
Album Gallery Security & Risk Analysis
wordpress.org/plugins/new-album-galleryCreate stunning photo and video albums with responsive layouts, lightbox display, and customizable hover effects.
Is Album Gallery Safe to Use in 2026?
Generally Safe
Score 97/100Album Gallery has a strong security track record. Known vulnerabilities have been patched promptly.
The 'new-album-gallery' v1.7.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a limited attack surface with all identified entry points (AJAX handlers and shortcodes) protected by at least one type of check (nonce or capability). The code demonstrates strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and a very high rate of output escaping (96%). There are no observed dangerous functions, file operations, or external HTTP requests, further contributing to a secure foundation.
However, the plugin's vulnerability history presents a significant concern. With three known CVEs, including one high and two medium severity vulnerabilities, and a recent patch in February 2025, it indicates a pattern of past security flaws. The common types of vulnerabilities like Deserialization of Untrusted Data, Missing Authorization, and Cross-Site Request Forgery suggest recurring security weaknesses that have required external intervention. While the current version might be patched, the historical data points to potential underlying architectural issues or a development process that has historically overlooked certain security aspects.
The taint analysis, while showing no critical or high severity unsanitized flows, does report two flows with unsanitized paths. Although these did not reach critical levels in the analysis, they represent potential areas where malicious input could be processed without adequate sanitization, which, when combined with the plugin's history, warrants careful consideration.
Key Concerns
- Past high severity vulnerabilities
- Past medium severity vulnerabilities
- Flows with unsanitized paths
Album Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Album Gallery – WordPress Gallery <= 1.6.3 - Authenticated (Editor+) PHP Object Injection via Gallery Meta
Album Gallery – WordPress Gallery <= 1.5.7 - Missing Authorization
Album Gallery – WordPress Gallery <= 1.4.9 - Cross-Site Request Forgery via album-gallery-column-settings.php
Album Gallery Release Timeline
Album Gallery Code Analysis
Output Escaping
Data Flow Analysis
Album Gallery Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 35
Maintenance & Trust
Album Gallery Maintenance & Trust
Maintenance Signals
Community Trust
Album Gallery Alternatives
FolioBlocks
folioblocks
Create fast, responsive photo and video galleries with grid, masonry, justified, modular, and carousel layouts—ideal for photographers and creatives.
Gallery by FooGallery
foogallery
Photo Gallery, Image Gallery by FooGallery — fast, responsive, SEO-optimized, and packed with beautiful layouts.
Photo Gallery – Responsive Image Galleries by Supsystic
gallery-by-supsystic
Photo Gallery helps you create clean, responsive image galleries and album galleries without wrestling with complex settings, layouts, or custom CSS.
Album Gallery For Flickr
flickr-album-gallery
Display Flickr albums on WordPress with lightbox preview, SEO-friendly galleries, and easy shortcode integration.
Image Gallery
new-image-gallery
Create responsive image galleries with lightbox, grid & masonry layouts. Easy shortcode display for posts and pages.
Album Gallery Developer Profile
64 plugins · 85K total installs
How We Detect Album Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/new-album-gallery/assets/js/album-gallery-common.js/wp-content/plugins/new-album-gallery/assets/js/magnific-popup/jquery.magnific-popup.min.js/wp-content/plugins/new-album-gallery/assets/js/magnific-popup/magnific-popup-init.js/wp-content/plugins/new-album-gallery/assets/css/gallery-style.css/wp-content/plugins/new-album-gallery/assets/css/magnific-popup.css/wp-content/plugins/new-album-gallery/assets/js/album-gallery-common.js/wp-content/plugins/new-album-gallery/assets/js/magnific-popup/jquery.magnific-popup.min.js/wp-content/plugins/new-album-gallery/assets/js/magnific-popup/magnific-popup-init.jsnew-album-gallery/assets/js/album-gallery-common.js?ver=new-album-gallery/assets/js/magnific-popup/jquery.magnific-popup.min.js?ver=new-album-gallery/assets/js/magnific-popup/magnific-popup-init.js?ver=new-album-gallery/assets/css/gallery-style.css?ver=new-album-gallery/assets/css/magnific-popup.css?ver=HTML / DOM Fingerprints
album-gallery-shortcodeag-gallery-mainag-gallery-itemag-gallery-captiondata-postidALBUMCopyShortcode[AGAL id=