
Fullscreen Galleria Security & Risk Analysis
wordpress.org/plugins/fullscreen-galleriaA simple fullscreen gallery to Wordpress
Is Fullscreen Galleria Safe to Use in 2026?
Generally Safe
Score 85/100Fullscreen Galleria has a strong security track record. Known vulnerabilities have been patched promptly.
The "fullscreen-galleria" plugin version 1.6.12 exhibits a mixed security posture. While the static analysis reveals no critical issues like dangerous functions, direct SQL injection vulnerabilities through prepared statements, or insecure file operations, there are notable areas of concern. The absence of any nonce checks or capability checks across its entry points, including four shortcodes, is a significant weakness. This means that users, even those with limited privileges, could potentially trigger functionality within these shortcodes without proper authorization, opening the door to unintended actions.
The plugin's vulnerability history shows one medium-severity Cross-Site Scripting (XSS) vulnerability, most recently patched on March 25, 2024. While the current version is unpatched for this specific CVE, the presence of past XSS issues coupled with the lack of input sanitization and output escaping in a significant portion (35%) of its outputs suggests a recurring pattern of insecure handling of user-supplied data. The static analysis also indicates that all SQL queries are executed without prepared statements, which, while not directly leading to an exploit in this analysis, represents a bad practice that could be exploited in conjunction with other vulnerabilities.
In conclusion, the plugin has some strengths in avoiding explicitly dangerous functions and external requests. However, the lack of robust authorization checks on its entry points, the historical pattern of XSS vulnerabilities, and the pervasive use of raw SQL queries without prepared statements present considerable risks. These issues suggest that the plugin requires further security hardening to ensure the safety of WordPress sites using it.
Key Concerns
- Raw SQL queries without prepared statements
- No nonce checks on entry points
- No capability checks on entry points
- Significant percentage of unescaped output
- Known medium severity CVE in history
Fullscreen Galleria Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Fullscreen Galleria <= 1.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
Fullscreen Galleria Code Analysis
SQL Query Safety
Output Escaping
Fullscreen Galleria Attack Surface
Shortcodes 4
WordPress Hooks 10
Maintenance & Trust
Fullscreen Galleria Maintenance & Trust
Maintenance Signals
Community Trust
Fullscreen Galleria Alternatives
FCP Lightest Lightbox
fcp-lightest-lightbox
Super lightweight Lighbox for WordPress
WP iSell Photo
wp-isell-photo
Easily Sell photos, images, digital print etc. using the built-in WordPress gallery feature. Convert your WordPress gallery into a photo store.
Basic Protected Lightbox
basic-protected-lightbox
A lightweight, simple lightbox with basic image protection capabilities.
Merging Image Boxes
merging-image-boxes
Merging Image Boxes
Lightbox & Modal Popup WordPress Plugin – FooBox
foobox-image-lightbox
A responsive image lightbox for WordPress galleries, WordPress attachments & FooGallery
Fullscreen Galleria Developer Profile
1 plugin · 900 total installs
How We Detect Fullscreen Galleria
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fullscreen-galleria/css/galleria.css/wp-content/plugins/fullscreen-galleria/js/galleria-1.6.12.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.classic.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.twocolumn.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.fullscreen.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.carousel.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.debug.js/wp-content/plugins/fullscreen-galleria/js/galleria.history.min.js+8 more/wp-content/plugins/fullscreen-galleria/js/galleria-1.6.12.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.classic.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.twocolumn.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.fullscreen.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.carousel.min.js/wp-content/plugins/fullscreen-galleria/js/galleria.debug.js+9 morefullscreen-galleria/css/galleria.css?ver=fullscreen-galleria/js/galleria-1.6.12.min.js?ver=fullscreen-galleria/js/galleria.classic.min.js?ver=fullscreen-galleria/js/galleria.twocolumn.min.js?ver=fullscreen-galleria/js/galleria.fullscreen.min.js?ver=fullscreen-galleria/js/galleria.carousel.min.js?ver=fullscreen-galleria/js/galleria.debug.js?ver=fullscreen-galleria/js/galleria.history.min.js?ver=fullscreen-galleria/js/galleria.flickr.min.js?ver=fullscreen-galleria/js/galleria.getimage.min.js?ver=fullscreen-galleria/js/galleria.image.min.js?ver=fullscreen-galleria/js/galleria.meta.min.js?ver=fullscreen-galleria/js/galleria.native.min.js?ver=fullscreen-galleria/js/galleria.photoswipe.min.js?ver=fullscreen-galleria/js/galleria.simplecaption.min.js?ver=fullscreen-galleria/js/galleria.statustext.min.js?ver=HTML / DOM Fingerprints
galleria-containergalleria-theme-classicgalleria-stagegalleria-images-containergalleria-image-navgalleria-arrowgalleria-image-wrappergalleria-current-img+19 moredata-galleriadata-themeGalleria[fsg_photobox][fsg_photolist][fsg_link][fsg_portfolio]