DDevs Media Gallery Security & Risk Analysis

wordpress.org/plugins/ddevs-media-gallery

This plugin will add Image, Video gallery items in your WordPress site using shortcodes and custom post.

10 active installs v1.2 PHP + WP 3.8.3+ Updated Nov 8, 2014
gallerygallery-effectimage-galleryvideo-galleryyoutube-gallery
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DDevs Media Gallery Safe to Use in 2026?

Generally Safe

Score 85/100

DDevs Media Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the "ddevs-media-gallery" v1.2 plugin exhibits a strong security posture. The absence of any dangerous functions, raw SQL queries, unsanitized taint flows, and the presence of 100% proper output escaping are all positive indicators. Furthermore, the plugin has no known CVEs, indicating a history of secure development or prompt patching. The limited attack surface, with only one shortcode and no unprotected entry points, further contributes to its favorable security profile. The lack of bundled libraries also eliminates a common vector for vulnerabilities.

While the overall security is good, the complete absence of nonce checks and capability checks across all entry points, including the shortcode, represents a notable area for improvement. Although the static analysis did not identify any immediate exploitable vulnerabilities stemming from this, these checks are fundamental to WordPress security and protect against common attacks like Cross-Site Request Forgery (CSRF) and unauthorized privilege escalation. The plugin could be further hardened by implementing these standard security measures.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
Vulnerabilities
None known

DDevs Media Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

DDevs Media Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

DDevs Media Gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ddmgallery] index.php:41
WordPress Hooks 2
actioninitindex.php:19
actionwp_headindex.php:28
Maintenance & Trust

DDevs Media Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedNov 8, 2014
PHP min version
Downloads2K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

DDevs Media Gallery Developer Profile

SaWKaT

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DDevs Media Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ddevs-media-gallery/css/lightGallery.min.css/wp-content/plugins/ddevs-media-gallery/js/lightGallery.min.js
Script Paths
/wp-content/plugins/ddevs-media-gallery/js/lightGallery.min.js

HTML / DOM Fingerprints

CSS Classes
ddm_videoddm_imggallerylist-unstyled
Data Attributes
data-htmldata-responsive-srcdata-src
JS Globals
jQuery
Shortcode Output
<ul id='lightGallery
FAQ

Frequently Asked Questions about DDevs Media Gallery