PhotoPress – Masonry Gallery Security & Risk Analysis

wordpress.org/plugins/photopress-masonry-gallery

Extends the [gallery] shortcode to add a masonry style display option.

50 active installs v1.2.8 PHP + WP 3.9+ Updated Mar 23, 2018
galleryimagesmasonryphotopressphotos
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PhotoPress – Masonry Gallery Safe to Use in 2026?

Generally Safe

Score 85/100

PhotoPress – Masonry Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin "photopress-masonry-gallery" v1.2.8 exhibits a strong security posture based on the static analysis provided. The complete absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate good practices, with no dangerous functions, 100% of SQL queries using prepared statements, and a high percentage of output being properly escaped. The lack of file operations, external HTTP requests, nonce checks, and capability checks in the analyzed code also contributes positively to its security. Taint analysis revealing zero flows with unsanitized paths further reinforces this assessment. The plugin also has no recorded vulnerability history, indicating a consistent track record of security. Overall, this plugin appears to be developed with security in mind, presenting minimal immediate risks. However, the analysis of "0 total entry points" and "0 flows analyzed" might suggest a very limited or perhaps non-existent scope for the static analysis performed. If the plugin actually has functionalities that were not captured by the analysis, there could be undiscovered risks. The absence of capability checks is a concern if the plugin's functionalities are intended to be restricted to certain user roles, as this could lead to unauthorized access if entry points were present but not properly secured.

Key Concerns

  • No capability checks found
Vulnerabilities
None known

PhotoPress – Masonry Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PhotoPress – Masonry Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped5 total outputs
Attack Surface

PhotoPress – Masonry Gallery Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_noticesphotopress-masonry-gallery.php:36
filtershortcode_atts_galleryphotopress-masonry-gallery.php:97
actionwp_enqueue_scriptsphotopress-masonry-gallery.php:99
filteruse_default_gallery_stylephotopress-masonry-gallery.php:133
filteruse_default_gallery_stylephotopress-masonry-gallery.php:149
filterpost_gallery_post_outputphotopress-masonry-gallery.php:150
actioninitphotopress-masonry-gallery.php:198
actionplugins_loadedphotopress-masonry-gallery.php:199
Maintenance & Trust

PhotoPress – Masonry Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 23, 2018
PHP min version
Downloads11K

Community Trust

Rating56/100
Number of ratings10
Active installs50
Developer Profile

PhotoPress – Masonry Gallery Developer Profile

padams

7 plugins · 350 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PhotoPress – Masonry Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/photopress-masonry-gallery/css/photopress-masonry-gallery.css/wp-content/plugins/photopress-masonry-gallery/js/imagesloaded.pkgd.min.js/wp-content/plugins/photopress-masonry-gallery/js/photopress-masonry-gallery.js
Script Paths
/wp-content/plugins/photopress-masonry-gallery/js/imagesloaded.pkgd.min.js/wp-content/plugins/photopress-masonry-gallery/js/photopress-masonry-gallery.js
Version Parameters
photopress-masonry-gallery/css/photopress-masonry-gallery.css?ver=photopress-masonry-gallery/js/imagesloaded.pkgd.min.js?ver=photopress-masonry-gallery/js/photopress-masonry-gallery.js?ver=

HTML / DOM Fingerprints

CSS Classes
photopress-gallery-masonry
HTML Comments
<!-- End PhotoPress Masonry Gallery -->
JS Globals
photopress.galleries
Shortcode Output
<script>jQuery( '#jQuery( '#photopress.galleries['
FAQ

Frequently Asked Questions about PhotoPress – Masonry Gallery