
New Simple Gallery Security & Risk Analysis
wordpress.org/plugins/new-simple-galleryTo display images as an automatic slideshow that can also be explicitly played or paused by the user.
Is New Simple Gallery Safe to Use in 2026?
Use With Caution
Score 63/100New Simple Gallery has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "new-simple-gallery" plugin version 8.0 exhibits a mixed security posture. On one hand, the static analysis reveals several positive security practices. The plugin utilizes prepared statements for all its SQL queries, indicating a strong defense against SQL injection through database interactions. There are also a reasonable number of nonce checks present, which helps in validating user requests. The limited attack surface, with only one shortcode and no exposed AJAX handlers or REST API routes without authentication, is also a positive indicator.
However, the plugin is not without its concerns. The most significant is the presence of a known, unpatched medium severity vulnerability from 2025-09-05, which historically has been related to SQL injection. This single unpatched CVE poses a considerable risk to any WordPress site using this version. Furthermore, the static analysis shows that only 63% of output is properly escaped. While not a critical flaw on its own, a large number of unescaped outputs can contribute to cross-site scripting (XSS) vulnerabilities if not carefully managed within the context of the application.
In conclusion, while the plugin demonstrates good practices in areas like SQL query handling and limiting its direct attack surface, the single unpatched SQL injection vulnerability from its history is a critical weakness that outweighs these strengths. The moderate rate of output escaping is also a point of attention. Website administrators should prioritize updating or replacing this plugin to mitigate the known security risk.
Key Concerns
- Unpatched medium CVE
- Significant amount of unescaped output
New Simple Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
New Simple Gallery <= 8.0 - Authenticated (Contributor+) SQL Injection
New Simple Gallery Release Timeline
New Simple Gallery Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
New Simple Gallery Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
New Simple Gallery Maintenance & Trust
Maintenance Signals
Community Trust
New Simple Gallery Alternatives
GPP Slideshow
gpp-slideshow
A minimalist slideshow plugin that creates a new gallery post type. Add slideshows to widgets, posts, pages and gallery posts.
WP Bootstrap Carousel
wp-bootstrap-carousel
A simple, straightforward implementation of the Twitter Bootstrap Carousel in WordPress.
Simple Slider
simple-slider
Create and Manage simple slideshows using images in WordPress media system
Coin Slider 4 WordPress
coin-slider-4-wp
Coin Slider 4 WP is Wordpress plugin for creating image gallery with unique transition effects of featured posts. You can choose between three types o …
WPJaipho Mobile Gallery
wpjaipho
WPJaipho extends native Wordpress image gallery, NextGEN 1.x and NextCellent Gallery with optimized support for mobile users
New Simple Gallery Developer Profile
54 plugins · 17K total installs
How We Detect New Simple Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/new-simple-gallery/new-simple-gallery.jsnew-simple-gallery/new-simple-gallery.js?ver=HTML / DOM Fingerprints
newsimplegallery<script type="text/javascript">var mygallery=new newsimplegallery({wrapperid:dimensions: [imagearray: [