
Photo Gallery by Ays – Responsive Image Gallery Security & Risk Analysis
wordpress.org/plugins/gallery-photo-galleryPhoto Gallery is a cool responsive image gallery plugin with beautiful views
Is Photo Gallery by Ays – Responsive Image Gallery Safe to Use in 2026?
Generally Safe
Score 86/100Photo Gallery by Ays – Responsive Image Gallery has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "gallery-photo-gallery" plugin version 6.6.4 exhibits a mixed security posture. While it demonstrates several good security practices, such as a high percentage of prepared SQL statements and a significant number of nonce and capability checks, there are notable areas of concern. The presence of 11 AJAX handlers without authentication checks presents a considerable attack surface, increasing the risk of unauthorized actions. The taint analysis reveals 3 high-severity flows with unsanitized paths, indicating potential vulnerabilities that could be exploited if user input is not properly handled. The plugin's historical vulnerability record is concerning, with 10 known CVEs, including past critical and high-severity issues like injection and XSS. The fact that the last recorded vulnerability was in 2025 suggests a recent history of security flaws, even if none are currently unpatched in this specific version. This history, coupled with the identified code signals, points to a plugin that requires careful attention to its security implementation and ongoing maintenance. The plugin shows strengths in database query security and authorization checks, but weaknesses in handling AJAX entry points and sanitizing data flows. Users should be aware of the potential risks associated with the exposed AJAX handlers and the implications of the plugin's past vulnerability trends.
Key Concerns
- 11 unprotected AJAX handlers
- 3 high severity unsanitized path flows
- 47% of outputs properly escaped
- 10 total known CVEs (historical)
- Bundled library Select2 (potential outdatedness)
Photo Gallery by Ays – Responsive Image Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
Photo Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk Actions
Photo Gallery by Ays <= 6.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Photo Gallery by Ays <= 5.7.0 - Authenticated (Administrator+) HTML Injection
Photo Gallery by Ays <= 5.5.2 - Reflected Cross-Site Scripting
Photo Gallery by Ays <= 5.2.6 - Cross-Site Request Forgery
Photo Gallery by Ays <= 5.1.6 - Reflected Cross-Site Scripting
Photo Gallery by Ays <= 5.1.3 - Reflected Cross-Site Scripting via ays_gpg_settings_tab
Photo Gallery by Ays - Responsive Image Gallery <= 4.4.3 - Authenticated Blind SQL Injections
Photo Gallery by Ays – Responsive Image Gallery <= 4.4.3 - Reflected Cross-Site Scripting
Photo Gallery by Ays – Responsive Image Gallery < 1.0.1 - SQL Injection
Photo Gallery by Ays – Responsive Image Gallery Release Timeline
Photo Gallery by Ays – Responsive Image Gallery Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Photo Gallery by Ays – Responsive Image Gallery Attack Surface
AJAX Handlers 11
Shortcodes 16
WordPress Hooks 29
Maintenance & Trust
Photo Gallery by Ays – Responsive Image Gallery Maintenance & Trust
Maintenance Signals
Community Trust
Photo Gallery by Ays – Responsive Image Gallery Alternatives
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
photo-gallery
Photo Gallery is a powerful image gallery plugin with a list of advanced options for creating responsive image galleries with beautiful lightbox.
Robo Gallery – Photo & Image Slider
robo-gallery
Robo Gallery is a powerful image gallery and photo gallery plugin with advanced features to create responsive galleries with a beautiful lightbox
Photo gallery lightbox – 📱 mobile friendly gallery plugin –– Story Show Gallery
story-show-gallery
Full screen photo gallery lightbox for delightful display of your photos, with a lot of features, fully customizable, free.
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More
envira-gallery-lite
Envira Gallery is a fast, easy and powerful gallery builder with lightbox, masonry and grid layouts, albums, videos, and responsive displays and more
Photo Gallery by Ays – Responsive Image Gallery Developer Profile
18 plugins · 111K total installs
How We Detect Photo Gallery by Ays – Responsive Image Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gallery-photo-gallery/admin/css/gallery-photo-gallery-admin.css/wp-content/plugins/gallery-photo-gallery/admin/js/gallery-photo-gallery-admin.js/wp-content/plugins/gallery-photo-gallery/assets/css/owl.carousel.min.css/wp-content/plugins/gallery-photo-gallery/assets/css/owl.theme.default.min.css/wp-content/plugins/gallery-photo-gallery/assets/css/photo-gallery-frontend.css/wp-content/plugins/gallery-photo-gallery/assets/js/jquery.min.js/wp-content/plugins/gallery-photo-gallery/assets/js/owl.carousel.min.js/wp-content/plugins/gallery-photo-gallery/assets/js/photo-gallery-frontend.jsgallery-photo-gallery/admin/css/gallery-photo-gallery-admin.css?ver=gallery-photo-gallery/admin/js/gallery-photo-gallery-admin.js?ver=gallery-photo-gallery/assets/css/owl.carousel.min.css?ver=gallery-photo-gallery/assets/css/owl.theme.default.min.css?ver=gallery-photo-gallery/assets/css/photo-gallery-frontend.css?ver=gallery-photo-gallery/assets/js/jquery.min.js?ver=gallery-photo-gallery/assets/js/owl.carousel.min.js?ver=gallery-photo-gallery/assets/js/photo-gallery-frontend.js?ver=HTML / DOM Fingerprints
ays-notice-bannerays-gpg-logo-container-upgradeays-gpg-logo-containergpg-logoays-gpg-upgrade-containerays-gpg-logo-container-one-time-textmodile-ddmenu-lgmodile-ddmenu-lg-custom+3 more<!-- START: Gallery - Photo Gallery ->Admin Notice--><!-- END: Gallery - Photo Gallery ->Admin Notice--><!-- Gallery - Photo Gallery -> START: Owl Carousel --><!-- Gallery - Photo Gallery -> END: Owl Carousel -->data-carusel="gallery-photo-gallery"