blueimp lightbox Security & Risk Analysis

wordpress.org/plugins/blueimp-lightbox

Official blueimp Gallery lightbox for Wordpress.

1K active installs v1.1.1 PHP + WP 3.6.1+ Updated Sep 4, 2014
desktoplightboxmobileresponsiveswipe
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is blueimp lightbox Safe to Use in 2026?

Generally Safe

Score 85/100

blueimp lightbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'blueimp-lightbox' plugin v1.1.1 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The static analysis reveals a complete absence of common attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events, indicating a very limited attack surface. Furthermore, the code demonstrates excellent security practices, with no dangerous functions, all SQL queries using prepared statements, and all outputs properly escaped. The absence of file operations, external HTTP requests, nonce checks, and capability checks further reinforces this good security hygiene, although the lack of these checks is not a concern given the absence of entry points that would necessitate them. The plugin also has a clean vulnerability history with zero recorded CVEs, suggesting a history of secure development and maintenance. This combination of a minimal attack surface, robust coding practices, and a spotless vulnerability record leads to a very low-risk assessment. The plugin appears to be well-developed and secure.

Vulnerabilities
None known

blueimp lightbox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

blueimp lightbox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

blueimp lightbox Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

blueimp lightbox Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.0
Last updatedSep 4, 2014
PHP min version
Downloads23K

Community Trust

Rating88/100
Number of ratings16
Active installs1K
Developer Profile

blueimp lightbox Developer Profile

blueimp

1 plugin · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect blueimp lightbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/blueimp-lightbox/css/blueimp-lightbox.css/wp-content/plugins/blueimp-lightbox/js/blueimp-lightbox.min.js
Script Paths
/wp-content/plugins/blueimp-lightbox/js/blueimp-lightbox.min.js
Version Parameters
blueimp-lightbox/css/blueimp-lightbox.css?ver=blueimp-lightbox/js/blueimp-lightbox.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
blueimp-galleryblueimp-gallery-indicatorblueimp-gallery-controlsblueimp-gallery-downloadblueimp-gallery-closeblueimp-gallery-prevblueimp-gallery-nextblueimp-gallery-play+1 more
Data Attributes
data-gallerydata-start-index
JS Globals
blueimp.Gallery
FAQ

Frequently Asked Questions about blueimp lightbox