
Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery Security & Risk Analysis
wordpress.org/plugins/gallery-videosGallery is a user-friendly plugin to display user or hashtag-based gallery feeds as a responsive customizable gallery.
Is Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery Safe to Use in 2026?
Generally Safe
Score 95/100Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery has a strong security track record. Known vulnerabilities have been patched promptly.
The 'gallery-videos' plugin version 2.5.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices with 100% of its SQL queries using prepared statements and a very high percentage of output being properly escaped, mitigating common web vulnerabilities like SQL injection and XSS. The absence of file operations and the limited external HTTP requests are also favorable. However, a concerning taint analysis result indicates one flow with an unsanitized path, which could potentially lead to vulnerabilities if exploited. Additionally, the plugin has a history of 5 known CVEs, with 3 high and 2 medium severity vulnerabilities in the past, suggesting a recurring pattern of security weaknesses despite current unpatched status. The plugin's total entry points are relatively low and all appear to have some form of protection, but the absence of capability checks on any entry points is a significant concern, leaving it open to privilege escalation or unauthorized access if other vulnerabilities are present. Overall, while the plugin has implemented some strong security measures, the presence of a taint flow and its past vulnerability history warrant careful consideration and ongoing vigilance.
Key Concerns
- Taint flow with unsanitized path
- History of 3 high severity CVEs
- History of 2 medium severity CVEs
- No capability checks on entry points
Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
YouTube Gallery and Vimeo Gallery Plugin <= 2.4.2 - Authenticated (Administrator+) SQL Injection
Video Gallery <= 2.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Video Gallery – YouTube Gallery <= 2.1.4 - Authenticated (Administrator+) SQL Injection
Video Gallery – YouTube Gallery <= 1.7.6 - Missing Authorization
Video Gallery – YouTube Gallery <= 1.7.6 - Authenticated (Admin+) Stored Cross Site Scripting
Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 18
Maintenance & Trust
Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery Maintenance & Trust
Maintenance Signals
Community Trust
Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery Alternatives
Modula Image Gallery – Photo Grid & Video Gallery
modula-best-grid-gallery
Create responsive image galleries with drag-and-drop grid builder. Custom layouts, video support, AI optimization. Works with any theme.
Mosaic Gallery – Advanced Gallery
mosaic-gallery-advanced-gallery
Mosaic Gallery is an advanced plugin for creating stunning, responsive mosaic-style galleries with ease, offering customizable layouts and effects.
Flare Lightbox Gallery for Elementor
flare-lightbox-gallery-for-elementor
Flare gallery for your Elementor Page Builder!.
Shader Grid
shader-grid
Powerful and extremely customizable responsive infinite image/video grid with WebGL shaders and lightbox support.
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery Developer Profile
4 plugins · 17K total installs
How We Detect Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gallery-videos/img/ts-poll-logo.pngHTML / DOM Fingerprints
tsvg-bannertsvg-banner-containertsvg-banner-circletsvg-banner-circle-atsvg-banner-circle-btsvg-banner-circle-ctsvg-banner-circle-dtsvg-banner-img+6 moretsvg-remind-metsvg-dismissed