
NextGEN Gallery Image Chooser Security & Risk Analysis
wordpress.org/plugins/nextgen-gallery-image-chooserComfortable Image Chooser for the NextGEN Gallery, based on g2image
Is NextGEN Gallery Image Chooser Safe to Use in 2026?
Generally Safe
Score 100/100NextGEN Gallery Image Chooser has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of nextgen-gallery-image-chooser v1.1.2 reveals a plugin with a generally good security posture in terms of attack vectors and SQL injection prevention. There are no reported CVEs, and the plugin uses prepared statements for all SQL queries. This indicates a proactive approach to common web vulnerabilities. Furthermore, the absence of shortcodes, cron events, and a limited attack surface with zero unprotected entry points are positive signs.
However, significant concerns arise from the code signals. The presence of a dangerous `create_function` usage is a critical red flag, as it can be a vector for remote code execution if not handled with extreme care and input validation. Additionally, the fact that 100% of outputs are unescaped is a major vulnerability, creating a high risk of Cross-Site Scripting (XSS) attacks. File operations without clear sanitization for paths also warrant attention.
While the plugin's history of zero known vulnerabilities is encouraging, it doesn't negate the immediate risks identified in the static analysis. The absence of vulnerabilities might be due to luck or the plugin's limited exposure. The plugin's strengths lie in its minimal attack surface and SQL safety, but its weaknesses in output sanitization and the use of a dangerous function pose substantial security risks that need immediate attention.
Key Concerns
- Unescaped output detected (13 total outputs, 0% escaped)
- Dangerous function 'create_function' used
- File operations present without taint analysis
NextGEN Gallery Image Chooser Security Vulnerabilities
NextGEN Gallery Image Chooser Code Analysis
Dangerous Functions Found
Output Escaping
NextGEN Gallery Image Chooser Attack Surface
WordPress Hooks 5
Maintenance & Trust
NextGEN Gallery Image Chooser Maintenance & Trust
Maintenance Signals
Community Trust
NextGEN Gallery Image Chooser Alternatives
NextGEN Download Gallery
nextgen-download-gallery
Add a template to NextGEN Gallery that provides multiple-file downloads for trade/media galleries
NextGEN Gallery Optimizer
nextgen-gallery-optimizer
The essential add-on for the NextGEN Gallery WordPress plugin.
NextGEN Custom Fields
nextgen-gallery-custom-fields
Creates the ability to quickly and easily add custom fields to NextGEN Galleries and Images.
NextGEN Scroll Gallery
nextgen-scrollgallery
Awesome free JavaScript gallery. BMo-Design's Mootools Javascript ScrollGallery as a Plugin for the Wordpress NextGEN Gallery.
Advanced Custom Fields: NextGEN Gallery Field add-on
advanced-custom-fields-nextgen-gallery-field-add-on
Adds a NextGEN Gallery Field to Advanced Custom Fields. Select one or more NextGEN Galleries and assign them to the post.
NextGEN Gallery Image Chooser Developer Profile
1 plugin · 200 total installs
How We Detect NextGEN Gallery Image Chooser
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nextgen-gallery-image-chooser/css/nggic.css/wp-content/plugins/nextgen-gallery-image-chooser/js/nggic.js/wp-content/plugins/nextgen-gallery-image-chooser/js/jquery.cookie.js/wp-content/plugins/nextgen-gallery-image-chooser/js/nggic.js/wp-content/plugins/nextgen-gallery-image-chooser/js/jquery.cookie.jsver=1.1.2HTML / DOM Fingerprints
nggic_img_titlenggic_controls<!-- Initializing NextGEN Gallery Image Chooser -->data-nggic-target-idnggic_tinymce_id