
InPost Gallery Security & Risk Analysis
wordpress.org/plugins/inpost-galleryInPost Gallery - photo and image gallery for WordPress
Is InPost Gallery Safe to Use in 2026?
Mostly Safe
Score 84/100InPost Gallery is generally safe to use. 7 past CVEs were resolved. Keep it updated.
The "inpost-gallery" v2.1.5 plugin exhibits a concerning security posture despite some positive indicators. While it demonstrates good practices in SQL query preparation and output escaping, the significant number of unprotected AJAX handlers presents a substantial attack surface. The presence of 4 out of 5 AJAX handlers lacking authentication checks means that unauthenticated users could potentially trigger sensitive actions or access data within the plugin. Furthermore, the plugin's history of 7 known CVEs, including critical and high-severity vulnerabilities like Code Injection, PHP Remote File Inclusion, and Cross-Site Scripting, is a major red flag. The fact that the last vulnerability was reported in 2025 suggests a recurring pattern of insecure coding practices that have led to serious security flaws in the past, even if none are currently unpatched. This history strongly indicates a need for thorough auditing and remediation of past issues before relying on this plugin.
Key Concerns
- High number of unprotected AJAX handlers
- High historical critical vulnerability count
- Historical high severity vulnerability count
- Historical medium severity vulnerability count
- Past vulnerabilities include Code Injection
- Past vulnerabilities include PHP Remote File Inclusion
- Past vulnerabilities include Cross-Site Scripting
- Past vulnerabilities include CSRF
InPost Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
InPost Gallery <= 2.1.4.5 - Authenticated (Subscriber+) Local File Inclusion
InPost Gallery <= 2.1.4.3 - Cross-Site Request Forgery
InPost Gallery <= 2.1.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template
InPost Gallery <= 2.1.4.1 - Reflected Cross-Site Scripting via 'imgurl'
InPost Gallery <= 2.1.4.1 - Local File Inclusion
InPost Gallery < 2.1.2.1 - Local File Inclusion
InPost Gallery <= 2.1.2 - Cross-Site Scripting
InPost Gallery Code Analysis
SQL Query Safety
Output Escaping
InPost Gallery Attack Surface
AJAX Handlers 5
WordPress Hooks 10
Maintenance & Trust
InPost Gallery Maintenance & Trust
Maintenance Signals
Community Trust
InPost Gallery Alternatives
Photo Gallery – Responsive Image Galleries by Supsystic
gallery-by-supsystic
Photo Gallery helps you create clean, responsive image galleries and album galleries without wrestling with complex settings, layouts, or custom CSS.
Album Gallery
new-album-gallery
Create stunning photo and video albums with responsive layouts, lightbox display, and customizable hover effects.
Social Photo Gallery
social-photo-gallery
Social Photo Gallery allow Polaroid image gallery.
Crisp Gallery
crisp-gallery
Free responsive WordPress gallery plugin where you can display images in a grid layout. Custom options included for each gallery with border or border …
Easy Album Gallery
easy-album-gallery
Easy Album Gallery is a powerful WordPress plugin that allows you to create stunning, professional photo galleries in minutes.
InPost Gallery Developer Profile
12 plugins · 188K total installs
How We Detect InPost Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/inpost-gallery/css/admin.css/wp-content/plugins/inpost-gallery/js/admin.js/wp-content/plugins/inpost-gallery/js/wp38/admin.js/wp-content/plugins/inpost-gallery/js/admin.js/wp-content/plugins/inpost-gallery/js/wp38/admin.jsinpost-gallery/style.css?ver=inpost-gallery/js/admin.js?ver=inpost-gallery/js/wp38/admin.js?ver=inpost-gallery/css/admin.css?ver=HTML / DOM Fingerprints
data-inpost-gallery-shortcode-idpn_ext_shortcodes_app_linkpn_ext_shortcodes_itemspn_lang_loadinginpost_is_frontinpost_gallery_post_idajaxurl+1 more/wp-json/inpost-gallery/v1/settings[inpost_gallery