
NextGEN Custom Fields Security & Risk Analysis
wordpress.org/plugins/nextgen-gallery-custom-fieldsCreates the ability to quickly and easily add custom fields to NextGEN Galleries and Images.
Is NextGEN Custom Fields Safe to Use in 2026?
Generally Safe
Score 85/100NextGEN Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'nextgen-gallery-custom-fields' v1.2.5 exhibits a mixed security posture. On one hand, it has no recorded vulnerabilities (CVEs), no external HTTP requests, and no file operations, which are positive indicators. The attack surface is also reported as zero entry points, which, if accurate, is excellent. However, the static analysis reveals significant concerns within the code itself. A substantial percentage of SQL queries (77%) are not using prepared statements, indicating a high risk of SQL injection vulnerabilities. Furthermore, a worrying 76% of output is not properly escaped, pointing to a strong likelihood of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis specifically flags two high-severity flows with unsanitized paths, directly corroborating the risks of injection attacks.
Key Concerns
- High percentage of SQL queries without prepared statements
- High percentage of unescaped output
- Two high-severity unsanitized path flows
- No nonce checks found
- No capability checks found
NextGEN Custom Fields Security Vulnerabilities
NextGEN Custom Fields Release Timeline
NextGEN Custom Fields Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
NextGEN Custom Fields Attack Surface
WordPress Hooks 9
Maintenance & Trust
NextGEN Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
NextGEN Custom Fields Alternatives
Advanced Custom Fields: NextGen Gallery Custom Field
advanced-custom-fields-nextgen-gallery-custom-field
This plugin provides an extra field for the Advanced Custom Fields plugin to support the NextGEN Gallery plugin.
Advanced Custom Fields: NextGEN Gallery Field add-on
advanced-custom-fields-nextgen-gallery-field-add-on
Adds a NextGEN Gallery Field to Advanced Custom Fields. Select one or more NextGEN Galleries and assign them to the post.
Simple History NGG Loggers
simple-history-ngg-loggers
This plugin adds custom loggers to the 'Simple History' plugin which protocoll user activities for the 'NextGEN Gallery' plugin.
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
NextGEN Custom Fields Developer Profile
3 plugins · 1K total installs
How We Detect NextGEN Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nextgen-gallery-custom-fields/css//wp-content/plugins/nextgen-gallery-custom-fields/js//wp-content/plugins/nextgen-gallery-custom-fields/css/ngg-custom-fields.css/wp-content/plugins/nextgen-gallery-custom-fields/js/ngg-custom-fields.js/wp-content/plugins/nextgen-gallery-custom-fields/js/ngg-custom-fields.jsnextgen-gallery-custom-fields/css/ngg-custom-fields.css?ver=nextgen-gallery-custom-fields/js/ngg-custom-fields.js?ver=HTML / DOM Fingerprints
nggcf_containernggcf_field_inputnggcf_field_textareanggcf_field_selectnggcf_field_datestop direct callinstall funcsapi stuffsave custom field values (checks if it needs to insert or update)+1 morenggcf_fieldsnggcf_galleryNGGCF_IMAGESNGGCF_GALLERYNGGCF_FIELD_TYPE_INPUTNGGCF_FIELD_TYPE_TEXTAREANGGCF_FIELD_TYPE_SELECTNGGCF_FIELD_TYPE_DATE+5 more