Import to Photo Gallery from NextGen gallery Security & Risk Analysis

wordpress.org/plugins/import-to-photo-gallery-from-nextgen-gallery

Import to Photo Gallery from NextGen gallery is an easy setup addon for importing photos and related data from NextGen Gallery to Photo Gallery.

500 active installs v1.0.5 PHP + WP 3.4+ Updated Oct 25, 2018
exportgalleryimportnextgen-galleryphoto-gallery
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Import to Photo Gallery from NextGen gallery Safe to Use in 2026?

Generally Safe

Score 85/100

Import to Photo Gallery from NextGen gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "import-to-photo-gallery-from-nextgen-gallery" plugin, version 1.0.5, exhibits a generally strong security posture based on the provided static analysis. The absence of any identified vulnerabilities in its history, coupled with the zero count for critical or high-severity taint flows, is a significant positive indicator. Furthermore, the attack surface appears to be minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks.

However, there are areas of concern that warrant attention. The low percentage of properly escaped output (29%) suggests a potential risk of Cross-Site Scripting (XSS) vulnerabilities. While the static analysis did not reveal any specific XSS flows, the general lack of robust output escaping increases the likelihood of such issues being present or emerging in future versions. The moderate rate of SQL queries using prepared statements (59%) also presents a minor risk of SQL injection if the remaining queries are executed with untrusted input.

In conclusion, this plugin demonstrates good security practices by minimizing its attack surface and having a clean vulnerability history. Nevertheless, the insufficient output escaping is a notable weakness that could expose users to XSS attacks. Addressing this by implementing proper escaping for all output is crucial for improving its overall security. The moderate SQL prepared statement usage is less concerning but still an area for potential improvement.

Key Concerns

  • Insufficient output escaping
  • Moderate rate of SQL queries without prepared statements
Vulnerabilities
None known

Import to Photo Gallery from NextGen gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Import to Photo Gallery from NextGen gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
13
19 prepared
Unescaped Output
12
5 escaped
Nonce Checks
1
Capability Checks
0
File Operations
6
External Requests
0
Bundled Libraries
0

SQL Query Safety

59% prepared32 total queries

Output Escaping

29% escaped17 total outputs
Attack Surface

Import to Photo Gallery from NextGen gallery Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menungitopg.php:22
Maintenance & Trust

Import to Photo Gallery from NextGen gallery Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedOct 25, 2018
PHP min version
Downloads39K

Community Trust

Rating70/100
Number of ratings4
Active installs500
Developer Profile

Import to Photo Gallery from NextGen gallery Developer Profile

10Web

9 plugins · 365K total installs

66
trust score
Avg Security Score
82/100
Avg Patch Time
724 days
View full developer profile
Detection Fingerprints

How We Detect Import to Photo Gallery from NextGen gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/import-to-photo-gallery-from-nextgen-gallery/images/icon-16x16.png/wp-content/plugins/import-to-photo-gallery-from-nextgen-gallery/js/pgi.js/wp-content/plugins/import-to-photo-gallery-from-nextgen-gallery/css/pgi_main.css
Script Paths
/wp-content/plugins/import-to-photo-gallery-from-nextgen-gallery/js/pgi.js

HTML / DOM Fingerprints

JS Globals
pgi_objectL10n
FAQ

Frequently Asked Questions about Import to Photo Gallery from NextGen gallery