
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery Security & Risk Analysis
wordpress.org/plugins/gt3-photo-video-galleryGT3 Image Gallery - create photo gallery, video gallery, block gallery, slider and more with ease. All photo galleries are responsive and loading fast
Is Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery Safe to Use in 2026?
Generally Safe
Score 95/100Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The gt3-photo-video-gallery plugin exhibits a mixed security posture. While it demonstrates good practices such as 100% of SQL queries using prepared statements and a significant portion of output being properly escaped, there are notable areas of concern. The presence of an unprotected REST API route is a direct entry point for potential attacks, and the high number of flows with unsanitized paths in taint analysis suggests that user-supplied data may not be adequately validated before being processed, even if no critical or high severity vulnerabilities were found in this specific analysis. The vulnerability history reveals a pattern of medium-severity Cross-Site Scripting (XSS) vulnerabilities, with four known CVEs, the last of which was documented in late 2025. This indicates a recurring issue with input sanitization and output encoding, and while no currently unpatched vulnerabilities are listed, the historical trend is a significant risk factor that requires careful monitoring and remediation.
Key Concerns
- Unprotected REST API route
- Flows with unsanitized paths found
- History of medium severity XSS vulnerabilities
- Significant portion of output not properly escaped
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Photo Gallery <= 2.7.7.26 - Reflected Cross-Site Scripting
Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery <= 2.7.7.25 - Authenticated (Contributor+) Stored Cross-Site Scripting
Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery <= 2.7.7.24 - Reflected Cross-Site Scripting
Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery <= 2.7.7.21 - Authenticated (Author+) Cross-Site Scripting
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery Release Timeline
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery Code Analysis
Output Escaping
Data Flow Analysis
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery Attack Surface
AJAX Handlers 5
REST API Routes 1
Shortcodes 2
WordPress Hooks 108
Scheduled Events 1
Maintenance & Trust
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery Maintenance & Trust
Maintenance Signals
Community Trust
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery Alternatives
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
photo-gallery
Photo Gallery is a powerful image gallery plugin with a list of advanced options for creating responsive image galleries with beautiful lightbox.
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More
envira-gallery-lite
Envira Gallery is a fast, easy and powerful gallery builder with lightbox, masonry and grid layouts, albums, videos, and responsive displays and more
Visual Portfolio, Photo Gallery & Post Grid
visual-portfolio
Powerful WordPress gallery plugin for stunning photo, video & album galleries with advanced layouts and flexible block editing.
Robo Gallery – Photo & Image Slider
robo-gallery
Robo Gallery is a powerful image gallery and photo gallery plugin with advanced features to create responsive galleries with a beautiful lightbox
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery Developer Profile
1 plugin · 10K total installs
How We Detect Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gt3-photo-video-gallery/dist/js/deprecated/editor.js/wp-content/plugins/gt3-photo-video-gallery/dist/css/deprecated/editor.css/wp-content/plugins/gt3-photo-video-gallery/dist/js/deprecated/frontend.js/wp-content/plugins/gt3-photo-video-gallery/dist/css/deprecated/frontend.css/wp-content/plugins/gt3-photo-video-gallery/dist/js/isotope.pkgd.min.js/wp-content/plugins/gt3-photo-video-gallery/dist/js/deprecated/editor.js/wp-content/plugins/gt3-photo-video-gallery/dist/js/deprecated/frontend.js/wp-content/plugins/gt3-photo-video-gallery/dist/js/isotope.pkgd.min.jsgt3-photo-video-gallery/dist/js/deprecated/editor.js?ver=gt3-photo-video-gallery/dist/css/deprecated/editor.css?ver=gt3-photo-video-gallery/dist/js/deprecated/frontend.js?ver=gt3-photo-video-gallery/dist/css/deprecated/frontend.css?ver=gt3-photo-video-gallery/dist/js/isotope.pkgd.min.js?ver=HTML / DOM Fingerprints
gt3-gallery-wrapgt3_gallery_itemgt3-gallery-content<!-- Exit if accessed directly --><!-- GT3 PG -->data-gt3-gallery-iddata-gallery-iddata-typegt3pg_litegt3pg_ajax/wp-json/gt3pg/v1/gallery<div class='gt3-gallery-wrap'