Document Gallery for Real Media Library Security & Risk Analysis

wordpress.org/plugins/dg-real-media-library

Create a gallery of documents from a folder in your media library created with Real Media Library.

100 active installs v1.0.0 PHP + WP 4.0+ Updated Mar 27, 2020
documentdocument-galleryfilesmediareal-media-library
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Document Gallery for Real Media Library Safe to Use in 2026?

Generally Safe

Score 85/100

Document Gallery for Real Media Library has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'dg-real-media-library' plugin version 1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, unsanitized output, file operations, external HTTP requests, and the complete reliance on prepared statements for SQL queries are all positive indicators. Furthermore, the lack of any recorded vulnerabilities in its history, including critical or high severity issues, suggests a commitment to secure development or simply a lack of prior exploitation attempts. The plugin also demonstrates good practice by not bundling external libraries, which can often be a source of vulnerabilities if not kept up-to-date.

However, the analysis reveals a complete absence of any detected entry points such as AJAX handlers, REST API routes, shortcodes, or cron events. While this indicates a minimal attack surface, it also means there are no capability checks or nonce checks being enforced across any potential interactions. This is a significant gap. The static analysis also reported zero taint flows and zero analyzed flows, which, while positive in that no vulnerabilities were found, also suggests limited complexity in the plugin's functionality or the analysis's scope. The plugin's strengths lie in its clean code and lack of historical vulnerabilities, but the absence of any authentication or authorization checks on the (currently non-existent) entry points is a critical weakness if functionality is ever added that interacts with the WordPress environment.

Key Concerns

  • No nonce checks on any entry points
  • No capability checks on any entry points
Vulnerabilities
None known

Document Gallery for Real Media Library Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Document Gallery for Real Media Library Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Document Gallery for Real Media Library Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitindex.php:24
actionadmin_noticesindex.php:30
actionadmin_noticesindex.php:34
actiondg_queryindex.php:38
Maintenance & Trust

Document Gallery for Real Media Library Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMar 27, 2020
PHP min version
Downloads6K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Document Gallery for Real Media Library Developer Profile

Matthias Günter

5 plugins · 4K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Document Gallery for Real Media Library

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
notice-erroris-dismissible
FAQ

Frequently Asked Questions about Document Gallery for Real Media Library