
Full Screen Galleries Security & Risk Analysis
wordpress.org/plugins/full-screen-galleriesFull Screen Galleries creates an automatic full-screen slideshow mode for image galleries in your content. Posts and pages with galleries are automati …
Is Full Screen Galleries Safe to Use in 2026?
Generally Safe
Score 92/100Full Screen Galleries has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "full-screen-galleries" v1.3 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and ensuring all output is properly escaped. There are also no recorded historical vulnerabilities, suggesting a generally stable development history. The absence of file operations and external HTTP requests further reduces potential attack vectors.
However, significant security concerns arise from the plugin's attack surface. It exposes two AJAX handlers, both of which lack any form of authentication or capability checks. This creates a substantial risk of unauthorized actions being performed by unauthenticated users, which is a critical oversight. The lack of nonce checks on these AJAX endpoints compounds this vulnerability, making them susceptible to CSRF attacks.
Despite the positive aspects of its code hygiene, the unprotected AJAX endpoints represent a serious weakness. While there are no recorded CVEs, the current implementation provides an easy entry point for attackers. A balanced conclusion would note the strong data handling and output sanitization but highlight the critical deficiency in securing its AJAX entry points, necessitating immediate attention to prevent exploitation.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
Full Screen Galleries Security Vulnerabilities
Full Screen Galleries Code Analysis
Output Escaping
Full Screen Galleries Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Full Screen Galleries Maintenance & Trust
Maintenance Signals
Community Trust
Full Screen Galleries Alternatives
ACF Galerie 4
acf-galerie-4
Enhance your WordPress website with ACF Galerie 4, a powerful and customizable gallery plugin.
Polaroid Gallery
polaroid-gallery
Polaroid Gallery is a CSS3 & jQuery Image Gallery plugin for WordPress Media Library.
Scissors and Watermark
scissors-watermark
Scissors and Watermark enhances WordPress' handling of images by introducing cropping, resizing, rotating, and watermarking functionality.
Automatic Alternative Text
automatic-alternative-text
Automatically generate alt text for images with Microsoft's Cognitive Services Computer Vision API.
ImageSnippets Gallery Block
is-gallery
Dynamic block to create an ImageSnippets gallery
Full Screen Galleries Developer Profile
27 plugins · 24K total installs
How We Detect Full Screen Galleries
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/full-screen-galleries/full-screen-galleries.css/wp-content/plugins/full-screen-galleries/full-screen-galleries.js/wp-content/plugins/full-screen-galleries/full-screen-galleries.jsfull-screen-galleries/full-screen-galleries.css?ver=full-screen-galleries/full-screen-galleries.js?ver=HTML / DOM Fingerprints
fsg-launchscreen-reader-text translators: %1$s is the current slide number and %2$s is the total number of slides id="fsg-container"id="full-screen-gallery"id="fsg-navigation"id="fsg-close"id="fsg-open-full"id="fsg-next"+9 morewindow.fsg_single_image_template