Embed Google Photos album Security & Risk Analysis

wordpress.org/plugins/embed-google-photos-album-easily

Embed Google Photos album using Player widget.

4K active installs v2.2.1 PHP 5.3+ WP 5.0+ Updated Mar 19, 2024
carousel-slideshowembed-galleryembed-google-photosgoogle-photoswordpress-carousel
84
B · Generally Safe
CVEs total1
Unpatched0
Last CVEApr 22, 2024
Safety Verdict

Is Embed Google Photos album Safe to Use in 2026?

Mostly Safe

Score 84/100

Embed Google Photos album is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVELast CVE: Apr 22, 2024Updated 2yr ago
Risk Assessment

The 'embed-google-photos-album-easily' plugin version 2.2.1 presents a mixed security posture. On the positive side, static analysis reveals good practices in key areas such as the absence of dangerous functions, 100% use of prepared statements for SQL queries, and proper output escaping for all identified outputs. The plugin also avoids file operations and does not appear to bundle external libraries, which reduces potential attack vectors. However, concerns arise from the lack of nonce checks and capability checks across its entry points, particularly the single shortcode. Furthermore, the presence of external HTTP requests without explicit security checks introduces a potential risk.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
  • External HTTP Request
Vulnerabilities
1

Embed Google Photos album Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-32775medium · 6.4Server-Side Request Forgery (SSRF)

Embed Google Photos album <= 2.1.9 - Authenticated (Contributor+) Server-Side Request Forgery

Apr 22, 2024 Patched in 2.2.1 (9d)
Code Analysis
Analyzed Mar 16, 2026

Embed Google Photos album Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

Embed Google Photos album Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[embed-google-photos-album] pavex-embed-google-photos-album.php:31
WordPress Hooks 2
actioninitpavex-embed-google-photos-album.php:276
actionsave_postpavex-embed-google-photos-album.php:284
Maintenance & Trust

Embed Google Photos album Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 19, 2024
PHP min version5.3
Downloads46K

Community Trust

Rating88/100
Number of ratings15
Active installs4K
Developer Profile

Embed Google Photos album Developer Profile

pavex

2 plugins · 4K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
9 days
View full developer profile
Detection Fingerprints

How We Detect Embed Google Photos album

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://cdn.jsdelivr.net/npm/publicalbum@latest/embed-ui.min.js

HTML / DOM Fingerprints

CSS Classes
pa-gallery-player-widgetpa-carousel-widget
HTML Comments
<!-- publicalbum.org -->
Data Attributes
data-linkdata-founddata-titledata-autoplaydata-delaydata-repeat+5 more
Shortcode Output
<div class="pa-gallery-player-widget"<div class="pa-carousel-widget"
FAQ

Frequently Asked Questions about Embed Google Photos album