
FlowGallery Security & Risk Analysis
wordpress.org/plugins/flowgalleryAutomatically creates an image gallery from any folder on your Wordpress Server in Flow Layout
Is FlowGallery Safe to Use in 2026?
Generally Safe
Score 100/100FlowGallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "flowgallery" plugin v1.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known vulnerabilities (CVEs) and the lack of critical or high-severity issues in taint analysis are positive indicators. The plugin also avoids potentially risky operations like file operations, external HTTP requests, and raw SQL queries. However, there are areas for improvement. The static analysis reveals that 75% of outputs are properly escaped, implying that 25% are not, which could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data reaches these unescaped outputs. Furthermore, the plugin has 0 nonce checks and 0 capability checks, meaning that its single shortcode entry point, while currently not directly exposed via AJAX or REST API, is not protected against unauthorized or unintended execution, which could be a concern if the shortcode's functionality is sensitive.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
FlowGallery Security Vulnerabilities
FlowGallery Code Analysis
Output Escaping
FlowGallery Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
FlowGallery Maintenance & Trust
Maintenance Signals
Community Trust
FlowGallery Alternatives
No alternatives data available yet.
FlowGallery Developer Profile
2 plugins · 30 total installs
How We Detect FlowGallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flowgallery/fancybox/jquery.fancybox.pack.js/wp-content/plugins/flowgallery/fancybox/jquery.fancybox.css/wp-content/plugins/flowgallery/js/masonry.pkgd.min.js/wp-content/plugins/flowgallery/fancybox/jquery.fancybox.pack.js/wp-content/plugins/flowgallery/js/masonry.pkgd.min.jsflowgallery/style.css?ver=flowgallery/js/masonry.pkgd.min.js?ver=flowgallery/fancybox/jquery.fancybox.pack.js?ver=flowgallery/fancybox/jquery.fancybox.css?ver=HTML / DOM Fingerprints
photogriditemshadeddata-fancybox-hrefjQuerymasonry<div class='photogrid'<div class='item shaded'<div class='item'<a href='