CTCL Image Gallery Security & Risk Analysis

wordpress.org/plugins/ctcl-image-gallery

Gutenberg block to add image gallery

100 active installs v2.2.1 PHP 7.0+ WP 6.2.2+ Updated Jun 16, 2025
blockctc-liteimage-gallery
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is CTCL Image Gallery Safe to Use in 2026?

Generally Safe

Score 100/100

CTCL Image Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'ctcl-image-gallery' plugin version 2.2.1 exhibits a remarkably strong security posture. The code analysis shows no dangerous functions, all SQL queries are prepared, and all output is properly escaped. Crucially, there are no identified flows with unsanitized paths in the taint analysis, and no external HTTP requests or file operations that could be exploited. The absence of any recorded vulnerabilities, including critical or high severity ones, further reinforces this positive assessment.

However, it is important to note the complete absence of any security checks such as nonces or capability checks. While the current code analysis reveals no immediate exploitable entry points, this lack of explicit security controls represents a potential weakness. If future versions introduce new features or if the plugin's interaction points change without proper authentication or authorization checks being implemented, the attack surface could become vulnerable. Therefore, while the current version is highly secure in its implementation, a lack of foundational security mechanisms warrants caution for future development.

In conclusion, version 2.2.1 of 'ctcl-image-gallery' appears to be very secure due to its clean code, proper sanitization and escaping, and a clean vulnerability history. The primary area for improvement lies in implementing robust authentication and authorization checks on any potential entry points, even if none are immediately apparent in this analysis. This would significantly strengthen its long-term security resilience.

Key Concerns

  • No Nonce checks detected
  • No Capability checks detected
Vulnerabilities
None known

CTCL Image Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CTCL Image Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

CTCL Image Gallery Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitctcl-image-gallery.php:26
Maintenance & Trust

CTCL Image Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 16, 2025
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

CTCL Image Gallery Developer Profile

UjW0L

17 plugins · 2K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CTCL Image Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ctcl-image-gallery/build/index.js/wp-content/plugins/ctcl-image-gallery/build/index.css
Version Parameters
ctcl-image-gallery/build/index.css?ver=ctcl-image-gallery/build/index.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about CTCL Image Gallery