
Fegallery – Featured Gallery Security & Risk Analysis
wordpress.org/plugins/fegalleryA simple WordPress image gallery with lightbox.
Is Fegallery – Featured Gallery Safe to Use in 2026?
Generally Safe
Score 85/100Fegallery – Featured Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The fegallery plugin v1.1.1 demonstrates a generally positive security posture based on the provided static analysis. The absence of known vulnerabilities in its history is a significant strength. The plugin utilizes prepared statements for all SQL queries, and has included nonce and capability checks, indicating good development practices for preventing common web attacks. The limited attack surface, consisting of a single shortcode and no exposed AJAX handlers or REST API routes, further enhances its security.
However, a notable concern is the significantly low rate of proper output escaping. With only 6% of 33 outputs properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the plugin that originates from user input or external sources could be injected with malicious scripts. While taint analysis showed no issues, this is likely due to the limited scope of the analysis (0 flows analyzed), and the low output escaping rate strongly suggests potential vulnerabilities that were not detected by this specific analysis method. The presence of the Select2 library, while bundled, does not inherently pose a risk without further analysis of its version and potential known vulnerabilities within the library itself.
In conclusion, the plugin's historical lack of vulnerabilities and good handling of SQL and authentication mechanisms are commendable. The primary and most significant weakness identified is the poor output escaping, which presents a tangible risk of XSS. Further investigation into the specific instances of unescaped output is highly recommended to fully mitigate potential security threats.
Key Concerns
- Low output escaping rate (6%)
- Bundled library (Select2) without version check
Fegallery – Featured Gallery Security Vulnerabilities
Fegallery – Featured Gallery Code Analysis
Bundled Libraries
Output Escaping
Fegallery – Featured Gallery Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Fegallery – Featured Gallery Maintenance & Trust
Maintenance Signals
Community Trust
Fegallery – Featured Gallery Alternatives
Gallery by FooGallery
foogallery
Photo Gallery, Image Gallery by FooGallery — fast, responsive, SEO-optimized, and packed with beautiful layouts.
Additional Variation Images Gallery for WooCommerce
woo-variation-gallery
Allows inserting multiple images per variation to let your store customers to see different sets of images when WooCommerce product variations are swi …
Album Gallery For Flickr
flickr-album-gallery
Display Flickr albums on WordPress with lightbox preview, SEO-friendly galleries, and easy shortcode integration.
Album Gallery
new-album-gallery
Create stunning photo and video albums with responsive layouts, lightbox display, and customizable hover effects.
Image Gallery
new-image-gallery
Create responsive image galleries with lightbox, grid & masonry layouts. Easy shortcode display for posts and pages.
Fegallery – Featured Gallery Developer Profile
4 plugins · 130 total installs
How We Detect Fegallery – Featured Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fegallery/lib/style-admin.css/wp-content/plugins/fegallery/lib/lightbox2/css/lightbox.min.css/wp-content/plugins/fegallery/lib/style-frontend.css/wp-content/plugins/fegallery/lib/lightbox2/js/lightbox.min.js/wp-content/plugins/fegallery/lib/script-frontend.js/wp-content/plugins/fegallery/lib/lightbox2/js/lightbox.min.js/wp-content/plugins/fegallery/lib/script-frontend.jsfegallery/lib/style-admin.css?ver=fegallery/lib/lightbox2/css/lightbox.min.css?ver=fegallery/lib/style-frontend.css?ver=fegallery/lib/lightbox2/js/lightbox.min.js?ver=fegallery/lib/script-frontend.js?ver=HTML / DOM Fingerprints
harislab-fegalleryfegallery_noncename<div class="harislab-fegallery">[gallery ids=link='file'