Gallery Stacked Slideshow Security & Risk Analysis

wordpress.org/plugins/gallery-stacked-slideshow

Absolutely NO javascript.stacked styleshow For Post and pages

10 active installs v2.0 PHP + WP 2.7+ Updated Sep 4, 2013
dynamicheaderimagespostposts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Gallery Stacked Slideshow Safe to Use in 2026?

Generally Safe

Score 85/100

Gallery Stacked Slideshow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The gallery-stacked-slideshow plugin v2.0 exhibits a mixed security posture. On the positive side, it has a small attack surface with no known CVEs in its history and no direct file operations or external HTTP requests. The use of capability checks (4 instances) is also a good practice. However, significant concerns arise from the static code analysis. A notable weakness is the lack of nonce checks, which is a critical security mechanism for AJAX handlers. Furthermore, the output escaping is poor, with only 29% of outputs being properly escaped, leaving the plugin vulnerable to cross-site scripting (XSS) attacks. The taint analysis reveals a high number of flows with unsanitized paths, with 3 classified as high severity, indicating potential for sensitive data exposure or manipulation.

The absence of any recorded vulnerabilities in the plugin's history might suggest a lack of diligent auditing or that previous versions were not widely used or targeted. Nevertheless, the current analysis points to potential security weaknesses that could be exploited. The combination of unescaped outputs and high-severity taint flows represents the most immediate risks. While the attack surface is small and largely protected by capability checks, the lack of nonces on AJAX handlers and the identified unsanitized paths are significant oversights that require attention to improve the plugin's overall security.

Key Concerns

  • High severity taint flows with unsanitized paths
  • Low percentage of properly escaped outputs
  • 0 Nonce checks for AJAX handlers
  • SQL queries not fully using prepared statements
Vulnerabilities
None known

Gallery Stacked Slideshow Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Gallery Stacked Slideshow Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
8 prepared
Unescaped Output
45
18 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

SQL Query Safety

53% prepared15 total queries

Output Escaping

29% escaped63 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
<gallery-details> (admin\gallery-details.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Gallery Stacked Slideshow Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_gss_tinymcetinymce\tinymce.php:15

Shortcodes 1

[gss-gallery] gallery-stacked-slideshow.php:50
WordPress Hooks 7
actionadmin_menugallery-stacked-slideshow.php:48
actionadmin_enqueue_scriptsgallery-stacked-slideshow.php:49
actionwp_print_scriptsgallery-stacked-slideshow.php:53
actioninitgallery-stacked-slideshow.php:54
actioninittinymce\tinymce.php:14
filtermce_external_pluginstinymce\tinymce.php:29
filtermce_buttonstinymce\tinymce.php:30
Maintenance & Trust

Gallery Stacked Slideshow Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedSep 4, 2013
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Gallery Stacked Slideshow Developer Profile

rashmisoni

2 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gallery Stacked Slideshow

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gallery-stacked-slideshow/css/gss-style.css
Script Paths
/wp-content/plugins/gallery-stacked-slideshow/js/gss-media-script.js
Version Parameters
gallery-stacked-slideshow/css/gss-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
gallery_stacked_slideshow
HTML Comments
<!-- Gallery Stacked Slideshow-->
Shortcode Output
[gss-gallery]
FAQ

Frequently Asked Questions about Gallery Stacked Slideshow