
Image Gallery Security & Risk Analysis
wordpress.org/plugins/new-image-galleryCreate responsive image galleries with lightbox, grid & masonry layouts. Easy shortcode display for posts and pages.
Is Image Gallery Safe to Use in 2026?
Generally Safe
Score 96/100Image Gallery has a strong security track record. Known vulnerabilities have been patched promptly.
The "new-image-gallery" plugin version 1.6.1 presents a mixed security posture. On the positive side, it demonstrates good practices such as exclusively using prepared statements for SQL queries, a high percentage of properly escaped output, and a good number of nonce and capability checks. The attack surface is relatively small with no identified unprotected entry points, and there are no external HTTP requests or file operations, which limits potential attack vectors. However, the presence of two instances of the `unserialize` function is a significant concern, as this function can be vulnerable to deserialization attacks if not handled with extreme care, especially with untrusted data. The taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high severity in this analysis, warrants attention given the use of `unserialize`.
The plugin's vulnerability history is a critical red flag. It has a total of two known CVEs, with one high and one medium severity vulnerability previously identified. Although currently no vulnerabilities are marked as unpatched, the recurring themes of "Deserialization of Untrusted Data" and "Missing Authorization" in past vulnerabilities are directly aligned with the static analysis findings, particularly the `unserialize` calls and the potential for authorization bypasses. The last vulnerability reported in 2026, while seemingly in the future, strongly suggests a pattern of past issues related to these categories. The plugin's strengths in other areas are overshadowed by these historical and statically identified risks, particularly the `unserialize` function, which requires rigorous validation of any data passed to it. While no active unpatched vulnerabilities are reported, the historical pattern and the presence of the `unserialize` function create a considerable risk.
Key Concerns
- Dangerous function unserialize used
- Flows with unsanitized paths found
- Previous high severity CVE
- Previous medium severity CVE
Image Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery <= 1.6.0 - Authenticated (Contributor+) PHP Object Injection
Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery <= 1.4.5 - Missing Authorization
Image Gallery Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Image Gallery Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 37
Maintenance & Trust
Image Gallery Maintenance & Trust
Maintenance Signals
Community Trust
Image Gallery Alternatives
Gallery by FooGallery
foogallery
Photo Gallery, Image Gallery by FooGallery — fast, responsive, SEO-optimized, and packed with beautiful layouts.
Album Gallery For Flickr
flickr-album-gallery
Display Flickr albums on WordPress with lightbox preview, SEO-friendly galleries, and easy shortcode integration.
Album Gallery
new-album-gallery
Create stunning photo and video albums with responsive layouts, lightbox display, and customizable hover effects.
Lightbox slider – Responsive Lightbox Gallery
simple-lightbox-gallery
Lightbox slider plugin is allow users to view larger versions of images, simple slide shows and Gallery view with Responsive grid layout.
Image Gallery Block – Create and display photo gallery/photo album.
3d-image-gallery
Image Gallery Block helps you create responsive photo galleries, masonry layouts, and 3D sliders. Offers professional layouts and lightbox effects.
Image Gallery Developer Profile
61 plugins · 64K total installs
How We Detect Image Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/new-image-gallery/js/custom.js/wp-content/plugins/new-image-gallery/css/custom.css/wp-content/plugins/new-image-gallery/js/custom.jsnew-image-gallery/js/custom.js?ver=new-image-gallery/css/custom.css?ver=HTML / DOM Fingerprints
ig-gallery-wrap<!--Start New Image Gallery--><!--End New Image Gallery-->data-gallery-idNewImageGallery[IMG-Gal id=