
FancyBox Security & Risk Analysis
wordpress.org/plugins/fancy-boxEnables fancybox on all image links including BMP, GIF, JPG, JPEG, and PNG links.
Is FancyBox Safe to Use in 2026?
Use With Caution
Score 64/100FancyBox has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "fancy-box" v1.1.0 plugin exhibits a seemingly strong static security posture. The absence of detected dangerous functions, file operations, external HTTP requests, and a complete reliance on prepared statements for SQL queries are positive indicators. Furthermore, all identified outputs are properly escaped, and the taint analysis shows no vulnerabilities. However, the plugin's vulnerability history presents a significant concern. With one known and currently unpatched CVE, specifically a medium-severity Cross-Site Scripting (XSS) vulnerability, the overall security risk escalates considerably. The fact that the last vulnerability was reported in the future (2025-03-21) is an anomaly that requires further investigation but, assuming it represents a real historical issue, it points to a pattern of past security weaknesses that have not been remediated in this version. While the code itself appears clean in static analysis, the unaddressed CVE overshadows these strengths, indicating that users are exposed to known risks.
Key Concerns
- Currently unpatched CVE exists
- Medium severity CVE history
FancyBox Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
FancyBox <= 1.0.1 - Reflected Cross-Site Scripting
FancyBox Code Analysis
FancyBox Attack Surface
WordPress Hooks 3
Maintenance & Trust
FancyBox Maintenance & Trust
Maintenance Signals
Community Trust
FancyBox Alternatives
FancyBox for WordPress
fancybox-for-wordpress
Seamlessly integrates FancyBox lightbox into your WordPress blog: Upload, activate, and you're done. Additional configuration optional.
PhotoSwipe
photo-swipe
A very light implementation of PhotoSwipe javascript plugin for WordPress
Shutter Reloaded
shutter-reloaded
Darkens the current page and displays an image (like Lightbox, Thickbox, etc.), but is a lot smaller (10KB) and faster.
Slimbox
slimbox
Enables slimbox 2.03 on all image links including BMP, GIF, JPG, JPEG, and PNG links.
Slimbox Plugin
slimbox-plugin
Plugin used to overlay images on the current page into neat Javascript-powered overlay popups.
FancyBox Developer Profile
2 plugins · 5K total installs
How We Detect FancyBox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/fancy-box/jquery.fancybox.css/fancy-box/jquery.fancybox.js/fancy-box/jquery.easing.jsfancy-box/jquery.fancybox.css?ver=fancy-box/jquery.fancybox.js?ver=fancy-box/jquery.easing.js?ver=HTML / DOM Fingerprints
rel="fancybox"jQuery