FlowGallery Security & Risk Analysis

wordpress.org/plugins/flowgallery

Automatically creates an image gallery from any folder on your Wordpress Server in Flow Layout

10 active installs v1.2 PHP + WP 2.5+ Updated Apr 8, 2025
cascading-layout-galleryflow-gallerymasonry-jspicture-gallery
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FlowGallery Safe to Use in 2026?

Generally Safe

Score 100/100

FlowGallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12mo ago
Risk Assessment

The "flowgallery" plugin v1.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known vulnerabilities (CVEs) and the lack of critical or high-severity issues in taint analysis are positive indicators. The plugin also avoids potentially risky operations like file operations, external HTTP requests, and raw SQL queries. However, there are areas for improvement. The static analysis reveals that 75% of outputs are properly escaped, implying that 25% are not, which could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data reaches these unescaped outputs. Furthermore, the plugin has 0 nonce checks and 0 capability checks, meaning that its single shortcode entry point, while currently not directly exposed via AJAX or REST API, is not protected against unauthorized or unintended execution, which could be a concern if the shortcode's functionality is sensitive.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

FlowGallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FlowGallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped4 total outputs
Attack Surface

FlowGallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[flowgallery] FlowGallery.php:122
WordPress Hooks 3
actionwp_footerFlowGallery.php:43
actionadmin_menuoptions.php:3
actionadmin_initoptions.php:12
Maintenance & Trust

FlowGallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 8, 2025
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

FlowGallery Alternatives

No alternatives data available yet.

Developer Profile

FlowGallery Developer Profile

klemmkeil

2 plugins · 30 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect FlowGallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flowgallery/fancybox/jquery.fancybox.pack.js/wp-content/plugins/flowgallery/fancybox/jquery.fancybox.css/wp-content/plugins/flowgallery/js/masonry.pkgd.min.js
Script Paths
/wp-content/plugins/flowgallery/fancybox/jquery.fancybox.pack.js/wp-content/plugins/flowgallery/js/masonry.pkgd.min.js
Version Parameters
flowgallery/style.css?ver=flowgallery/js/masonry.pkgd.min.js?ver=flowgallery/fancybox/jquery.fancybox.pack.js?ver=flowgallery/fancybox/jquery.fancybox.css?ver=

HTML / DOM Fingerprints

CSS Classes
photogriditemshaded
Data Attributes
data-fancybox-href
JS Globals
jQuerymasonry
Shortcode Output
<div class='photogrid'<div class='item shaded'<div class='item'<a href='
FAQ

Frequently Asked Questions about FlowGallery