
post gallery Security & Risk Analysis
wordpress.org/plugins/post-gallery-and-archivethis plugin create a gallery/archive of posts. you can decide how many words will be Shawn under each post and more. used very easily using the shortc …
Is post gallery Safe to Use in 2026?
Generally Safe
Score 85/100post gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "post-gallery-and-archive" version 0.4 exhibits a mixed security posture. On the positive side, the static analysis shows no dangerous functions, file operations, external HTTP requests, or raw SQL queries. All SQL queries are using prepared statements, which is a strong security practice. The plugin also boasts a small attack surface with only one shortcode and no AJAX handlers or REST API routes, further minimizing potential entry points for attackers. However, there are significant concerns regarding output escaping. With 100% of outputs not being properly escaped, this presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks, even for the single shortcode, is also a significant weakness, potentially allowing unauthorized actions or information disclosure depending on the shortcode's functionality. The vulnerability history is clean, with no recorded CVEs. This is a positive indicator, but it cannot fully offset the identified security flaws in the current version. In conclusion, while the plugin avoids common pitfalls like raw SQL and external requests, the lack of output escaping and insufficient authorization checks are critical vulnerabilities that need immediate attention. The clean history suggests a lack of past exploitation, but the current code leaves it exposed.
Key Concerns
- Outputs are not properly escaped
- Missing nonce checks
- Missing capability checks
post gallery Security Vulnerabilities
post gallery Release Timeline
post gallery Code Analysis
Output Escaping
post gallery Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
post gallery Maintenance & Trust
Maintenance Signals
Community Trust
post gallery Alternatives
EasyIndex
easyindex
Wordpress indexes made easy! EasyIndex makes post indexes, recipe indexes, product indexes and more in just minutes. Easy to use, easy to customize.
Blog Layout Design by Themes Awesome
blog-layout-design
Create stunning blog layout without headache with Blog Layout Design.
Post gallery slider
post-gallery-slider
Post gallery slider, with thumbnails and with nice animation, and auto height.
SV Posts
sv-posts
SV Posts is an advanced block to show Posts with custom order, filters and styles.
LazyLoad Post Gallery
lazyload-post-gallery
This plugin adds a lightbox to the native galleries of WordPress articles.
post gallery Developer Profile
5 plugins · 120 total installs
How We Detect post gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-gallery-and-archive/default-img.pngHTML / DOM Fingerprints
zeevul<ul class="zeevul"><style>
ul.zeevul {width:100%;}