
Gallery Custom Links Security & Risk Analysis
wordpress.org/plugins/gallery-custom-linksGallery Custom Links allows you to link images to a specified URL. Tested with WordPress Gallery, Gutenberg, the Meow Gallery and others.
Is Gallery Custom Links Safe to Use in 2026?
Generally Safe
Score 99/100Gallery Custom Links has a strong security track record. Known vulnerabilities have been patched promptly.
The 'gallery-custom-links' plugin v2.2.9 exhibits a generally positive security posture, with a strong emphasis on secure coding practices. The static analysis reveals a commendable absence of dangerous functions, a high percentage of properly escaped output, and a significant number of capability checks, indicating a developer conscious of common security pitfalls. The complete lack of unprotected AJAX handlers, REST API routes, and shortcodes significantly limits the plugin's attack surface. Furthermore, the absence of any identified taint flows with unsanitized paths or critical/high severity vulnerabilities in the code analysis is a strong positive indicator. However, a previously documented medium severity Cross-Site Scripting (XSS) vulnerability, though now patched, suggests a past oversight in input sanitization or output escaping for web page generation. While no current unpatched vulnerabilities exist, this history warrants continued vigilance.
Key Concerns
- Previous medium severity XSS vulnerability
Gallery Custom Links Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Gallery Custom Links <= 2.2.5 - Authenticated (Author+) Stored Cross-Site Scripting
Gallery Custom Links Code Analysis
SQL Query Safety
Output Escaping
Gallery Custom Links Attack Surface
WordPress Hooks 37
Maintenance & Trust
Gallery Custom Links Maintenance & Trust
Maintenance Signals
Community Trust
Gallery Custom Links Alternatives
EXMAGE – WordPress Image Links
exmage-wp-image-links
Add images using external links - Save your storage with EXMAGE effortlessly
Steve's Attributes
steves-attributes
Extends Gutenberg blocks to easily add custom attributes to links in various blocks without resorting to custom HTML.
Permalink Manager Lite
permalink-manager
Permalink Manager enhances WordPress’s built-in URL system, allowing you to change the URLs of native and custom post types and taxonomies.
Advanced Import: One-Click Demo Import for WordPress
advanced-import
Advanced Import simplifies importing demo data for WordPress sites, enabling users to import posts, pages, media, widgets, customizer settings, and Gu …
ACF Photo Gallery Field
navz-photo-gallery
A lightweight extension of Advanced Custom Field (ACF) that adds Photo Gallery field to any post/pages on your WordPress website.
Gallery Custom Links Developer Profile
27 plugins · 371K total installs
How We Detect Gallery Custom Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gallery-custom-links/app/index.js/wp-content/plugins/gallery-custom-links/app/vendor.js/wp-content/plugins/gallery-custom-links/app/vendor.js/wp-content/plugins/gallery-custom-links/app/index.jsgallery-custom-links/app/index.js?ver=gallery-custom-links/app/vendor.js?ver=HTML / DOM Fingerprints
XXXX: Custom modification to add "noopener noreferrer" als REL-option, Christoph Letmaier, 14.01.2020XXXX: Custom code for new aria-label field, Christoph Letmaier, 14.01.2020XXXX: Custom code for saving _gallery_link_aria, Christoph Letmaier, 14.01.2020gallery_link_urlgallery_link_targetgallery_link_relgallery_link_ariamgcl_gallery_custom_links/gallery-custom-links/v1