
NextGEN Gallery Date Security & Risk Analysis
wordpress.org/plugins/nextgen-gallery-dateThis plugin will let you sort the galleries by date and get info about gallery creation (and modification) date.
Is NextGEN Gallery Date Safe to Use in 2026?
Generally Safe
Score 85/100NextGEN Gallery Date has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "nextgen-gallery-date" v0.1.5 exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the presence of nonce and capability checks indicates an awareness of basic WordPress security practices. The plugin also avoids dangerous functions, file operations, and external HTTP requests, which are common vectors for vulnerabilities.
However, there are areas for improvement. The SQL query analysis reveals that a significant percentage (44%) are not using prepared statements, which could lead to SQL injection vulnerabilities if the data used in these queries is not properly sanitized. The output escaping is also a concern, with only 20% of outputs being properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities. The single taint flow with an unsanitized path, while not critical or high severity, warrants further investigation to ensure it doesn't pose a hidden risk.
The plugin's vulnerability history is exceptionally clean, with no known CVEs. This, coupled with the limited attack surface and the presence of some security checks, suggests that the plugin has likely been developed with security in mind, or has benefited from a lack of targeted attacks due to its obscurity or minimal functionality. Despite the positive history and limited attack surface, the identified issues with SQL queries and output escaping represent real, albeit potentially low-severity, risks that should be addressed.
Key Concerns
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- Taint flow with unsanitized path (low risk)
NextGEN Gallery Date Security Vulnerabilities
NextGEN Gallery Date Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
NextGEN Gallery Date Attack Surface
WordPress Hooks 12
Maintenance & Trust
NextGEN Gallery Date Maintenance & Trust
Maintenance Signals
Community Trust
NextGEN Gallery Date Alternatives
GPP Slideshow
gpp-slideshow
A minimalist slideshow plugin that creates a new gallery post type. Add slideshows to widgets, posts, pages and gallery posts.
WPJaipho Mobile Gallery
wpjaipho
WPJaipho extends native Wordpress image gallery, NextGEN 1.x and NextCellent Gallery with optimized support for mobile users
flshow Manager
flshow-manager
This plugin adds a management interface for the flShow photo carousel as well as template tags to insert the carousel into your WordPress template.
SSP Director Tools
ssp-director-tools
SSP Director Tools give you means for integrating SlideShowPro Director content into a WordPress blog.
Lightbox with PhotoSwipe
lightbox-photoswipe
Integration of PhotoSwipe (http://photoswipe.com) for WordPress.
NextGEN Gallery Date Developer Profile
3 plugins · 100 total installs
How We Detect NextGEN Gallery Date
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nextgen-gallery-date/date/admin/admin.php/wp-content/plugins/nextgen-gallery-date/date/date.php/wp-content/plugins/nextgen-gallery-date/classes/humanrelativedate/humanRelativeDate.class.php/wp-content/plugins/nextgen-gallery-date/functions/functions.php