
Gallery Just Better Security & Risk Analysis
wordpress.org/plugins/gallery-just-betterIt's a tiny bit more flexible than wp native gallery. It finally allows non-linked images and images linking to external URLs.
Is Gallery Just Better Safe to Use in 2026?
Generally Safe
Score 85/100Gallery Just Better has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gallery-just-better plugin version 0.3 exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and properly escaping all output. The absence of file operations and external HTTP requests further reduces potential attack vectors. Notably, there are no recorded vulnerabilities (CVEs) for this plugin, suggesting a history of secure development or a lack of discovered flaws. The attack surface is minimal, with only one shortcode identified and no unprotected entry points.
However, there are a few areas that could be improved. The absence of nonce checks and capability checks on its single entry point (the shortcode) represents a potential weakness. While the static analysis found no taint flows, the lack of these checks means that if any user-supplied data were to be processed by the shortcode without proper sanitization and validation within the shortcode's callback function itself, it could lead to vulnerabilities. The plugin's limited functionality and small attack surface likely contribute to its clean vulnerability history, but relying solely on this is not a robust security strategy. Overall, while the current version appears secure due to its limited features and good coding practices, the lack of explicit authorization checks on its shortcode is a concern that should be addressed to prevent future issues if functionality expands.
Key Concerns
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
Gallery Just Better Security Vulnerabilities
Gallery Just Better Code Analysis
Output Escaping
Gallery Just Better Attack Surface
Shortcodes 1
Maintenance & Trust
Gallery Just Better Maintenance & Trust
Maintenance Signals
Community Trust
Gallery Just Better Alternatives
Social Photo Fetcher
facebook-photo-fetcher
Allows you to automatically create Wordpress photo galleries from Facebook albums. Simple to use and highly customizable.
ThickBox
thickbox
Embed ThickBox into your posts and pages.
Easy Gallery Slider
easy-gallery-slider
Responsive slider uses the images attached to a post or page. Simple to customize and configure.
SmoothGallery
smoothgallery
Embed JonDesign's SmoothGallery into your posts and pages.
T&P Gallery Slider
tp-gallery-slider
T&P Gallery Slider for WordPress is an image hover/click gallery as a WordPress plugin.
Gallery Just Better Developer Profile
2 plugins · 410 total installs
How We Detect Gallery Just Better
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gallery-just-better/gallery-just-better.css/wp-content/plugins/gallery-just-better/gallery-just-better.js/wp-content/plugins/gallery-just-better/gallery-just-better.jsgallery-just-better/gallery-just-better.css?ver=gallery-just-better/gallery-just-better.js?ver=HTML / DOM Fingerprints
gallery-itemgallery-icongallery-captionwp-caption-textgalleryid-gallery-columns-gallery-size-<!-- see gallery_shortcode() in wp-includes/media.php -->galleryjb<p style="text-align:center; font-size: 0.8em">powered by <a target="_blank" href="http://www.stefaniamarchisio.com/gallery-just-better-plugin/">Gallery Just Better plugin</a></p>