
Featured Galleries Security & Risk Analysis
wordpress.org/plugins/featured-galleriesDo you like giving posts a Featured Image? Try out a Featured Gallery. It's like a Featured Images ... except as many images as you want.
Is Featured Galleries Safe to Use in 2026?
Generally Safe
Score 85/100Featured Galleries has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The featured-galleries v2.1.0 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no external HTTP requests or file operations. The plugin also includes nonce and capability checks, which are crucial for security.
However, significant concerns arise from the static analysis. The most critical finding is an unprotected AJAX handler, representing a substantial attack surface that could be exploited without authentication. Additionally, the analysis indicates unsanitized paths in taint flows, which, although not classified as critical or high severity in this report, is a red flag for potential path traversal or file inclusion vulnerabilities if not handled carefully. Furthermore, a concerning 0% of outputs are properly escaped, suggesting a high risk of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into user-facing content.
The vulnerability history for this plugin is clean, with no recorded CVEs. This lack of past issues is positive, but it does not negate the immediate risks identified in the current code analysis. The absence of historical vulnerabilities could be due to its obscurity, limited usage, or simply a recent period of good security practices. It's important to note that the current code's weaknesses, particularly the unescaped outputs and unprotected AJAX handler, are serious enough to warrant immediate attention regardless of past history.
Key Concerns
- Unprotected AJAX handler
- Unsanitized paths in taint flows
- 0% of outputs properly escaped
Featured Galleries Security Vulnerabilities
Featured Galleries Code Analysis
Output Escaping
Data Flow Analysis
Featured Galleries Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
Featured Galleries Maintenance & Trust
Maintenance Signals
Community Trust
Featured Galleries Alternatives
Require Featured Image
require-featured-image
Requires content you specify to have a featured image set before they can be published.
Insert Featured Image Shortcode
add-post-thumbnail-shortcode
Adds a shortcode to insert the post's featured image into the post's content.
Easy Featured Images
admin-featured-image
A small plugin to add featured images in the "All Posts" page.
Responsive Lightbox & Gallery
responsive-lightbox
The most popular lightbox plugin and responsive gallery builder for WordPress.
Quick Featured Images
quick-featured-images
The time-saving solution for managing tons of featured images within minutes: Set, replace and delete in bulk and set default images for future posts.
Featured Galleries Developer Profile
2 plugins · 3K total installs
How We Detect Featured Galleries
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/featured-galleries/assets/scripts/fg-admin.js/wp-content/plugins/featured-galleries/assets/stylesheets/fg-admin.css/wp-content/plugins/featured-galleries/assets/scripts/fg-admin.jsfeatured-galleries/assets/scripts/fg-admin.js?ver=featured-galleries/assets/stylesheets/fg-admin.css?ver=HTML / DOM Fingerprints
fg-post-galleryhide-if-no-jshide-if-jsdata-post_idfgInfoFromPHP