imageLightbox Security & Risk Analysis

wordpress.org/plugins/imagelightbox

Image Lightbox, Responsive and Touch‑friendly.

300 active installs v0.1.1 PHP + WP 3.8+ Updated Oct 8, 2016
imagesjquerylightboxlightweight
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is imageLightbox Safe to Use in 2026?

Generally Safe

Score 85/100

imageLightbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The imagelightbox v0.1.1 plugin exhibits a strong security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all outputs are properly escaped. Furthermore, the absence of file operations, external HTTP requests, and the lack of any recorded vulnerabilities, including CVEs, suggest a well-developed and secure plugin. The attack surface is effectively zero, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. Taint analysis also reveals no concerning flows, indicating a low risk of injection vulnerabilities.

While the current state of the plugin appears very secure, it's important to note the complete absence of nonce and capability checks. This might be due to the plugin's limited functionality and lack of entry points, but it represents a potential, albeit currently unrealized, area for concern should functionality expand without proper security measures. The lack of vulnerability history is a positive sign, suggesting consistent security awareness from the developers. Overall, imagelightbox v0.1.1 is a highly secure plugin at this version, with its primary strength lying in its minimal and well-protected attack surface and robust coding practices. The only minor weakness identified is the absence of any auth checks, which is currently mitigated by the lack of any exploitable entry points.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

imageLightbox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

imageLightbox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

imageLightbox Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitimagelightbox.php:36
actionwp_enqueue_scriptsimagelightbox.php:40
Maintenance & Trust

imageLightbox Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedOct 8, 2016
PHP min version
Downloads15K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

imageLightbox Developer Profile

Bjørn Johansen

7 plugins · 20K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
3065 days
View full developer profile
Detection Fingerprints

How We Detect imageLightbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/imagelightbox/css/styles.css/wp-content/plugins/imagelightbox/js/imagelightbox.js/wp-content/plugins/imagelightbox/js/imagelightbox-init.js/wp-content/plugins/imagelightbox/js/combined.min.js
Script Paths
js/imagelightbox.jsjs/imagelightbox-init.jsjs/combined.min.js
Version Parameters
imagelightbox/css/styles.css?ver=imagelightbox/js/imagelightbox.js?ver=imagelightbox/js/imagelightbox-init.js?ver=imagelightbox/js/combined.min.js?ver=

HTML / DOM Fingerprints

JS Globals
imagelightbox
FAQ

Frequently Asked Questions about imageLightbox