
NGG Image Rotation Security & Risk Analysis
wordpress.org/plugins/nggimagerotationThis is a custom module to extend NextGEN Gallery with a custom view that places the thumbnails in the left column, places a large image in the right …
Is NGG Image Rotation Safe to Use in 2026?
Generally Safe
Score 85/100NGG Image Rotation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The `nggimagerotation` plugin, version 1.0, exhibits a mixed security posture. On the positive side, it has a zero attack surface exposed through standard WordPress entry points like AJAX, REST API, shortcodes, and cron jobs, and all SQL queries are properly prepared. There are also no known vulnerabilities or CVEs associated with this plugin, nor any recorded history of past issues. However, significant concerns arise from the code analysis. The presence of the `create_function` function is a critical red flag, as it is considered deprecated and can be a source of security vulnerabilities if not handled with extreme care. Furthermore, the complete lack of output escaping across all identified output points (13 in total) presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Without proper escaping, user-supplied data displayed on the frontend could be maliciously manipulated.
While the plugin's limited attack surface and good SQL practices are strengths, the identified use of `create_function` and the pervasive lack of output escaping are substantial weaknesses. The absence of vulnerability history is reassuring, but it does not negate the inherent risks posed by the observed code practices. Users should exercise caution due to the high likelihood of XSS vulnerabilities. This plugin is not recommended for production environments without significant code remediation focusing on output sanitization and potentially refactoring the use of `create_function`.
Key Concerns
- No output escaping detected
- Use of dangerous function: create_function
- No nonce checks
- No capability checks
NGG Image Rotation Security Vulnerabilities
NGG Image Rotation Release Timeline
NGG Image Rotation Code Analysis
Dangerous Functions Found
Output Escaping
NGG Image Rotation Attack Surface
WordPress Hooks 4
Maintenance & Trust
NGG Image Rotation Maintenance & Trust
Maintenance Signals
Community Trust
NGG Image Rotation Alternatives
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
photo-gallery
Photo Gallery is a powerful image gallery plugin with a list of advanced options for creating responsive image galleries with beautiful lightbox.
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More
envira-gallery-lite
Envira Gallery is a fast, easy and powerful gallery builder with lightbox, masonry and grid layouts, albums, videos, and responsive displays and more
Gallery by FooGallery
foogallery
Photo Gallery, Image Gallery by FooGallery — fast, responsive, SEO-optimized, and packed with beautiful layouts.
Robo Gallery – Photo & Image Slider
robo-gallery
Robo Gallery is a powerful image gallery and photo gallery plugin with advanced features to create responsive galleries with a beautiful lightbox
NGG Image Rotation Developer Profile
1 plugin · 20 total installs
How We Detect NGG Image Rotation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nggimagerotation/view.css/wp-content/plugins/nggimagerotation/view.js/wp-content/plugins/nggimagerotation/view.jsnggimagerotation/view.css?ver=nggimagerotation/view.js?ver=HTML / DOM Fingerprints
[nggallery id=x template="imagerotation"]