NexGrid Catalog Gallery Security & Risk Analysis

wordpress.org/plugins/nexgrid-catalog-gallery

Lightweight product catalog with tree view and responsive grid. Easily filter products from blog posts using root category.

0 active installs v3.9.4 PHP + WP 5.0+ Updated Mar 23, 2026
category-treegrid-layoutproduct-catalogproduct-galleryresponsive-catalog
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NexGrid Catalog Gallery Safe to Use in 2026?

Generally Safe

Score 100/100

NexGrid Catalog Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The nexgrid-catalog-gallery plugin version 3.9.4 exhibits a strong security posture based on the provided static analysis. There are no detected dangerous functions, SQL queries are exclusively using prepared statements, and all output is properly escaped. Furthermore, the plugin avoids file operations and external HTTP requests, which are common vectors for vulnerabilities. The absence of any recorded CVEs, critical taint flows, or critical severity issues in the vulnerability history is highly reassuring, indicating a well-maintained and secure codebase over time.

While the static analysis reveals an excellent adherence to secure coding practices and a clean vulnerability history, the absence of any capability checks or nonce checks is a notable area of concern. This suggests that the single identified shortcode entry point, while not directly identified as vulnerable by static analysis, might lack the necessary authorization and integrity checks. If this shortcode handles any user-provided data or performs actions that could be exploited by an authenticated or unauthenticated user, it could represent a potential risk. The lack of recorded vulnerabilities in the past is a positive indicator, but it is crucial to ensure all entry points are adequately protected, especially as the plugin evolves.

In conclusion, nexgrid-catalog-gallery v3.9.4 demonstrates a commendable commitment to security through its code quality and lack of historical vulnerabilities. However, the absence of capability and nonce checks on its shortcode presents a potential, albeit unproven, weakness that warrants further investigation to ensure robust access control and to prevent potential exploit scenarios.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

NexGrid Catalog Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

NexGrid Catalog Gallery Release Timeline

v3.9.4Current
v3.9.0
Code Analysis
Analyzed Apr 16, 2026

NexGrid Catalog Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
80 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped80 total outputs
Attack Surface

NexGrid Catalog Gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ngcgal_catalog] nexgrid-catalog-gallery.php:178
WordPress Hooks 8
actionadmin_menunexgrid-catalog-gallery.php:22
actionadmin_initnexgrid-catalog-gallery.php:38
filterngcgal_product_contentnexgrid-catalog-gallery.php:420
filterngcgal_product_contentnexgrid-catalog-gallery.php:421
filterngcgal_product_contentnexgrid-catalog-gallery.php:422
filterngcgal_product_contentnexgrid-catalog-gallery.php:423
filterngcgal_product_contentnexgrid-catalog-gallery.php:424
filterngcgal_product_contentnexgrid-catalog-gallery.php:425
Maintenance & Trust

NexGrid Catalog Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 23, 2026
PHP min version
Downloads98

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

NexGrid Catalog Gallery Developer Profile

Hakan GERMAN

2 plugins · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NexGrid Catalog Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nexgrid-catalog-gallery/css/ngcgal-style.css/wp-content/plugins/nexgrid-catalog-gallery/js/ngcgal-main.js
Script Paths
/wp-content/plugins/nexgrid-catalog-gallery/js/ngcgal-main.js
Version Parameters
nexgrid-catalog-gallery/css/ngcgal-style.css?ver=nexgrid-catalog-gallery/js/ngcgal-main.js?ver=

HTML / DOM Fingerprints

CSS Classes
ngcgal-listngcgal-rootngcgal-subngcgal-itemngcgal-titlengcgal-gridngcgal-arrowngcgal-grid-wrapper+8 more
HTML Comments
<!-- NexGrid Catalog Gallery Settings --><!-- Quick Start Guide -->
Data Attributes
data-iddata-target
JS Globals
ngcgal_data
Shortcode Output
[ngcgal_catalog]
FAQ

Frequently Asked Questions about NexGrid Catalog Gallery