
All In One Lightbox – Display Images, Audio, and Video in Popups Security & Risk Analysis
wordpress.org/plugins/lightbox-blockLightbox Block lets you display images, audio, video, and custom content in responsive lightbox galleries or media popups.
Is All In One Lightbox – Display Images, Audio, and Video in Popups Safe to Use in 2026?
Generally Safe
Score 99/100All In One Lightbox – Display Images, Audio, and Video in Popups has a strong security track record. Known vulnerabilities have been patched promptly.
The "lightbox-block" plugin v1.1.39 exhibits a generally strong security posture based on the static analysis. The code demonstrates good practices by utilizing prepared statements for all SQL queries and ensuring a very high percentage of output is properly escaped, minimizing the risk of cross-site scripting vulnerabilities originating from standard output. The presence of nonce and capability checks on several entry points further enhances its security. However, the plugin does make an external HTTP request, which is a potential point of concern if the target endpoint is not secure or if the request is made without proper validation of the response. The vulnerability history indicates a past medium-severity cross-site scripting vulnerability, and while it is currently patched, this pattern suggests a need for continued vigilance. The presence of the Freemius SDK, while common for monetization, can also introduce additional dependencies and potential attack vectors if not managed securely.
Key Concerns
- Past medium severity XSS vulnerability
- External HTTP request made
- Bundled Freemius SDK
All In One Lightbox – Display Images, Audio, and Video in Popups Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
LightBox Block <= 1.1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting
All In One Lightbox – Display Images, Audio, and Video in Popups Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
All In One Lightbox – Display Images, Audio, and Video in Popups Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 20
Maintenance & Trust
All In One Lightbox – Display Images, Audio, and Video in Popups Maintenance & Trust
Maintenance Signals
Community Trust
All In One Lightbox – Display Images, Audio, and Video in Popups Alternatives
Video Popup Block by WPZOOM
wpzoom-video-popup-block
Easily add a Gutenberg block to create customizable Play icon that open popups with YouTube, YouTube Shorts, TikTok, Vimeo, or MP4 videos
Carousel Block – Responsive Image and Content Carousel
b-carousel-block
Create stunning carousels effortlessly with the Carousel Block. Showcase your images in an elegant carousel directly within the Gutenberg editor.
bSlider – Create Responsive Image, Post, Product, and Video Sliders
b-slider
bSlider is a WordPress slider plugin that lets you create responsive image, post, product, and video carousels using the Gutenberg block & shortcode.
Light Modal Block
light-modal-block
Lightweight, customizable modal block for the WordPress block editor
Gutena Video Lightbox
gutena-lightbox
Gutena Video Lightbox is a WordPress Block that allows you to add a video in a popup window that goes over the website content.
All In One Lightbox – Display Images, Audio, and Video in Popups Developer Profile
120 plugins · 738K total installs
How We Detect All In One Lightbox – Display Images, Audio, and Video in Popups
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lightbox-block/assets/css/carousel.css/wp-content/plugins/lightbox-block/assets/css/carousel-thum.css/wp-content/plugins/lightbox-block/assets/css/shortcode.css/wp-content/plugins/lightbox-block/assets/css/plyr.min.css/wp-content/plugins/lightbox-block/assets/js/carousel.js/wp-content/plugins/lightbox-block/assets/js/carousel-thum.js/wp-content/plugins/lightbox-block/assets/js/plyr.min.js/wp-content/plugins/lightbox-block/assets/js/shortcode.js+2 more/wp-content/plugins/lightbox-block/assets/js/carousel.js/wp-content/plugins/lightbox-block/assets/js/carousel-thum.js/wp-content/plugins/lightbox-block/assets/js/plyr.min.js/wp-content/plugins/lightbox-block/assets/js/shortcode.js/wp-content/plugins/lightbox-block/build/custom-popup.jslightbox-block/assets/css/carousel.css?ver=lightbox-block/assets/css/carousel-thum.css?ver=lightbox-block/assets/css/shortcode.css?ver=lightbox-block/assets/css/plyr.min.css?ver=lightbox-block/assets/js/carousel.js?ver=lightbox-block/assets/js/carousel-thum.js?ver=lightbox-block/assets/js/plyr.min.js?ver=lightbox-block/assets/js/shortcode.js?ver=lightbox-block/build/custom-popup.js?ver=lightbox-block/build/custom-popup.css?ver=HTML / DOM Fingerprints
bpllb-lightboxbpllb-iconbpllb-icon-bpllb-close-buttonbpllb-img-wrapbpllb-img-bpllb-content-wrapbpllb-img-caption+8 moredata-lbb-elementdata-lbb-typedata-lbb-groupdata-lbb-optionsdata-lbb-itemdata-lbb-autoplay+2 morelbb_plugin_databpllbMediaUrlIdLBB_ASSETS_DIRLBB_DIR_URLLBB_PLUGIN_VERSION/wp-json/bpllb/v1/options[lbb_gallery[lbb_gallery_item