Gallery for Google Photos – Import and Showcase Photo Albums Security & Risk Analysis

wordpress.org/plugins/embed-google-photos

Embed stunning Google Photos galleries directly into your WordPress site with the Embed Google Photos plugin.

1K active installs v1.0.9 PHP 7.1+ WP 6.5+ Updated Feb 26, 2026
blockgallerygoogle-photosgutenberg-blockphotos
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Gallery for Google Photos – Import and Showcase Photo Albums Safe to Use in 2026?

Generally Safe

Score 100/100

Gallery for Google Photos – Import and Showcase Photo Albums has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "embed-google-photos" v1.0.9 plugin exhibits a generally strong security posture based on the static analysis and vulnerability history provided. The plugin demonstrates good practices by implementing 100% output escaping and using prepared statements for all SQL queries, which are critical for preventing common web vulnerabilities like cross-site scripting (XSS) and SQL injection. The absence of file operations and dangerous functions further enhances its security. The fact that there are no recorded CVEs, and therefore no currently unpatched vulnerabilities, is a significant positive indicator of the plugin's maintenance and security record.

However, there are a few areas that warrant attention. The presence of 3 AJAX handlers, while currently reported as having no unprotected entry points and passing nonce checks (implied by the presence of 2 nonces checks), could still be a potential area for future attacks if checks are ever removed or bypassed. The lack of capability checks on AJAX handlers, despite the presence of nonce checks, is a weakness. While nonces prevent CSRF, they don't inherently restrict access to logged-in users with specific roles. A missing capability check could allow users who shouldn't have access to perform actions if they can obtain a valid nonce.

In conclusion, the plugin is well-developed with strong foundational security practices. The main concern lies in the potential for privilege escalation if capability checks are not robustly implemented on AJAX actions, especially since the attack surface is entirely reliant on nonce checks for authorization. While the vulnerability history is excellent, the absence of capability checks on the AJAX endpoints represents a demonstrable, albeit currently mitigated, risk.

Key Concerns

  • AJAX handlers lack capability checks
Vulnerabilities
None known

Gallery for Google Photos – Import and Showcase Photo Albums Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gallery for Google Photos – Import and Showcase Photo Albums Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped14 total outputs
Attack Surface

Gallery for Google Photos – Import and Showcase Photo Albums Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_bpgpb_retrieve_access_tokenGoogleAPI\google-api.php:13
noprivwp_ajax_bpgpb_retrieve_access_tokenGoogleAPI\google-api.php:14
authwp_ajax_retrieve_refresh_tokenGoogleAPI\google-api.php:15
WordPress Hooks 2
actionenqueue_block_assetsembed-google-photos.php:24
actioninitembed-google-photos.php:25
Maintenance & Trust

Gallery for Google Photos – Import and Showcase Photo Albums Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.1
Downloads8K

Community Trust

Rating60/100
Number of ratings5
Active installs1K
Developer Profile

Gallery for Google Photos – Import and Showcase Photo Albums Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Gallery for Google Photos – Import and Showcase Photo Albums

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/embed-google-photos/dist/style.css/wp-content/plugins/embed-google-photos/dist/script.js/wp-content/plugins/embed-google-photos/dist/editor.css
Script Paths
/wp-content/plugins/embed-google-photos/dist/script.js
Version Parameters
embed-google-photos/dist/style.css?ver=embed-google-photos/dist/script.js?ver=embed-google-photos/dist/editor.css?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-bpgpb-google-photos
Data Attributes
data-attributesdata-info
Shortcode Output
<div class='wp-block-bpgpb-google-photosid='BPGPBBlockDirectory-data-attributes='data-info='
FAQ

Frequently Asked Questions about Gallery for Google Photos – Import and Showcase Photo Albums