
Gallery for Immich Security & Risk Analysis
wordpress.org/plugins/gallery-for-immichDisplay your Immich photo albums and galleries in WordPress using simple shortcodes.
Is Gallery for Immich Safe to Use in 2026?
Generally Safe
Score 100/100Gallery for Immich has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gallery-for-immich" plugin v0.7.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, which significantly mitigates SQL injection risks. The plugin also shows a high percentage of properly escaped output, indicating an effort to prevent cross-site scripting (XSS) vulnerabilities.
However, several areas raise concerns. The presence of one unprotected REST API route represents a significant entry point for potential attacks, as it lacks permission checks. Furthermore, the taint analysis revealed three flows with unsanitized paths, although they were not classified as critical or high severity. This suggests a potential for issues like path traversal, even if not immediately exploitable in a severe manner. The use of the dangerous function `set_time_limit` could also be a point of concern in certain environments or if not carefully managed. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting a relatively stable codebase or diligent patching by developers.
In conclusion, while "gallery-for-immich" v0.7.0 has strengths in SQL handling and output escaping, the unprotected REST API route and unsanitized path flows are notable weaknesses. The plugin's history of zero CVEs is encouraging, but the identified code signals warrant attention for a comprehensive security assessment.
Key Concerns
- Unprotected REST API route
- Flows with unsanitized paths
- Use of dangerous function set_time_limit
Gallery for Immich Security Vulnerabilities
Gallery for Immich Release Timeline
Gallery for Immich Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Gallery for Immich Attack Surface
AJAX Handlers 1
REST API Routes 2
Shortcodes 1
WordPress Hooks 10
Scheduled Events 1
Maintenance & Trust
Gallery for Immich Maintenance & Trust
Maintenance Signals
Community Trust
Gallery for Immich Alternatives
Lightbox with PhotoSwipe
lightbox-photoswipe
Integration of PhotoSwipe (http://photoswipe.com) for WordPress.
FancyBox Gallery
fancybox-gallery
Integrates the FancyBox jQuery plugin to generate dynamic pop-up image overlays for WordPress galleries.
Responsive Lightbox2
responsive-lightbox2
Add responsive lightbox effect to your images, pop up photos and photo gallery in lightbox
PhotoSwipe Lightbox for FooGallery Extension
photoswipe-foogallery
Implements the great "PhotoSwipe"-Lightbox of Dmitry Semenov in FooGallery
SimpleGal
simplegal
Create an Image-Gallery in 5 simple Steps. Just add the shortcode to your posts.
Gallery for Immich Developer Profile
1 plugin · 60 total installs
How We Detect Gallery for Immich
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gallery-for-immich/build/gallery-for-immich-admin.css/wp-content/plugins/gallery-for-immich/build/gallery-for-immich-admin.js/wp-content/plugins/gallery-for-immich/build/gallery-for-immich-frontend.css/wp-content/plugins/gallery-for-immich/build/gallery-for-immich-frontend.js/wp-content/plugins/gallery-for-immich/build/gallery-for-immich-frontend.jsgallery-for-immich/build/gallery-for-immich-frontend.css?ver=gallery-for-immich/build/gallery-for-immich-frontend.js?ver=gallery-for-immich/build/gallery-for-immich-admin.css?ver=gallery-for-immich/build/gallery-for-immich-admin.js?ver=HTML / DOM Fingerprints
gallery-for-immich-containergallery-for-immich-imagegallery-for-immich-album<!-- galleries_for_immich_block --><!-- Gallery for Immich shortcode placeholder -->data-gallery-for-immich-server-urldata-gallery-for-immich-api-keygalleryForImmichFrontendGalleryForImmichAdmin/wp-json/gallery-for-immich/v1/assets/wp-json/gallery-for-immich/v1/albums[gallery_for_immich][gallery_for_immich album_id=""][gallery_for_immich search=""]