
Image Gallery Security & Risk Analysis
wordpress.org/plugins/new-image-galleryCreate responsive image gallery, photo gallery with lightbox, grid & masonry layouts. Display using shortcode, Gutenberg block or Elementor widget.
Is Image Gallery Safe to Use in 2026?
Generally Safe
Score 97/100Image Gallery has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "new-image-gallery" plugin version 1.6.1 presents a mixed security posture. On the positive side, it demonstrates good practices such as exclusively using prepared statements for SQL queries, a high percentage of properly escaped output, and a good number of nonce and capability checks. The attack surface is relatively small with no identified unprotected entry points, and there are no external HTTP requests or file operations, which limits potential attack vectors. However, the presence of two instances of the `unserialize` function is a significant concern, as this function can be vulnerable to deserialization attacks if not handled with extreme care, especially with untrusted data. The taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high severity in this analysis, warrants attention given the use of `unserialize`.
The plugin's vulnerability history is a critical red flag. It has a total of two known CVEs, with one high and one medium severity vulnerability previously identified. Although currently no vulnerabilities are marked as unpatched, the recurring themes of "Deserialization of Untrusted Data" and "Missing Authorization" in past vulnerabilities are directly aligned with the static analysis findings, particularly the `unserialize` calls and the potential for authorization bypasses. The last vulnerability reported in 2026, while seemingly in the future, strongly suggests a pattern of past issues related to these categories. The plugin's strengths in other areas are overshadowed by these historical and statically identified risks, particularly the `unserialize` function, which requires rigorous validation of any data passed to it. While no active unpatched vulnerabilities are reported, the historical pattern and the presence of the `unserialize` function create a considerable risk.
Key Concerns
- Dangerous function unserialize used
- Flows with unsanitized paths found
- Previous high severity CVE
- Previous medium severity CVE
Image Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery <= 1.6.0 - Authenticated (Contributor+) PHP Object Injection
Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery <= 1.4.5 - Missing Authorization
Image Gallery Release Timeline
Image Gallery Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Image Gallery Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 37
Maintenance & Trust
Image Gallery Maintenance & Trust
Maintenance Signals
Community Trust
Image Gallery Alternatives
Gallery by Visual Portfolio
visual-portfolio
Build photo galleries, image galleries, and portfolio grids with gallery blocks. Masonry, lightbox, sliders, and filters included.
Filter Gallery
filter-gallery
Build a responsive filter gallery for your portfolio. Organize images with filters in a stunning grid or masonry layout easily.
Image Gallery Block – Photo Gallery, Masonry & Lightbox
3d-image-gallery
Image gallery & photo gallery block for Gutenberg - responsive grids, masonry layouts, lightbox popups, and 3D image sliders.
Masonry Image Gallery Block
mgb-masonry-image-gallery
Masonry Image Gallery is a custom Gutenberg Block built with Native Components to show image gallery in masonry style.
Grid Gallery – for Photo Gallery, Image Gallery & Portfolio
new-grid-gallery
Create a beautiful Photo Gallery, Image Gallery, or Portfolio. Use Simple Shortcodes and it Supports Gutenberg Block and Elementor Widget.
Image Gallery Developer Profile
65 plugins · 87K total installs
How We Detect Image Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/new-image-gallery/js/custom.js/wp-content/plugins/new-image-gallery/css/custom.css/wp-content/plugins/new-image-gallery/js/custom.jsnew-image-gallery/js/custom.js?ver=new-image-gallery/css/custom.css?ver=HTML / DOM Fingerprints
ig-gallery-wrap<!--Start New Image Gallery--><!--End New Image Gallery-->data-gallery-idNewImageGallery[IMG-Gal id=