
Innozilla Image Gallery 8 Security & Risk Analysis
wordpress.org/plugins/innozilla-image-gallery-8Very Simple Image Gallery with filter and load more
Is Innozilla Image Gallery 8 Safe to Use in 2026?
Generally Safe
Score 92/100Innozilla Image Gallery 8 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'innozilla-image-gallery-8' v1.1.0 plugin exhibits a generally positive security posture based on the provided static analysis. It demonstrates good practices by having no known CVEs, no unpatched vulnerabilities, and no critical or high-severity vulnerabilities recorded. The absence of dangerous functions, file operations, external HTTP requests, and SQL queries executed without prepared statements are also strong indicators of secure coding. The limited attack surface, with only one shortcode entry point and no unprotected AJAX or REST API routes, further contributes to its security.
However, a significant concern arises from the output escaping. With only 26% of outputs properly escaped, there's a high potential for Cross-Site Scripting (XSS) vulnerabilities, especially given the presence of a shortcode which is an entry point that could potentially handle user-supplied data. The lack of nonce checks and capability checks on the single shortcode entry point means that unauthorized users could potentially trigger its functionality, and the results could be rendered without proper sanitization or validation.
While the vulnerability history is clean, this does not negate the risks identified in the static analysis. The absence of past vulnerabilities could be due to low usage, limited attack vectors in previous versions, or simply fortunate circumstances. The current code analysis, particularly the low output escaping rate, presents a clear and present danger of XSS. Therefore, while the plugin has a good foundation in some areas, the insufficient output escaping is a critical weakness that needs immediate attention.
Key Concerns
- Low output escaping percentage
- Missing nonce check on shortcode
- Missing capability check on shortcode
Innozilla Image Gallery 8 Security Vulnerabilities
Innozilla Image Gallery 8 Release Timeline
Innozilla Image Gallery 8 Code Analysis
Output Escaping
Innozilla Image Gallery 8 Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Innozilla Image Gallery 8 Maintenance & Trust
Maintenance Signals
Community Trust
Innozilla Image Gallery 8 Alternatives
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
photo-gallery
Photo Gallery is a powerful image gallery plugin with a list of advanced options for creating responsive image galleries with beautiful lightbox.
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More
envira-gallery-lite
Envira Gallery is a fast, easy and powerful gallery builder with lightbox, masonry and grid layouts, albums, videos, and responsive displays and more
Gallery by FooGallery
foogallery
Photo Gallery, Image Gallery by FooGallery — fast, responsive, SEO-optimized, and packed with beautiful layouts.
Robo Gallery – Photo & Image Slider
robo-gallery
Robo Gallery is a powerful image gallery and photo gallery plugin with advanced features to create responsive galleries with a beautiful lightbox
Innozilla Image Gallery 8 Developer Profile
2 plugins · 2K total installs
How We Detect Innozilla Image Gallery 8
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/innozilla-image-gallery-8/css/front_style.css/wp-content/plugins/innozilla-image-gallery-8/css/lity.css/wp-content/plugins/innozilla-image-gallery-8/js/isotope.pkgd.min.js/wp-content/plugins/innozilla-image-gallery-8/js/isotope_configure.js/wp-content/plugins/innozilla-image-gallery-8/js/imagesloaded.pkgd.min.js/wp-content/plugins/innozilla-image-gallery-8/js/infinite-scroll.pkgd.min.js/wp-content/plugins/innozilla-image-gallery-8/js/lity.js/wp-content/plugins/innozilla-image-gallery-8/js/isotope.pkgd.min.js/wp-content/plugins/innozilla-image-gallery-8/js/imagesloaded.pkgd.min.js/wp-content/plugins/innozilla-image-gallery-8/js/isotope_configure.js/wp-content/plugins/innozilla-image-gallery-8/js/infinite-scroll.pkgd.min.js/wp-content/plugins/innozilla-image-gallery-8/js/lity.jsinnozilla-image-gallery-8/js/isotope.pkgd.min.js?ver=innozilla-image-gallery-8/js/imagesloaded.pkgd.min.js?ver=innozilla-image-gallery-8/js/isotope_configure.js?ver=innozilla-image-gallery-8/js/infinite-scroll.pkgd.min.js?ver=innozilla-image-gallery-8/css/front_style.css?ver=innozilla-image-gallery-8/js/lity.js?ver=innozilla-image-gallery-8/css/lity.css?ver=HTML / DOM Fingerprints
IIG8_js_filterIIG8_listIIG8_list__itemdata-filterdata-litydata-titleiig8_option<div class="IIG8_js_filter" id=""><button data-filter="*" class="is-active"><button data-filter=".<ul class="IIG8_list">