FancyBox Gallery Security & Risk Analysis

wordpress.org/plugins/fancybox-gallery

Integrates the FancyBox jQuery plugin to generate dynamic pop-up image overlays for WordPress galleries.

400 active installs v0.3.2 PHP + WP 2.8+ Updated Aug 26, 2015
fancyboxgalleriesgallerylightboxphotos
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FancyBox Gallery Safe to Use in 2026?

Generally Safe

Score 85/100

FancyBox Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'fancybox-gallery' v0.3.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, nonce checks, or capability checks is a significant positive. Furthermore, the taint analysis revealing zero flows with unsanitized paths indicates a robust approach to preventing injection vulnerabilities. The plugin's attack surface appears to be nonexistent, with no identifiable entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are not properly secured.

The vulnerability history is equally impressive, with no recorded CVEs of any severity. This suggests a history of secure development or prompt patching of any discovered issues. The presence of jQuery v1.3.2, however, is a notable concern. This version is significantly outdated and known to have numerous vulnerabilities, potentially exposing the site to risks if specific jQuery exploits are targeted at this older version. While the plugin itself shows no direct vulnerabilities, relying on an outdated bundled library introduces an indirect risk.

In conclusion, 'fancybox-gallery' v0.3.2 is remarkably secure in its own code, demonstrating excellent development practices for handling data and interactions. The primary weakness lies in its bundled, outdated jQuery library. Users should be aware that while the plugin's core logic is sound, the underlying dependency presents a potential attack vector. Addressing the outdated jQuery library would elevate the plugin's security to an even higher standard.

Key Concerns

  • Bundled outdated jQuery library
Vulnerabilities
None known

FancyBox Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

FancyBox Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery1.3.2
Attack Surface

FancyBox Gallery Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterwp_get_attachment_linkfancybox-gallery.php:23
actioninitfancybox-gallery.php:65
Maintenance & Trust

FancyBox Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedAug 26, 2015
PHP min version
Downloads56K

Community Trust

Rating94/100
Number of ratings3
Active installs400
Developer Profile

FancyBox Gallery Developer Profile

Dougal Campbell

5 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FancyBox Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fancybox-gallery/fancybox/jquery.fancybox-1.2.1.js/wp-content/plugins/fancybox-gallery/fancybox/jquery.easing.1.3.js/wp-content/plugins/fancybox-gallery/fbg-init.js/wp-content/plugins/fancybox-gallery/fancybox/jquery.fancybox.css/wp-content/plugins/fancybox-gallery/fbg-override.css
Script Paths
/wp-content/plugins/fancybox-gallery/fancybox/jquery.fancybox-1.2.1.js/wp-content/plugins/fancybox-gallery/fancybox/jquery.easing.1.3.js/wp-content/plugins/fancybox-gallery/fbg-init.js
Version Parameters
fancybox-gallery/fancybox/jquery.fancybox-1.2.1.js?ver=fancybox-gallery/fancybox/jquery.easing.1.3.js?ver=fancybox-gallery/fbg-init.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about FancyBox Gallery