
EL-Gallery Security & Risk Analysis
wordpress.org/plugins/el-galleryEL-Gallery is an elegant untra-lightweight javascript & css gallery replacement for Wordpress.
Is EL-Gallery Safe to Use in 2026?
Generally Safe
Score 85/100EL-Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The el-gallery plugin version 1.5 exhibits a mixed security posture. On the positive side, it has a small attack surface with no identified AJAX handlers or REST API routes, and all SQL queries are properly prepared. The absence of known vulnerabilities in its history is also a significant strength, suggesting a generally well-maintained codebase. However, a critical concern arises from the complete lack of output escaping for all identified output points. This means any dynamic content displayed to users, particularly if it originates from user input or external sources, could be vulnerable to cross-site scripting (XSS) attacks. Additionally, the plugin lacks nonce checks, which could be exploited in conjunction with other weaknesses if an attack vector were present. While the taint analysis shows no critical or high-severity unsanitized flows, the unescaped output is a significant, directly observable risk.
Despite the absence of historical vulnerabilities and a clean taint analysis, the complete failure to escape output presents a tangible risk that cannot be overlooked. This deficiency, coupled with the lack of nonce checks, creates potential entry points for XSS attacks. The plugin's strengths lie in its limited attack surface and secure database interactions. Therefore, while the plugin is not riddled with known severe vulnerabilities, the unescaped output is a crucial area requiring immediate attention to mitigate potential security breaches. The overall security posture is therefore concerning due to the easily exploitable nature of unescaped output.
Key Concerns
- 0% output escaping
- 0 nonce checks
EL-Gallery Security Vulnerabilities
EL-Gallery Code Analysis
Output Escaping
Data Flow Analysis
EL-Gallery Attack Surface
Shortcodes 2
WordPress Hooks 4
Maintenance & Trust
EL-Gallery Maintenance & Trust
Maintenance Signals
Community Trust
EL-Gallery Alternatives
EWSEL Lightbox For Galleries
ewsel-lightbox-for-galleries
Makes the WordPress galleries use a lightbox script called ColorBox to display the fullsize images.
PrettyGallery
prettygallery
Integrate Wordpress default gallery shortcode ([gallery]) with jquery modal popup.
Image 3D Carousel
image-3d-carousel
Image 3D Carousel With Shortcode for WordPress.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Animate It!
animate-it
Add cool CSS3 animations to your content.
EL-Gallery Developer Profile
1 plugin · 10 total installs
How We Detect EL-Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/el-gallery/css/el-gallery.css/wp-content/plugins/el-gallery/css/el-icons.css/wp-content/plugins/el-gallery/js/el-gallery.jsel-gallery/style.css?ver=el-gallery/el-gallery.js?ver=HTML / DOM Fingerprints
el_galleryel_gallery-slideshow_wrapperel_navel_nav-leftel_loadingel_pauseel_nav-rightel_gallery-thumbnails_wrapper+8 more<!-- EL-Gallery Plugin -->itemprop="image"el_gallery_parameters<figure class="el_gallery<div class="el_gallery-slideshow_wrapper<div class="el_nav"><a href="#" class="el_nav-left">