
My WP Photos Security & Risk Analysis
wordpress.org/plugins/my-wp-photosDisplay your WordPress Photo Directory photos as a shortcode or Gutenberg block gallery.
Is My WP Photos Safe to Use in 2026?
Generally Safe
Score 100/100My WP Photos has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'my-wp-photos' v1.0 plugin exhibits a generally positive security posture, largely due to the absence of critical vulnerabilities in its code and a clean vulnerability history. The static analysis reveals a limited attack surface with only one shortcode, and importantly, no unprotected entry points. The use of prepared statements for all SQL queries and the presence of capability checks are strong indicators of good security practices. However, there are areas for improvement. A significant portion of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly echoed. The presence of external HTTP requests, while not inherently problematic, warrants careful review to ensure they are not fetching data from untrusted sources or being used in a way that could be exploited. The lack of nonce checks on the shortcode is a concern, as it could potentially be exploited by malicious actors to trigger unintended actions. The plugin's vulnerability history is clean, suggesting a developer who is either diligent about security or has not yet encountered complex vulnerabilities. Despite the positive aspects, the unescaped output and missing nonce check present tangible risks that should be addressed.
Key Concerns
- Unescaped output detected
- Missing nonce checks on shortcode
My WP Photos Security Vulnerabilities
My WP Photos Code Analysis
Output Escaping
My WP Photos Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
My WP Photos Maintenance & Trust
Maintenance Signals
Community Trust
My WP Photos Alternatives
WP iSell Photo
wp-isell-photo
Easily Sell photos, images, digital print etc. using the built-in WordPress gallery feature. Convert your WordPress gallery into a photo store.
Media Tagz Gallery
media-tags-gallery
Media Tagz Gallery extends the Media Tags plugin to provide a simple, lightweight image gallery
EGPS – Easy Sell for Google Photo
egps-easy-sell-for-google-photo
The simpliest way to display and sell your images from your Google Photos account on your WordPress site.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Simple Lightbox
simple-lightbox
The highly customizable lightbox for WordPress
My WP Photos Developer Profile
6 plugins · 2K total installs
How We Detect My WP Photos
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-wp-photos/build/index.css/wp-content/plugins/my-wp-photos/build/index.js/wp-content/plugins/my-wp-photos/build/index.jsmy-wp-photos/build/index.css?ver=my-wp-photos/build/index.js?ver=HTML / DOM Fingerprints
wp-block-my-wp-photos-gallerydata-aspectdata-columnsdata-countdata-randomdata-show-captiondata-show-exif+2 morewindow.wp.blocks.registerBlockTypewindow.wp.element.createElementwindow.wp.i18n.__window.wp.components.PanelBodywindow.wp.components.SelectControlwindow.wp.components.TextControl+3 more[my_wp_photos[my-wp-photos