ModuloBox – NextGen Lightbox Security & Risk Analysis

wordpress.org/plugins/modulobox-lite

A modular, versatile & highly customizable lightbox plugin to display your media in a fully responsive popup.

200 active installs v1.7.0 PHP 7.0+ WP 6.0+ Updated Jan 10, 2025
gallerygridimageslightboxpopup
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ModuloBox – NextGen Lightbox Safe to Use in 2026?

Generally Safe

Score 92/100

ModuloBox – NextGen Lightbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Modulobox Lite v1.7.0 presents a generally good security posture, with several positive indicators. The plugin has a very small attack surface, consisting of a single shortcode, and importantly, all identified entry points lack direct unprotected access. The code demonstrates strong adherence to secure database practices, with 100% of SQL queries utilizing prepared statements, and a commendable number of nonce and capability checks (3 and 5 respectively). This suggests the developers are mindful of common WordPress security vulnerabilities.

However, there are areas for improvement. The code analysis reveals that 62% of output is properly escaped, leaving a significant portion potentially vulnerable to cross-site scripting (XSS) attacks. Furthermore, the taint analysis identified two flows with unsanitized paths, which could represent a risk if these paths are influenced by user input without proper validation or sanitization. While the plugin has no recorded vulnerability history, this could be due to its relative obscurity or a lack of rigorous public auditing rather than absolute security.

In conclusion, Modulobox Lite v1.7.0 exhibits a solid foundation in secure coding practices, particularly regarding database interactions and entry point protection. The low attack surface and presence of checks are strengths. The primary concerns revolve around the unescaped output and the identified unsanitized paths in the taint analysis, which warrant further investigation. The absence of past vulnerabilities is positive but should be viewed with caution, as it doesn't guarantee future immunity.

Key Concerns

  • Unescaped output found
  • Unsanitized paths in taint flow
Vulnerabilities
None known

ModuloBox – NextGen Lightbox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ModuloBox – NextGen Lightbox Release Timeline

v1.7.0Current
v1.5.0
v1.4.0
v1.3.0
v1.2.0
v1.0.5
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

ModuloBox – NextGen Lightbox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
116
190 escaped
Nonce Checks
3
Capability Checks
5
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

62% escaped306 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
import_settings (admin\settings-field.class.php:323)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ModuloBox – NextGen Lightbox Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[gallery] public\gallery.class.php:88
WordPress Hooks 11
actionadmin_menuadmin\admin-init.class.php:31
actionadmin_enqueue_scriptsadmin\admin-init.class.php:33
actionadmin_initadmin\attachment.class.php:30
actionprint_media_templatesadmin\attachment.class.php:47
actionwp_enqueue_mediaadmin\attachment.class.php:49
actionadmin_initadmin\settings-field.class.php:73
actionadmin_enqueue_scriptsadmin\settings-field.class.php:75
actioninitmodulobox.php:137
filterrender_blockpublic\gallery.class.php:90
actionwppublic\init.class.php:47
actionwp_enqueue_scriptspublic\init.class.php:68
Maintenance & Trust

ModuloBox – NextGen Lightbox Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 10, 2025
PHP min version7.0
Downloads12K

Community Trust

Rating96/100
Number of ratings6
Active installs200
Developer Profile

ModuloBox – NextGen Lightbox Developer Profile

Themeone

1 plugin · 200 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ModuloBox – NextGen Lightbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/modulobox-lite/admin/css/admin-style.css/wp-content/plugins/modulobox-lite/admin/js/admin-script.js/wp-content/plugins/modulobox-lite/public/css/lightbox.css/wp-content/plugins/modulobox-lite/public/js/gallery.js/wp-content/plugins/modulobox-lite/public/js/lightbox.js
Script Paths
/wp-content/plugins/modulobox-lite/admin/js/admin-script.js/wp-content/plugins/modulobox-lite/public/js/gallery.js/wp-content/plugins/modulobox-lite/public/js/lightbox.js
Version Parameters
modulobox-lite/admin/css/admin-style.css?ver=modulobox-lite/admin/js/admin-script.js?ver=modulobox-lite/public/css/lightbox.css?ver=modulobox-lite/public/js/gallery.js?ver=modulobox-lite/public/js/lightbox.js?ver=

HTML / DOM Fingerprints

CSS Classes
mobx-gallerymobx-gallery-item
HTML Comments
<!-- ModuloBox Lite Admin Views Header --><!-- ModuloBox Lite Admin Views Tabs --><!-- ModuloBox Lite Admin Views Form Start --><!-- ModuloBox Lite Admin Views General Section -->+12 more
Data Attributes
data-mobx-gallery-id
JS Globals
window.ModuloBox
FAQ

Frequently Asked Questions about ModuloBox – NextGen Lightbox