
Code Pixelz Simple Responsive Image Gallery Plugin Security & Risk Analysis
wordpress.org/plugins/cpm-galleryAdd gallery feature to your website. Supports lightbox and shortcodes to display your gallery images anywhere.
Is Code Pixelz Simple Responsive Image Gallery Plugin Safe to Use in 2026?
Generally Safe
Score 85/100Code Pixelz Simple Responsive Image Gallery Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cpm-gallery" plugin v2.3 exhibits a generally good security posture based on the provided static analysis. There are no known critical or high-severity vulnerabilities in its history, and the code analysis shows no dangerous functions, no direct SQL queries without prepared statements, no file operations, and no external HTTP requests. The lack of critical or high taint flows is also a positive indicator. The plugin correctly identifies one entry point (a shortcode) but also correctly notes that none of these entry points are unprotected, and there are no unpatched CVEs. This suggests a proactive approach to security by the developers.
However, there are a few areas for improvement. The low percentage of properly escaped output (14%) is a significant concern. This means that user-supplied data displayed on the frontend or within the admin area could be vulnerable to cross-site scripting (XSS) attacks if not handled carefully by the plugin's logic. Additionally, the complete absence of nonce checks, while not directly flagged as a vulnerability in this specific analysis, is a deviation from best practices for securing actions within WordPress, especially if the shortcode has any interactive elements or performs actions on submission.
In conclusion, "cpm-gallery" v2.3 demonstrates strengths in preventing common vulnerabilities like direct SQL injection and external request abuse. Its clean vulnerability history further bolsters confidence. The primary weaknesses lie in the inadequate output escaping, which poses an XSS risk, and the missing nonce checks, which, while not leading to immediate deductions based on this data alone, represent a potential area of concern for securing actions. The plugin's limited attack surface (one shortcode) and clear indication of capability checks are positive mitigating factors.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on entry points
Code Pixelz Simple Responsive Image Gallery Plugin Security Vulnerabilities
Code Pixelz Simple Responsive Image Gallery Plugin Code Analysis
Output Escaping
Code Pixelz Simple Responsive Image Gallery Plugin Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Code Pixelz Simple Responsive Image Gallery Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Code Pixelz Simple Responsive Image Gallery Plugin Alternatives
Gallery by FooGallery
foogallery
Photo Gallery, Image Gallery by FooGallery — fast, responsive, SEO-optimized, and packed with beautiful layouts.
Album Gallery For Flickr
flickr-album-gallery
Display Flickr albums on WordPress with lightbox preview, SEO-friendly galleries, and easy shortcode integration.
Album Gallery
new-album-gallery
Create stunning photo and video albums with responsive layouts, lightbox display, and customizable hover effects.
Image Gallery
new-image-gallery
Create responsive image galleries with lightbox, grid & masonry layouts. Easy shortcode display for posts and pages.
Lightbox slider – Responsive Lightbox Gallery
simple-lightbox-gallery
Lightbox slider plugin is allow users to view larger versions of images, simple slide shows and Gallery view with Responsive grid layout.
Code Pixelz Simple Responsive Image Gallery Plugin Developer Profile
2 plugins · 110 total installs
How We Detect Code Pixelz Simple Responsive Image Gallery Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cpm-gallery/css/codegallery.css/wp-content/plugins/cpm-gallery/css/blueimp-gallery.min.css/wp-content/plugins/cpm-gallery/css/blueimp-gallery-indicator.css/wp-content/plugins/cpm-gallery/js/upload.js/wp-content/plugins/cpm-gallery/js/blueimp-gallery.js/wp-content/plugins/cpm-gallery/js/blueimp-gallery-vimeo.js/wp-content/plugins/cpm-gallery/js/upload.js/wp-content/plugins/cpm-gallery/js/blueimp-gallery.js/wp-content/plugins/cpm-gallery/js/blueimp-gallery-vimeo.jsHTML / DOM Fingerprints
code-gallery-attachmentCopyright 2014 codepixelzmedia (email : info@codepixelz.market)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License, version 2, aspublished by the Free Software Foundation.+13 morecode-gallery-attachment