Display CPG Thumbnails Security & Risk Analysis
wordpress.org/plugins/display-cpg-thumbnailsA widget that accesses your Coppermine Gallery and displays thumbnails on your Wordpress page.
Is Display CPG Thumbnails Safe to Use in 2026?
Generally Safe
Score 85/100Display CPG Thumbnails has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "display-cpg-thumbnails" plugin v1.0 demonstrates a mixed security posture. On the positive side, it exhibits excellent practices regarding SQL queries, exclusively using prepared statements, and it has no recorded vulnerability history, which is a strong indicator of a well-maintained and secure codebase over time. Furthermore, the static analysis shows a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without checks. However, significant concerns arise from the code analysis. The presence of the `create_function` dangerous function is a notable risk, as it can lead to arbitrary code execution if user-supplied input is ever used within it. Compounding this is the low percentage of properly escaped output, suggesting potential for cross-site scripting (XSS) vulnerabilities if dynamic content is displayed without adequate sanitization. The taint analysis, while not reporting critical or high severity issues, did identify flows with unsanitized paths, which, when combined with the poor output escaping, could still pose a risk.
Key Concerns
- Dangerous function create_function found
- Low percentage of properly escaped output
- Taint flows with unsanitized paths found
- No nonce checks found
- No capability checks found
Display CPG Thumbnails Security Vulnerabilities
Display CPG Thumbnails Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Display CPG Thumbnails Attack Surface
WordPress Hooks 1
Maintenance & Trust
Display CPG Thumbnails Maintenance & Trust
Maintenance Signals
Community Trust
Display CPG Thumbnails Alternatives
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Feeds for YouTube (YouTube video, channel, and gallery plugin)
feeds-for-youtube
The Feeds for YouTube plugin allows you to display customizable YouTube feeds from any YouTube channel.
Social Feed Gallery
insta-gallery
Formerly known as "Instagram Feed", this is the best plugin for displaying Instagram feeds on WordPress. It also supports Instagram reels.
WPZOOM Social Feed Widget & Block
instagram-widget-by-wpzoom
Instagram feed plugin for WordPress: Display your Instagram photos, videos & reels. Easy setup with Gutenberg block, widget, shortcode & Elementor
Meks Easy Photo Feed Widget
meks-easy-instagram-widget
Easily display Instagram photos as a widget that looks good in (almost) any WordPress theme.
Display CPG Thumbnails Developer Profile
2 plugins · 30 total installs
How We Detect Display CPG Thumbnails
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
displaycpgthumbnails