
Joli CLEAR Lightbox Security & Risk Analysis
wordpress.org/plugins/joli-clear-lightboxUltralight Lightbox for WordPress. Designed for Speed. No jQuery. Responsive with gestures. Simple, Elegant, yet highly Customizable.
Is Joli CLEAR Lightbox Safe to Use in 2026?
Generally Safe
Score 85/100Joli CLEAR Lightbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "joli-clear-lightbox" v1.0.3 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has a clean vulnerability history with no recorded CVEs. The absence of dangerous functions and a low number of file operations are also strengths. However, a significant concern is the presence of one AJAX handler that lacks authentication checks, creating a potential entry point for unauthorized actions. Furthermore, the taint analysis reveals four flows with unsanitized paths, indicating a risk of improper handling of user-supplied data, though these did not escalate to critical or high severity vulnerabilities in the static analysis. The plugin also has a high percentage of improperly escaped output, which could lead to cross-site scripting (XSS) vulnerabilities if the tainted data is rendered without proper sanitization. While the vulnerability history is clean, the static analysis findings point to areas that require immediate attention to bolster the plugin's overall security.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths
- Low percentage of properly escaped output
- Bundled Freemius v1.0 library
Joli CLEAR Lightbox Security Vulnerabilities
Joli CLEAR Lightbox Release Timeline
Joli CLEAR Lightbox Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Joli CLEAR Lightbox Attack Surface
AJAX Handlers 1
WordPress Hooks 33
Maintenance & Trust
Joli CLEAR Lightbox Maintenance & Trust
Maintenance Signals
Community Trust
Joli CLEAR Lightbox Alternatives
WP fancybox
wp-fancybox
View image, YouTube video, Vimeo video, inline HTML in lightbox. Add fancybox lightbox effect to your WordPress site.
Firelight Lightbox
easy-fancybox
Formerly Easy Fancybox. The most popular WordPress lightbox plugin. Simple, fast, and responsive. Opens images, videos, PDFs, and custom popups.
Gallery by FooGallery
foogallery
Photo Gallery, Image Gallery by FooGallery — fast, responsive, SEO-optimized, and packed with beautiful layouts.
Simple Lightbox
simple-lightbox
The highly customizable lightbox for WordPress
FancyBox for WordPress
fancybox-for-wordpress
Seamlessly integrates FancyBox lightbox into your WordPress blog: Upload, activate, and you're done. Additional configuration optional.
Joli CLEAR Lightbox Developer Profile
5 plugins · 8K total installs
How We Detect Joli CLEAR Lightbox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/joli-clear-lightbox/assets/admin/css/joli-clb-admin.css/wp-content/plugins/joli-clear-lightbox/assets/admin/js/joli-clb-admin.js/wp-content/plugins/joli-clear-lightbox/assets/admin/js/joli-clb-admin-notices.js/wp-content/plugins/joli-clear-lightbox/assets/public/css/wpjoli-clear-lightbox.css/wp-content/plugins/joli-clear-lightbox/assets/public/js/wpjoli-clear-lightbox.jsassets/admin/js/joli-clb-admin.jsassets/admin/js/joli-clb-admin-notices.jsassets/public/js/wpjoli-clear-lightbox.jsjoli-clear-lightbox/assets/admin/css/joli-clb-admin.css?ver=joli-clear-lightbox/assets/admin/js/joli-clb-admin.js?ver=joli-clear-lightbox/assets/admin/js/joli-clb-admin-notices.js?ver=joli-clear-lightbox/assets/public/css/wpjoli-clear-lightbox.css?ver=joli-clear-lightbox/assets/public/js/wpjoli-clear-lightbox.js?ver=HTML / DOM Fingerprints
wpjoli-clear-lightboxdata-wpjoli-lightbox-optionsjclbAdminjclbAdminNoticeJCLB