Xpro Gallery For Beaver Builder – Lite Security & Risk Analysis

wordpress.org/plugins/filterable-photo-gallery-beaver-builder-elementor

The Most Premium Gallery Addon for Your Beaver Builder Websites

100 active installs v1.4.2 PHP + WP 4.6+ Updated May 8, 2024
beaver-builder-free-gallerygallery-imagephoto-gallerywordpress-gallery-pluginwordpress-gallery-responsive-mobile-friendly
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Xpro Gallery For Beaver Builder – Lite Safe to Use in 2026?

Generally Safe

Score 85/100

Xpro Gallery For Beaver Builder – Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "filterable-photo-gallery-beaver-builder-elementor" plugin v1.4.2 exhibits a generally positive security posture based on the provided static analysis. Notably, there are no identified dangerous functions, raw SQL queries, file operations, external HTTP requests, or bundled libraries. The complete absence of reported CVEs and historical vulnerabilities further strengthens this assessment, suggesting a well-maintained and secure codebase. The attack surface is effectively zero, with no AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential for exploitation.

However, a critical concern arises from the complete lack of output escaping. With 77 total outputs and 0% properly escaped, this presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered by the plugin, especially if it originates from user input or external sources, is susceptible to malicious code injection. While the plugin has no historical vulnerabilities, this fundamental security flaw in output handling could be easily exploited. The absence of nonce and capability checks, while less critical given the zero attack surface, could become a concern if any entry points were to be introduced in future versions without proper authorization checks.

In conclusion, while the plugin demonstrates strong practices in many security areas, the severe lack of output escaping is a major weakness that needs immediate attention. The zero attack surface and clean vulnerability history are commendable, but they do not negate the inherent risks posed by unescaped output. Addressing this output escaping issue should be the highest priority to ensure the plugin's continued security.

Key Concerns

  • Output escaping: 0% properly escaped
  • Nonce checks: 0
  • Capability checks: 0
Vulnerabilities
None known

Xpro Gallery For Beaver Builder – Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Xpro Gallery For Beaver Builder – Lite Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Xpro Gallery For Beaver Builder – Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
77
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped77 total outputs
Attack Surface

Xpro Gallery For Beaver Builder – Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitclasses\class-xpro-gallery-lite-for-wp-init.php:18
actioninitfilterable-photo-gallery-beaver-builder-elementor.php:35
actionplugins_loadedfilterable-photo-gallery-beaver-builder-elementor.php:38
actionadmin_noticesfilterable-photo-gallery-beaver-builder-elementor.php:74
actionadmin_noticesfilterable-photo-gallery-beaver-builder-elementor.php:91
Maintenance & Trust

Xpro Gallery For Beaver Builder – Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 8, 2024
PHP min version
Downloads6K

Community Trust

Rating80/100
Number of ratings4
Active installs100
Developer Profile

Xpro Gallery For Beaver Builder – Lite Developer Profile

Xpro

7 plugins · 42K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
19 days
View full developer profile
Detection Fingerprints

How We Detect Xpro Gallery For Beaver Builder – Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/css/xpro-gallery-filter.css/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/js/xpro-gallery-filter.js/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/css/isotope.css/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/js/isotope.min.js/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/js/magnific-popup.min.js/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/css/magnific-popup.css
Script Paths
/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/js/xpro-gallery-filter.js/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/js/isotope.min.js/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/js/magnific-popup.min.js
Version Parameters
/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/css/xpro-gallery-filter.css?ver=/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/js/xpro-gallery-filter.js?ver=/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/css/isotope.css?ver=/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/js/isotope.min.js?ver=/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/js/magnific-popup.min.js?ver=/wp-content/plugins/filterable-photo-gallery-beaver-builder-elementor/assets/css/magnific-popup.css?ver=

HTML / DOM Fingerprints

CSS Classes
xpro-gallery-filter-wrapxpro-gallery-filter-content
Data Attributes
data-xpro-gallery-settings
JS Globals
XproGalleryFilter
FAQ

Frequently Asked Questions about Xpro Gallery For Beaver Builder – Lite