
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress Security & Risk Analysis
wordpress.org/plugins/gallery-pluginAdd beautiful, fully responsive galleries, albums, images, and categories to your WordPress website quickly and easily. Showcase your portfolio, photo …
Is Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress Safe to Use in 2026?
Generally Safe
Score 95/100Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'gallery-plugin' v4.7.7 exhibits a mixed security posture. While the static analysis reveals a relatively small attack surface with no unprotected AJAX handlers or REST API routes, and a strong emphasis on output escaping (97%) and nonce checks (31), there are underlying concerns. The presence of 26 SQL queries, with 38% not using prepared statements, is a significant risk for potential SQL injection vulnerabilities, despite the absence of critical taint flows in the current analysis. Furthermore, the plugin's history of 5 known CVEs, including 2 high severity vulnerabilities (SQL Injection and Cross-Site Scripting, and Deserialization of Untrusted Data), indicates a pattern of historical weaknesses that, even if currently patched, suggest a recurring need for vigilant maintenance and potentially deeper code scrutiny. The last vulnerability being in 2025 also suggests a relatively recent discovery, implying that the plugin might still be actively targeted or has had persistent issues.
While the current static analysis shows no critical or high severity issues, and all previous CVEs are reported as patched, the high percentage of non-prepared SQL statements and the historical trend of significant vulnerabilities are substantial weaknesses. The plugin has demonstrated an ability to develop critical flaws in the past, and the static analysis does not fully mitigate the risk associated with the 38% of SQL queries that are not prepared. The absence of critical taint flows is a positive sign for the current version, but the overall historical context and the identified code signals warrant caution.
Key Concerns
- SQL queries without prepared statements
- History of high severity vulnerabilities
- History of medium severity vulnerabilities
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authenticated (Administrator+) PHP Object Injection
Gallery by BestWebSoft <= 4.6.9 - Authenticated (Author+) Stored Cross-Site Scripting
Gallery by BestWebSoft <= 4.6.9 - Authenticated (Author+) SQL Injection
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress <= 4.6.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress < 4.5.0 - Reflected Cross-Site Scripting
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress Release Timeline
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 56
Maintenance & Trust
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress Alternatives
As Gallery
as-gallery
As Gallery is a great plugin for adding image gallery for your site.
WP Image Size Selection
image-size-selection
Allows you to add any available image sizes to the media size selection drop down.
custom blogger images
custom-blogger-images
Custom blogger images adds extra image sizes & golden ratio proportions to your Wordpress themes.
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress Developer Profile
18 plugins · 207K total installs
How We Detect Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gallery-plugin/assets/css/gallery-frontend.min.css/wp-content/plugins/gallery-plugin/assets/css/gallery-frontend-gallery.min.css/wp-content/plugins/gallery-plugin/assets/js/gallery-frontend.min.js/wp-content/plugins/gallery-plugin/assets/js/gallery-frontend-gallery.min.js/wp-content/plugins/gallery-plugin/assets/js/admin-gallery.js/wp-content/plugins/gallery-plugin/assets/css/admin-gallery.css/wp-content/plugins/gallery-plugin/assets/js/gallery-frontend.min.js/wp-content/plugins/gallery-plugin/assets/js/gallery-frontend-gallery.min.jsgallery-plugin/assets/css/gallery-frontend.min.css?ver=gallery-plugin/assets/css/gallery-frontend-gallery.min.css?ver=gallery-plugin/assets/js/gallery-frontend.min.js?ver=gallery-plugin/assets/js/gallery-frontend-gallery.min.js?ver=gallery-plugin/assets/js/admin-gallery.js?ver=gallery-plugin/assets/css/admin-gallery.css?ver=HTML / DOM Fingerprints
gllr-gallery-containergllr-portfoliogllr-gallery-itemgllr-thumb-overlaygllr-thumb-titlegllr-gallery-descriptiongllr-album-containergllr-album-itemdata-gllr-iddata-gllr-settingsgllr_gallery_options[gallery[gallery-album