Image show box Security & Risk Analysis

wordpress.org/plugins/img-show-box

一款炫酷的图片查看插件,仿QQ空间个人中心查看图片效果。A cool image show box.

10 active installs v2.2.0 PHP + WP 3.0+ Updated Sep 14, 2011
imageimglightboxshow
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image show box Safe to Use in 2026?

Generally Safe

Score 85/100

Image show box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The plugin "img-show-box" v2.2.0 exhibits a seemingly strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in zero entry points and an entirely protected attack surface. Furthermore, the analysis shows no dangerous functions, no raw SQL queries (all use prepared statements), no file operations, and no external HTTP requests. The absence of critical and high severity taint flows is also a positive indicator.

However, a significant concern arises from the output escaping. With 100% of outputs unescaped, this presents a substantial risk for Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the plugin that originates from user input or external sources could be directly rendered in the browser without sanitization, allowing attackers to inject malicious scripts. The lack of nonces and capability checks, while not an immediate issue due to the zero attack surface, means that if new entry points were introduced in future versions without proper security measures, these vulnerabilities would be exploitable.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the static analysis findings of no dangerous code patterns, suggests that the developers may have good coding practices for the current version and features. Despite the clean history, the unescaped output is a critical weakness that overshadows the otherwise positive findings.

Key Concerns

  • 100% of outputs are unescaped
  • Bundled outdated library: jQuery v1.6.1
Vulnerabilities
None known

Image show box Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Image show box Release Timeline

v2.1.8
v2.1.7
v2.1.6
v2.1.5
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.3
v2.0.2
v2.0.1
Code Analysis
Analyzed Mar 17, 2026

Image show box Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery1.6.1

Output Escaping

0% escaped2 total outputs
Attack Surface

Image show box Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwp_footerimgshowbox.php:30
Maintenance & Trust

Image show box Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedSep 14, 2011
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Image show box Developer Profile

overtrue

4 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image show box

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/img-show-box/img/jquery-1.6.1.js/wp-content/plugins/img-show-box/img/show.js/wp-content/plugins/img-show-box/img/imgshow.css
Script Paths
/wp-content/plugins/img-show-box/img/jquery-1.6.1.js/wp-content/plugins/img-show-box/img/show.js
Version Parameters
img-show-box/img/jquery-1.6.1.js?ver=img-show-box/img/show.js?ver=img-show-box/img/imgshow.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Image show box