attack surface. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Furthermore, the plugin has no recorded vulnerability history, suggesting a generally well-maintained codebase. However, a significant concern arises from the complete lack of output escaping. This means that any data processed or displayed by the plugin, if originating from user input or external sources, could be vulnerable to cross-site scripting (XSS) attacks.

While the static analysis shows no critical or high severity issues in taint flows, the lack of output escaping is a major weakness that can be exploited. The absence of nonce and capability checks on the identified entry points (shortcodes) is also a point of concern, although the limited nature of the attack surface (only one shortcode) mitigates this risk to some extent. In conclusion, the plugin has positive security attributes, but the unescaped output is a critical flaw that needs immediate attention to prevent potential security breaches.

Key Concerns

  • Unescaped output identified
  • Missing nonce check on entry point
  • Missing capability check on entry point
Vulnerabilities
None known

Bilych Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Bilych Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Bilych Gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[gallery] public\class-bilych-gallery-public.php:97
WordPress Hooks 6
actionplugins_loadedincludes\class-bilych-gallery.php:140
actionadmin_enqueue_scriptsincludes\class-bilych-gallery.php:155
actionadmin_menuincludes\class-bilych-gallery.php:156
actionadmin_initincludes\class-bilych-gallery.php:157
actionwp_enqueue_scriptsincludes\class-bilych-gallery.php:172
actionwp_enqueue_scriptsincludes\class-bilych-gallery.php:173
Maintenance & Trust

Bilych Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedFeb 20, 2015
PHP min version
Downloads2K

Community Trust

Rating70/100
Number of ratings2
Active installs10
Developer Profile

Bilych Gallery Developer Profile

Bilych

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bilych Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bilych-gallery/admin/css/bilych-gallery-admin.css/wp-content/plugins/bilych-gallery/public/css/bilych-gallery-public.css/wp-content/plugins/bilych-gallery/public/js/bilych-gallery-public.js
Version Parameters
bilych-gallery/css/bilych-gallery-admin.css?ver=bilych-gallery/css/bilych-gallery-public.css?ver=bilych-gallery/js/bilych-gallery-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
bilych-gallery-thumbnailsbilych-gallery-thumbnails-image
Data Attributes
data-gallery-iddata-image-id
JS Globals
bilych_gallery_params
Shortcode Output
[bilych_gallery]
FAQ

Frequently Asked Questions about Bilych Gallery