
Contributors Gallery – The Ultimate WordPress Contributors Showcase Security & Risk Analysis
wordpress.org/plugins/contributors-galleryDisplay WordPress contributors beautifully with live profiles, avatars, and powerful search. Showcase the people who make WordPress great.
Is Contributors Gallery – The Ultimate WordPress Contributors Showcase Safe to Use in 2026?
Generally Safe
Score 92/100Contributors Gallery – The Ultimate WordPress Contributors Showcase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'contributors-gallery' plugin version 1.2.0 exhibits a strong security posture in several key areas. The static analysis indicates robust implementation of prepared statements for all SQL queries and complete output escaping, which significantly mitigates risks of SQL injection and cross-site scripting (XSS). The absence of known vulnerabilities in its history further reinforces this positive assessment. However, there are areas for improvement. The presence of three unsanitized path flows identified in the taint analysis is a notable concern, even though they are not classified as critical or high severity. This suggests potential for information disclosure or unintended file access if these paths are manipulated by an attacker. Additionally, while nonce checks are present, they are not applied to all AJAX handlers, leaving them potentially vulnerable to CSRF attacks.
Overall, the plugin demonstrates good development practices regarding data sanitization and output handling. The lack of historical vulnerabilities is a positive indicator of ongoing security awareness. The primary concerns stem from the identified unsanitized path flows and the incomplete nonce protection on AJAX endpoints. These represent potential entry points that, while not currently exploited or critically flagged, could be leveraged by attackers. Addressing these specific weaknesses would further enhance the plugin's security, moving it towards a more secure and resilient state.
Key Concerns
- Unsanitized path flows found
- Missing nonce checks on some AJAX handlers
Contributors Gallery – The Ultimate WordPress Contributors Showcase Security Vulnerabilities
Contributors Gallery – The Ultimate WordPress Contributors Showcase Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Contributors Gallery – The Ultimate WordPress Contributors Showcase Attack Surface
AJAX Handlers 4
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
Contributors Gallery – The Ultimate WordPress Contributors Showcase Maintenance & Trust
Maintenance Signals
Community Trust
Contributors Gallery – The Ultimate WordPress Contributors Showcase Alternatives
No alternatives data available yet.
Contributors Gallery – The Ultimate WordPress Contributors Showcase Developer Profile
10 plugins · 400 total installs
How We Detect Contributors Gallery – The Ultimate WordPress Contributors Showcase
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contributors-gallery/assets/css/wpcg-styles.css/wp-content/plugins/contributors-gallery/assets/js/wpcg-contributors-handler.js/wp-content/plugins/contributors-gallery/assets/css/wpcg-search-styles.css/wp-content/plugins/contributors-gallery/assets/js/wpcg-search-handler.jsHTML / DOM Fingerprints
wpcg-gallerywpcg-gallery__containerwpcg-gallery__version-switcherwpcg-contributors__search-formwpcg-contributors__search-inputwpcg-contributors__search-buttonwpcg-contributors__resultswpcg-contributors__list+4 moredata-versiondata-noncewpcg_ajaxwpcg_search_ajax/wp-json/wpcg/v1/contributors[wpcg_contributors][wpcg_contributor_search]