
Photo Gallery – Responsive Image Galleries by Supsystic Security & Risk Analysis
wordpress.org/plugins/gallery-by-supsysticPhoto Gallery helps you create clean, responsive image galleries and album galleries without wrestling with complex settings, layouts, or custom CSS.
Is Photo Gallery – Responsive Image Galleries by Supsystic Safe to Use in 2026?
Generally Safe
Score 98/100Photo Gallery – Responsive Image Galleries by Supsystic has a strong security track record. Known vulnerabilities have been patched promptly.
The "gallery-by-supsystic" plugin version 1.15.33 exhibits a mixed security posture. On the positive side, the vast majority of SQL queries utilize prepared statements, and almost all output is properly escaped, indicating good practices in handling data and preventing common web vulnerabilities like XSS. The plugin also demonstrates a reasonable number of capability checks and nonce checks overall.
However, significant concerns arise from the identified attack surface. With two unprotected AJAX handlers, there are clear opportunities for unauthenticated attackers to interact with sensitive plugin functionalities. This is a critical weakness, especially when combined with the presence of the `unserialize` function, which can be a gateway to remote code execution if not handled with extreme care and input validation. Taint analysis did not reveal any immediate issues, but the lack of thorough taint analysis (0 flows analyzed) means this is not a definitive sign of safety.
The plugin's vulnerability history is also a point of concern. With three known CVEs, including one high and two medium severity vulnerabilities, it suggests a pattern of past security weaknesses. While there are currently no unpatched vulnerabilities, the recurring nature of past issues, particularly Cross-Site Scripting and CSRF, warrants vigilance. The most recent vulnerability being in March 2024 indicates that this plugin has been a target for security researchers. The combination of unprotected entry points and a history of vulnerabilities leads to a moderate to high risk assessment.
Key Concerns
- Two AJAX handlers without auth checks
- Use of 'unserialize' function
- 1 High severity CVE historically
- 2 Medium severity CVEs historically
- 1 nonce check for 3 entry points
Photo Gallery – Responsive Image Galleries by Supsystic Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Photo Gallery by Supsystic <= 1.15.16 - Authenticated (Administrator+) Stored Cross-Site Scripting
Photo Gallery by Supsystic <= 1.15.5 - Cross-Site Request Forgery to Plugin Settings Change
Photo Gallery by Supsystic <= 1.8.8 - Cross-Site Request Forgery
Photo Gallery – Responsive Image Galleries by Supsystic Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Photo Gallery – Responsive Image Galleries by Supsystic Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 29
Maintenance & Trust
Photo Gallery – Responsive Image Galleries by Supsystic Maintenance & Trust
Maintenance Signals
Community Trust
Photo Gallery – Responsive Image Galleries by Supsystic Alternatives
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
photo-gallery
Photo Gallery is a powerful image gallery plugin with a list of advanced options for creating responsive image galleries with beautiful lightbox.
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More
envira-gallery-lite
Envira Gallery is a fast, easy and powerful gallery builder with lightbox, masonry and grid layouts, albums, videos, and responsive displays and more
Robo Gallery – Photo & Image Slider
robo-gallery
Robo Gallery is a powerful image gallery and photo gallery plugin with advanced features to create responsive galleries with a beautiful lightbox
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery
gt3-photo-video-gallery
GT3 Image Gallery - create photo gallery, video gallery, block gallery, slider and more with ease. All photo galleries are responsive and loading fast
Photo Gallery – Responsive Image Galleries by Supsystic Developer Profile
7 plugins · 97K total installs
How We Detect Photo Gallery – Responsive Image Galleries by Supsystic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gallery-by-supsystic/app/assets/css/editor-dialog.css/wp-content/plugins/gallery-by-supsystic/app/assets/js/jquery.bpopup.min.js/wp-content/plugins/gallery-by-supsystic/app/assets/js/buttons.js/wp-content/plugins/gallery-by-supsystic/app/assets/js/jquery.bpopup.min.js/wp-content/plugins/gallery-by-supsystic/app/assets/js/buttons.jsgallery-by-supsystic/app/assets/js/jquery.bpopup.min.js?ver=gallery-by-supsystic/app/assets/css/editor-dialog.css?ver=gallery-by-supsystic/app/assets/js/buttons.js?ver=HTML / DOM Fingerprints
supsystic-gallerysgg-gallery<!-- Grid Gallery Plugin -->data-sg-idsgg_gallerysgg_params/wp-json/sgg/v1[supsystic-gallery