
Geo2 Maps Add-on for NextGEN Gallery Security & Risk Analysis
wordpress.org/plugins/nextgen-gallery-geoNGG Geo2 Maps Add-on displays maps with photos, galleries, or albums using EXIF GPS data or geocoding. Requires NextGEN Gallery.
Is Geo2 Maps Add-on for NextGEN Gallery Safe to Use in 2026?
Generally Safe
Score 100/100Geo2 Maps Add-on for NextGEN Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of nextgen-gallery-geo v2.1.6 shows a mixed bag of good practices alongside some notable concerns. On the positive side, the plugin demonstrates strong adherence to secure coding practices with a high percentage of SQL queries using prepared statements and a majority of output being properly escaped. The absence of dangerous functions and known vulnerabilities in its history is also encouraging, suggesting a generally well-maintained codebase. However, the presence of three unprotected entry points, specifically two AJAX handlers and one REST API route without proper authorization checks, presents a significant risk. Additionally, the taint analysis, while limited in scope, revealed flows with unsanitized paths, indicating potential for path traversal or file inclusion vulnerabilities if these paths are user-controlled. The large number of file operations also warrants attention as it can increase the attack surface. Overall, while the plugin benefits from secure defaults in many areas, the identified unprotected entry points and potential path sanitization issues require immediate attention to mitigate potential exploitation.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API route
- Flows with unsanitized paths
- High number of file operations
Geo2 Maps Add-on for NextGEN Gallery Security Vulnerabilities
Geo2 Maps Add-on for NextGEN Gallery Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Geo2 Maps Add-on for NextGEN Gallery Attack Surface
AJAX Handlers 6
REST API Routes 1
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
Geo2 Maps Add-on for NextGEN Gallery Maintenance & Trust
Maintenance Signals
Community Trust
Geo2 Maps Add-on for NextGEN Gallery Alternatives
Google Maps Photo Gallery
google-maps-photo-gallery
The shortcode for gallery on Google Maps with geotagged photos.
Leaflet Maps Marker Image Extension
image-marker
Extension to Leaflet Maps Marker to make markers from images.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
WPZOOM Social Feed Widget & Block
instagram-widget-by-wpzoom
Instagram feed plugin for WordPress: Display your Instagram photos, videos & reels. Easy setup with Gutenberg block, widget, shortcode & Elementor
Easy Social Feed – Social Photos Gallery and Post Feed for WordPress
easy-facebook-likebox
Display Instagram, Facebook & YouTube feeds with photos, videos, reels, events & galleries. Fast, responsive & easy to set up.
Geo2 Maps Add-on for NextGEN Gallery Developer Profile
2 plugins · 90 total installs
How We Detect Geo2 Maps Add-on for NextGEN Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nextgen-gallery-geo/css/geo2.css/wp-content/plugins/nextgen-gallery-geo/css/map.css/wp-content/plugins/nextgen-gallery-geo/css/lightbox.css/wp-content/plugins/nextgen-gallery-geo/js/jquery.fancybox.min.js/wp-content/plugins/nextgen-gallery-geo/js/jquery.slimbox2.min.js/wp-content/plugins/nextgen-gallery-geo/js/geo2.js/wp-content/plugins/nextgen-gallery-geo/js/map.js/wp-content/plugins/nextgen-gallery-geo/js/jquery.fancybox.min.js/wp-content/plugins/nextgen-gallery-geo/js/jquery.slimbox2.min.js/wp-content/plugins/nextgen-gallery-geo/js/geo2.js/wp-content/plugins/nextgen-gallery-geo/js/map.jsnextgen-gallery-geo/css/geo2.css?ver=nextgen-gallery-geo/css/map.css?ver=nextgen-gallery-geo/css/lightbox.css?ver=nextgen-gallery-geo/js/jquery.fancybox.min.js?ver=nextgen-gallery-geo/js/jquery.slimbox2.min.js?ver=nextgen-gallery-geo/js/geo2.js?ver=nextgen-gallery-geo/js/map.js?ver=HTML / DOM Fingerprints
geo2-map-containergeo2-map-canvas<!-- Geo2 Maps Add-on for NextGEN Gallery --><!-- HERE BEGINS THE DIV TO BE SEARCHED BY THE GEOTAG FUNCTION. -->data-geo2-mapdata-geo2-map-providerdata-geo2-map-latdata-geo2-map-lngdata-geo2-map-zoomdata-geo2-map-height+2 moregeo2_maps_settingsgeo2_maps_data[geo2_map][geo2_map_gallery][geo2_map_album]