Meta-box GalleryMeta Security & Risk Analysis

wordpress.org/plugins/meta-box-gallerymeta

Just another gallery plugin. Simple but flexible.

0 active installs v3.1 PHP 7.4+ WP 5.8+ Updated Jan 26, 2026
carouselgalleryslider
98
A · Safe
CVEs total2
Unpatched0
Last CVEJan 23, 2026
Safety Verdict

Is Meta-box GalleryMeta Safe to Use in 2026?

Generally Safe

Score 98/100

Meta-box GalleryMeta has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jan 23, 2026Updated 2mo ago
Risk Assessment

The plugin "meta-box-gallerymeta" v3.1 demonstrates generally good security practices with a strong emphasis on output escaping and the use of prepared statements for SQL queries. The code analysis reveals no dangerous functions, file operations, or external HTTP requests, and all identified entry points (shortcodes) appear to have proper authorization checks and nonce validation. Taint analysis also shows no critical or high severity vulnerabilities, indicating that the plugin is not susceptible to common input-based attacks like cross-site scripting or SQL injection through tainted data.

Key Concerns

  • Two medium severity CVEs in history
  • History of XSS and Missing Authorization vulnerabilities
  • Last vulnerability in the future
Vulnerabilities
2

Meta-box GalleryMeta Security Vulnerabilities

CVEs by Year

2 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-1302medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Meta-box GalleryMeta <= 3.0.1 - Authenticated (Editor+) Stored Cross-Site Scripting via Image Caption

Jan 23, 2026 Patched in 3.1 (11d)
CVE-2026-0687medium · 4.3Missing Authorization

Meta-box GalleryMeta <= 3.0.1 - Missing Authorization to Authenticated (Author+) Gallery Management

Jan 23, 2026 Patched in 3.1 (11d)
Code Analysis
Analyzed Mar 17, 2026

Meta-box GalleryMeta Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
79 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped83 total outputs
Attack Surface

Meta-box GalleryMeta Attack Surface

Entry Points5
Unprotected0

Shortcodes 5

[mbg-front-show] gallerymetaboxes.php:178
[mbg-front-mordan] gallerymetaboxes.php:251
[mbg-front-carousel] gallerymetaboxes.php:293
[mbgm_gallery] gallerymetaboxes.php:354
[mbgm_sliders] include\sliders.php:127
WordPress Hooks 14
filtersingle_templategallerymetaboxes.php:35
actionadd_meta_boxesgallerymetaboxes.php:50
actionsave_postgallerymetaboxes.php:94
actionadmin_initgallerymetaboxes.php:357
actionadmin_menugallerymetaboxes.php:378
filtermanage_mb_gallery_posts_columnsgallerymetaboxes.php:585
filtermanage_mb_gallery_posts_columnsgallerymetaboxes.php:595
actionmanage_mb_gallery_posts_custom_columngallerymetaboxes.php:601
actionadmin_enqueue_scriptsinclude\enqueue.php:12
actionwp_enqueue_scriptsinclude\enqueue.php:48
filterattachment_fields_to_editinclude\medianame.php:21
filterattachment_fields_to_saveinclude\medianame.php:36
actioninitinclude\posttype.php:5
actioninitinclude\posttype.php:42
Maintenance & Trust

Meta-box GalleryMeta Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 26, 2026
PHP min version7.4
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Meta-box GalleryMeta Developer Profile

Md. Shahinur Islam

7 plugins · 730 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect Meta-box GalleryMeta

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/meta-box-gallerymeta/assets/js/main.js/wp-content/plugins/meta-box-gallerymeta/assets/css/style.css
Script Paths
meta-box-gallerymeta/assets/js/main.jsmeta-box-gallerymeta/assets/css/style.css
Version Parameters
meta-box-gallerymeta/assets/js/main.js?ver=meta-box-gallerymeta/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
gallery-addgallery-metabox-listimage-previewchange-imageremove-imagecarousel-innercarousel-itemembed-responsive+2 more
Data Attributes
data-uploader-titledata-uploader-button-text
JS Globals
mbgm_gallery_id
Shortcode Output
<div class="container"><div class="row"><article class="post"><div class="post-media">
FAQ

Frequently Asked Questions about Meta-box GalleryMeta