
JJ NextGen Image List Security & Risk Analysis
wordpress.org/plugins/jj-nextgen-image-listAllows you to pick a gallery from the 'NextGen Gallery' plugin to list images from. You can list images vertically or horizontally.
Is JJ NextGen Image List Safe to Use in 2026?
Generally Safe
Score 85/100JJ NextGen Image List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "jj-nextgen-image-list" v1.0.3 plugin exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities and a very small attack surface, with no identified AJAX handlers or REST API routes lacking proper authorization checks. The absence of file operations and external HTTP requests further contributes to a generally safer profile. However, several concerning code signals are present. The use of the `create_function` is a significant red flag, as it can lead to remote code execution vulnerabilities if not handled with extreme care, especially when dealing with user-supplied input. Furthermore, all SQL queries are executed without prepared statements, making them susceptible to SQL injection attacks. The low percentage of properly escaped output suggests a high likelihood of cross-site scripting (XSS) vulnerabilities. The lack of nonce checks, despite having a shortcode, could also present a security risk if that shortcode handles sensitive operations or displays user-modifiable content without proper CSRF protection. The vulnerability history shows a clean slate, which is positive, but it doesn't negate the inherent risks identified in the code analysis.
Key Concerns
- Dangerous function used (create_function)
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- No nonce checks on shortcode
- No capability checks
JJ NextGen Image List Security Vulnerabilities
JJ NextGen Image List Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
JJ NextGen Image List Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
JJ NextGen Image List Maintenance & Trust
Maintenance Signals
Community Trust
JJ NextGen Image List Alternatives
JJ NextGen JQuery Slider
jj-nextgen-jquery-slider
Allows you to pick a gallery from the 'NextGen Gallery' plugin to use as a 'JQuery Nivo slider'.
NextGEN Gallery Sidebar Widget
nextgen-gallery-sidebar-widget
A widget to show NextGEN galleries in your sidebar.
JJ NextGen JQuery Carousel
jj-nextgen-jquery-carousel
Allows you to pick a gallery from the 'NextGen Gallery' plugin to use as a 'JQuery JCarousel'.
NextGen NivoSlider
nextgen-nivoslider
The NextGen Nivoslider plugin allows you to create a NivoSlider, using images from your NextGen gallery, with a simple shortcode or widget.
JJ NextGen JQuery Cycle
jj-nextgen-jquery-cycle
Allows you to pick a gallery from the 'NextGen Gallery' plugin to use with 'JQuery Cycle Lite'.
JJ NextGen Image List Developer Profile
5 plugins · 2K total installs
How We Detect JJ NextGen Image List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jj-nextgen-image-list/script/jquery.jj_ngg_shuffle.js/wp-content/plugins/jj-nextgen-image-list/stylesheets/style.css/wp-content/plugins/jj-nextgen-image-list/script/jquery.jj_ngg_shuffle.jsjj-nextgen-image-list/script/jquery.jj_ngg_shuffle.js?ver=jj-nextgen-image-list/stylesheets/style.css?ver=HTML / DOM Fingerprints
jj-ngg-image-listdata-gallery-iddata-orderdata-html-iddata-countdata-typedata-thumb-width+15 morejQuery.jj_ngg_shuffle[jj-ngg-image-list]