Fullscreen Galleria Security & Risk Analysis

wordpress.org/plugins/fullscreen-galleria

A simple fullscreen gallery to Wordpress

900 active installs v1.6.12 PHP + WP 4.0+ Updated Dec 12, 2023
galleriagalleryimagesphotography
85
A · Safe
CVEs total1
Unpatched0
Last CVEMar 25, 2024
Safety Verdict

Is Fullscreen Galleria Safe to Use in 2026?

Generally Safe

Score 85/100

Fullscreen Galleria has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 25, 2024Updated 2yr ago
Risk Assessment

The "fullscreen-galleria" plugin version 1.6.12 exhibits a mixed security posture. While the static analysis reveals no critical issues like dangerous functions, direct SQL injection vulnerabilities through prepared statements, or insecure file operations, there are notable areas of concern. The absence of any nonce checks or capability checks across its entry points, including four shortcodes, is a significant weakness. This means that users, even those with limited privileges, could potentially trigger functionality within these shortcodes without proper authorization, opening the door to unintended actions.

The plugin's vulnerability history shows one medium-severity Cross-Site Scripting (XSS) vulnerability, most recently patched on March 25, 2024. While the current version is unpatched for this specific CVE, the presence of past XSS issues coupled with the lack of input sanitization and output escaping in a significant portion (35%) of its outputs suggests a recurring pattern of insecure handling of user-supplied data. The static analysis also indicates that all SQL queries are executed without prepared statements, which, while not directly leading to an exploit in this analysis, represents a bad practice that could be exploited in conjunction with other vulnerabilities.

In conclusion, the plugin has some strengths in avoiding explicitly dangerous functions and external requests. However, the lack of robust authorization checks on its entry points, the historical pattern of XSS vulnerabilities, and the pervasive use of raw SQL queries without prepared statements present considerable risks. These issues suggest that the plugin requires further security hardening to ensure the safety of WordPress sites using it.

Key Concerns

  • Raw SQL queries without prepared statements
  • No nonce checks on entry points
  • No capability checks on entry points
  • Significant percentage of unescaped output
  • Known medium severity CVE in history
Vulnerabilities
1

Fullscreen Galleria Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-29801medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fullscreen Galleria <= 1.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 25, 2024 Patched in 1.6.12 (8d)
Code Analysis
Analyzed Mar 16, 2026

Fullscreen Galleria Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
9
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

65% escaped26 total outputs
Attack Surface

Fullscreen Galleria Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[fsg_photobox] galleria-fs.php:154
[fsg_photolist] galleria-fs.php:155
[fsg_link] galleria-fs.php:156
[fsg_portfolio] galleria-fs.php:157
WordPress Hooks 10
filterthe_contentgalleria-fs.php:146
actionwp_enqueue_scriptsgalleria-fs.php:147
actionwp_headgalleria-fs.php:148
actionwp_footergalleria-fs.php:149
filterattachment_fields_to_editgalleria-fs.php:150
filterattachment_fields_to_savegalleria-fs.php:151
filterwp_read_image_metadatagalleria-fs.php:152
filtersharing_permalinkgalleria-fs.php:153
actionadmin_initgalleria-fs.php:158
actionadmin_menugalleria-fs.php:159
Maintenance & Trust

Fullscreen Galleria Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedDec 12, 2023
PHP min version
Downloads106K

Community Trust

Rating96/100
Number of ratings15
Active installs900
Developer Profile

Fullscreen Galleria Developer Profile

pdamsten

1 plugin · 900 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Fullscreen Galleria

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fullscreen-galleria/css/galleria.css/wp-content/plugins/fullscreen-galleria/js/galleria-1.6.12.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.classic.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.twocolumn.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.fullscreen.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.carousel.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.debug.js/wp-content/plugins/fullscreen-galleria/js/galleria.history.min.js+8 more
Script Paths
/wp-content/plugins/fullscreen-galleria/js/galleria-1.6.12.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.classic.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.twocolumn.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.fullscreen.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.carousel.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.debug.js+9 more
Version Parameters
fullscreen-galleria/css/galleria.css?ver=fullscreen-galleria/js/galleria-1.6.12.min.js?ver=fullscreen-galleria/js/galleria.classic.min.js?ver=fullscreen-galleria/js/galleria.twocolumn.min.js?ver=fullscreen-galleria/js/galleria.fullscreen.min.js?ver=fullscreen-galleria/js/galleria.carousel.min.js?ver=fullscreen-galleria/js/galleria.debug.js?ver=fullscreen-galleria/js/galleria.history.min.js?ver=fullscreen-galleria/js/galleria.flickr.min.js?ver=fullscreen-galleria/js/galleria.getimage.min.js?ver=fullscreen-galleria/js/galleria.image.min.js?ver=fullscreen-galleria/js/galleria.meta.min.js?ver=fullscreen-galleria/js/galleria.native.min.js?ver=fullscreen-galleria/js/galleria.photoswipe.min.js?ver=fullscreen-galleria/js/galleria.simplecaption.min.js?ver=fullscreen-galleria/js/galleria.statustext.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
galleria-containergalleria-theme-classicgalleria-stagegalleria-images-containergalleria-image-navgalleria-arrowgalleria-image-wrappergalleria-current-img+19 more
Data Attributes
data-galleriadata-theme
JS Globals
Galleria
Shortcode Output
[fsg_photobox][fsg_photolist][fsg_link][fsg_portfolio]
FAQ

Frequently Asked Questions about Fullscreen Galleria