
Image show box Security & Risk Analysis
wordpress.org/plugins/img-show-box一款炫酷的图片查看插件,仿QQ空间个人中心查看图片效果。A cool image show box.
Is Image show box Safe to Use in 2026?
Generally Safe
Score 85/100Image show box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "img-show-box" v2.2.0 exhibits a seemingly strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in zero entry points and an entirely protected attack surface. Furthermore, the analysis shows no dangerous functions, no raw SQL queries (all use prepared statements), no file operations, and no external HTTP requests. The absence of critical and high severity taint flows is also a positive indicator.
However, a significant concern arises from the output escaping. With 100% of outputs unescaped, this presents a substantial risk for Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the plugin that originates from user input or external sources could be directly rendered in the browser without sanitization, allowing attackers to inject malicious scripts. The lack of nonces and capability checks, while not an immediate issue due to the zero attack surface, means that if new entry points were introduced in future versions without proper security measures, these vulnerabilities would be exploitable.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the static analysis findings of no dangerous code patterns, suggests that the developers may have good coding practices for the current version and features. Despite the clean history, the unescaped output is a critical weakness that overshadows the otherwise positive findings.
Key Concerns
- 100% of outputs are unescaped
- Bundled outdated library: jQuery v1.6.1
Image show box Security Vulnerabilities
Image show box Release Timeline
Image show box Code Analysis
Bundled Libraries
Output Escaping
Image show box Attack Surface
WordPress Hooks 1
Maintenance & Trust
Image show box Maintenance & Trust
Maintenance Signals
Community Trust
Image show box Alternatives
Simple Lightbox
simple-lightbox
The highly customizable lightbox for WordPress
peLightbox Gallery Slider – Responsive Lightbox, Slideshow, Carousel, Image & Video Gallery
pelightbox-gallery-slider
peLightbox Gallery is a beautiful, responsive WordPress lightbox gallery and slider plugin
Hover Effects With Lightbox For WPBakery Page Builder (formely Visual Composer)
hover-effects-with-lightbox-vc-extension
Add images to your pages with beautiful hover effects and captions.
Zoom img
zoom-img
Click to enlarge the image to view.
Bilych Gallery
bilych-gallery
This plugin replace default Wordpress gallery.
Image show box Developer Profile
4 plugins · 130 total installs
How We Detect Image show box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/img-show-box/img/jquery-1.6.1.js/wp-content/plugins/img-show-box/img/show.js/wp-content/plugins/img-show-box/img/imgshow.css/wp-content/plugins/img-show-box/img/jquery-1.6.1.js/wp-content/plugins/img-show-box/img/show.jsimg-show-box/img/jquery-1.6.1.js?ver=img-show-box/img/show.js?ver=img-show-box/img/imgshow.css?ver=