
All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink Security & Risk Analysis
wordpress.org/plugins/image-viewerA Gutenberg block to display images with zoom, magnify, map, pan viewer, comparison slider, masking, transform, and more.
Is All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink Safe to Use in 2026?
Generally Safe
Score 97/100All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink has a strong security track record. Known vulnerabilities have been patched promptly.
The "image-viewer" v1.0.5 plugin exhibits a generally positive security posture, with no immediate critical vulnerabilities detected through static analysis. The absence of dangerous functions, a complete reliance on prepared statements for SQL queries, and a strong percentage of properly escaped output are commendable practices. The plugin also appears to implement capability checks, indicating an awareness of access control. However, there are areas that warrant attention. The presence of an external HTTP request, while not analyzed for taint, represents a potential attack vector if not handled with extreme care. Furthermore, the lack of explicit nonce checks on the identified AJAX handler, although reported as protected by a capability check, is a minor concern that could be strengthened.
The vulnerability history reveals a past high-severity vulnerability, specifically SSRF, which was patched. The fact that the last vulnerability occurred in 2026-02-04 suggests it has been addressed, but the presence of past high-severity issues, particularly SSRF, is a red flag. This indicates a historical tendency for vulnerabilities in this plugin, and while none are currently unpatched, vigilance is still recommended. Overall, the plugin demonstrates good security practices in many areas, but the past high-severity vulnerability and the limited analysis of external requests suggest a need for continued monitoring and potential hardening of specific entry points.
Key Concerns
- Past high severity vulnerability (SSRF)
- External HTTP request without taint analysis
- Missing nonce checks on AJAX (though protected by capability)
All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
All In One Image Viewer Block <= 1.0.2 - Unauthenticated Server-Side Request Forgery via image-proxy Endpoint
All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink Code Analysis
Bundled Libraries
Output Escaping
All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink Maintenance & Trust
Maintenance Signals
Community Trust
All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink Alternatives
WP Image Zoom
wp-image-zoooom
Awesome image zoom plugin for images in posts/pages and for WooCommerce products.
Featured Image Zoom
featured-image-zoom
Add a [zoom] shortcode to display a zoomable featured image.
Ultimate Image Gallery – Image Zoom, Viewer, Lightbox and Filter Gallery
ultimate-image-gallery
This plugin enhances image presentation with zoom, viewer, lightbox, and filter gallery features for a better website experience.
SmartZoom
smartzoom
A lightweight plugin that adds a clean magnifying zoom effect to WooCommerce single product images.
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink Developer Profile
120 plugins · 738K total installs
How We Detect All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-viewer/build/admin/dashboard.css/wp-content/plugins/image-viewer/build/admin/dashboard.js/wp-content/plugins/image-viewer/build/admin-post.css/wp-content/plugins/image-viewer/build/admin-post.js/wp-content/plugins/image-viewer/build/admin/dashboard.js/wp-content/plugins/image-viewer/build/admin-post.jsimage-viewer/build/admin/dashboard.css?ver=image-viewer/build/admin/dashboard.js?ver=image-viewer/build/admin-post.css?ver=image-viewer/build/admin-post.js?ver=HTML / DOM Fingerprints
/wp-json/bpivb/v1/image-proxy