Nic Image Gallery Security & Risk Analysis

wordpress.org/plugins/nic-image-gallery

Advance great image gallery wordpress plugin for image rollover and slider effect.

20 active installs v1.0 PHP + WP 3.2+ Updated Jun 20, 2014
image-gallery-pluginimage-rollover-effectindianic-easy-image-gallery-with-small-group-imagesindianic-galleryindianic-image-slide-show
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nic Image Gallery Safe to Use in 2026?

Generally Safe

Score 85/100

Nic Image Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The nic-image-gallery plugin version 1.0 presents a generally positive security posture, adhering to several good practices. The complete absence of known CVEs and unpatched vulnerabilities, along with no recorded history of past issues, suggests a well-maintained and potentially secure codebase. The static analysis also indicates a limited attack surface, with only one shortcode identified as an entry point and no unprotected handlers or routes. Furthermore, all SQL queries are prepared, and file operations are absent, mitigating common attack vectors. However, a significant concern arises from the output escaping. With 39% of outputs properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce checks across its entry points is another area of weakness, as it allows for potential Cross-Site Request Forgery (CSRF) attacks, especially if the shortcode performs any sensitive actions. While the capability check is present for the shortcode, the absence of nonce checks is a notable oversight.

Key Concerns

  • Low percentage of properly escaped outputs
  • Missing nonce checks on entry points
Vulnerabilities
None known

Nic Image Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Nic Image Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
18 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

39% escaped46 total outputs
Attack Surface

Nic Image Gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[nic-image-gallery-view-mode] nic-image-gallery.php:34
WordPress Hooks 6
actionadmin_menunic-image-gallery.php:29
actionadmin_initnic-image-gallery.php:30
actionadd_meta_boxesnic-image-gallery.php:31
actionsave_postnic-image-gallery.php:32
actionwp_enqueue_scriptsnic-image-gallery.php:33
actioninitnic-image-gallery.php:424
Maintenance & Trust

Nic Image Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJun 20, 2014
PHP min version
Downloads7K

Community Trust

Rating80/100
Number of ratings4
Active installs20
Alternatives

Nic Image Gallery Alternatives

No alternatives data available yet.

Developer Profile

Nic Image Gallery Developer Profile

jignesh_dekavadiya

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nic Image Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nic-image-gallery/images/nic_default.png/wp-content/plugins/nic-image-gallery/js/get-images.js/wp-content/plugins/nic-image-gallery/js/custom.js/wp-content/plugins/nic-image-gallery/css/custom-css.css
Script Paths
plugins/nic-image-gallery/js/get-images.jsplugins/nic-image-gallery/js/custom.js

HTML / DOM Fingerprints

CSS Classes
preview_imgheadingimage_view
HTML Comments
<!-- NIC Image gallery settings --><!-- Use shortcode --><!-- in post or page content area. --><!-- Set Default Image -->
Data Attributes
id="droppable"name="post_ID"
JS Globals
var pluginPathvar pluginUrl
Shortcode Output
[nic-image-gallery-view-mode]
FAQ

Frequently Asked Questions about Nic Image Gallery