
IS Circular Photo Gallery Security & Risk Analysis
wordpress.org/plugins/is-circular-photo-galleryCircle style picture gallery with Lightbox popups. Uses images from either the Wordpress Media Library or an uploaded directory of images.
Is IS Circular Photo Gallery Safe to Use in 2026?
Generally Safe
Score 85/100IS Circular Photo Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'is-circular-photo-gallery' plugin v1.9 exhibits a generally strong security posture based on the provided static analysis. The plugin has a very limited attack surface, with only one shortcode identified and no AJAX handlers, REST API routes, or cron events that are not protected by authentication checks. The code signals further reinforce this positive assessment, showing no dangerous functions, file operations, or external HTTP requests. All SQL queries are properly prepared, and crucial security mechanisms like nonce checks and capability checks are present. The absence of any taint analysis findings, critical or high severity, suggests that direct code execution or injection vulnerabilities are unlikely.
However, a significant concern arises from the output escaping analysis, where only 4% of 53 total outputs are properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the plugin demonstrates good practices in other areas, the lack of adequate output sanitization for the majority of its outputs is a critical weakness that could be exploited by attackers to inject malicious scripts into the website.
The vulnerability history of this plugin is clean, with no recorded CVEs. This, combined with the static analysis findings (excluding the output escaping issue), suggests a development team that is likely aware of security best practices. Nevertheless, the identified output escaping deficiency represents a tangible and exploitable risk that overshadows the otherwise positive security indicators.
Key Concerns
- Low percentage of properly escaped output
IS Circular Photo Gallery Security Vulnerabilities
IS Circular Photo Gallery Code Analysis
Output Escaping
Data Flow Analysis
IS Circular Photo Gallery Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
IS Circular Photo Gallery Maintenance & Trust
Maintenance Signals
Community Trust
IS Circular Photo Gallery Alternatives
PiwigoPress
piwigopress
From any open API Piwigo gallery, swiftly include your photos in Posts/Pages and/or add randomized thumbnails and menus in your sidebar.
IS Photo Gallery
is-photo-gallery
Picture gallery with Lightbox popups. Uses images from either the Wordpress Media Library or an uploaded directory of images.
WP-Polaroid Plus
polaroid-plus-gallery
Polaroid Plus style picture gallery with Lightbox popups. Uses images from either the Wordpress Media Library or an uploaded directory of images.
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress
gallery-plugin
Add beautiful, fully responsive galleries, albums, images, and categories to your WordPress website quickly and easily. Showcase your portfolio, photo …
Social Photo Fetcher
facebook-photo-fetcher
Allows you to automatically create Wordpress photo galleries from Facebook albums. Simple to use and highly customizable.
IS Circular Photo Gallery Developer Profile
3 plugins · 40 total installs
How We Detect IS Circular Photo Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/is-circular-photo-gallery/js/iscpgallery.js/wp-content/plugins/is-circular-photo-gallery/css/iscpgallery.css/wp-content/plugins/is-circular-photo-gallery/img/loading.gif/wp-content/plugins/is-circular-photo-gallery/js/iscpgallery.jsis-circular-photo-gallery/js/iscpgallery.js?ver=is-circular-photo-gallery/css/iscpgallery.css?ver=HTML / DOM Fingerprints
iscp_imageflowiscp_loadingiscp_imagesiscp_captionsiscp_slideriscp_scrollbariscp_imageflow_noscriptiscp_largerimages+1 more**
Nothing needs to be done for now
*/**
Nothing needs to be done for now
*/**
** WP-IS Circular Photo gallery shortcode handler
*/**
** Increment the instance to support multiple galleries on a single page
*/+11 moredata-styledata-descriptioniscirculargallery<div id="iscp_imageflow_<div id="iscp_loading_<img src="/img/loading.gif