
Multiple Gallery on Post Security & Risk Analysis
wordpress.org/plugins/multiple-gallery-on-postVery simple gallery plugin embedded on post as metaboxes, be able to add multiple metaboxes in one post with ability to insert multiple images for eac …
Is Multiple Gallery on Post Safe to Use in 2026?
Generally Safe
Score 85/100Multiple Gallery on Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "multiple-gallery-on-post" plugin, version 0.4, exhibits a generally strong security posture due to the absence of known vulnerabilities and a limited attack surface. The analysis indicates good practices such as 100% of SQL queries using prepared statements and the presence of nonce and capability checks. The lack of external HTTP requests and file operations further strengthens its security profile.
However, a significant concern arises from the very low percentage of properly escaped output (3%). This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data, if not properly sanitized before being displayed, could be exploited to inject malicious scripts. Although taint analysis reported no flows, this is based on zero flows being analyzed, making it an unreliable indicator of safety. The plugin's sole entry point, a shortcode, is not protected by authentication, which, while not immediately exploitable without other factors, represents a potential vector if it interacts with user-controlled input that is not properly escaped.
Overall, while the plugin demonstrates a commitment to secure coding practices in key areas like database interactions, the lack of adequate output escaping is a critical weakness. The absence of historical vulnerabilities is positive, but it does not negate the immediate risks identified in the static analysis. Users should be aware of the potential for XSS attacks due to insufficient output sanitization, despite the apparent lack of other severe security flaws.
Key Concerns
- Low percentage of properly escaped output
- Shortcode entry point lacks authentication
- Taint analysis not performed on any flows
Multiple Gallery on Post Security Vulnerabilities
Multiple Gallery on Post Code Analysis
Output Escaping
Multiple Gallery on Post Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Multiple Gallery on Post Maintenance & Trust
Maintenance Signals
Community Trust
Multiple Gallery on Post Alternatives
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Smart Slider 3
smart-slider-3
Responsive slider plugin to create sliders in visual editor easily. Build beautiful image slider, layer slider, video slider, post slider, and more.
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider
ml-slider
Slider, gallery, carousel plugin for WordPress. Build your image slider, video slider, post slider, YouTube slider, or WooCommerce product slider.
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Firelight Lightbox
easy-fancybox
Formerly Easy Fancybox. The most popular WordPress lightbox plugin. Simple, fast, and responsive. Opens images, videos, PDFs, and custom popups.
Multiple Gallery on Post Developer Profile
1 plugin · 200 total installs
How We Detect Multiple Gallery on Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multiple-gallery-on-post/admin/admin.css/wp-content/plugins/multiple-gallery-on-post/admin/admin.jsHTML / DOM Fingerprints
mgop-wrapmgop-formmgop_logomgop-filedmgop-filed-headermgop-post-typemgop-filed-contentinactive+8 moredata-fordata-rel[gallery-on-postgallery-on-post