ReFlex Gallery » WordPress Photo Gallery Security & Risk Analysis

wordpress.org/plugins/reflex-gallery

ReFlex Gallery is an easy to use responsive WordPress Photo Gallery Plugin that is two gallery plugins in one.

100 active installs v3.1.7 PHP + WP 3.0+ Updated Mar 10, 2021
imageimagesmediaphotophoto-albums
81
B · Generally Safe
CVEs total3
Unpatched0
Last CVEAug 6, 2021
Safety Verdict

Is ReFlex Gallery » WordPress Photo Gallery Safe to Use in 2026?

Mostly Safe

Score 81/100

ReFlex Gallery » WordPress Photo Gallery is generally safe to use though it hasn't been updated recently. 3 past CVEs were resolved.

3 known CVEsLast CVE: Aug 6, 2021Updated 5yr ago
Risk Assessment

The Reflex Gallery plugin version 3.1.7 presents a mixed security posture. While the static analysis shows a relatively small attack surface with no unprotected entry points and a reasonable number of nonce checks, several significant concerns arise from the code signals and vulnerability history. The presence of raw SQL queries without prepared statements is a notable risk, potentially leading to SQL injection vulnerabilities if not handled with extreme care. Furthermore, the plugin has a history of critical vulnerabilities, specifically Cross-Site Scripting (XSS) and unrestricted file uploads, indicating a pattern of weaknesses in input sanitization and validation. Although there are currently no unpatched CVEs, the recurrence of severe vulnerability types suggests a need for ongoing vigilance and robust security practices from the developers.

Key Concerns

  • SQL queries not using prepared statements
  • Significant history of critical vulnerabilities (XSS, Unrestricted Upload)
  • 53% of output escaping is concerningly low
Vulnerabilities
3 published

ReFlex Gallery » WordPress Photo Gallery Security Vulnerabilities

CVEs by Year

1 CVE in 2013
2013
1 CVE in 2015
2015
1 CVE in 2021
2021
Patched Has unpatched

Severity Breakdown

Critical
2
Medium
1

3 total CVEs

CVE-2013-7482medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ReFlex Gallery < 1.4.3 - Cross-Site Scripting

Aug 6, 2021 Patched in 1.4.3 (900d)
CVE-2015-4133critical · 9.8Unrestricted Upload of File with Dangerous Type

ReFlex Gallery » WordPress Photo Gallery < 3.1.4 - Arbitrary File Upload

Mar 16, 2015 Patched in 3.1.4 (3235d)
WF-fe17abd8-9ee2-4b9c-a30b-68d95e341722-reflex-gallerycritical · 9.8Unrestricted Upload of File with Dangerous Type

ReFlex Gallery » WordPress Photo Gallery < 3.1.4 - Arbitrary File Upload

Jan 3, 2013 Patched in 3.1.4 (4037d)
Version History

ReFlex Gallery » WordPress Photo Gallery Release Timeline

v3.1.5
v3.1.4
Code Analysis
Analyzed Mar 16, 2026

ReFlex Gallery » WordPress Photo Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
14
16 escaped
Nonce Checks
9
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

53% escaped30 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
<add-gallery> (admin\add-gallery.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ReFlex Gallery » WordPress Photo Gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ReflexGallery] reflex-gallery.php:34
WordPress Hooks 8
actioninitreflex-gallery.php:26
actionwp_enqueue_scriptsreflex-gallery.php:27
actionwp_headreflex-gallery.php:29
actionadmin_initreflex-gallery.php:31
actionadmin_menureflex-gallery.php:32
actioninitreflex-gallery.php:230
filtermce_external_pluginsreflex-gallery.php:232
filtermce_buttonsreflex-gallery.php:233
Maintenance & Trust

ReFlex Gallery » WordPress Photo Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 10, 2021
PHP min version
Downloads67K

Community Trust

Rating58/100
Number of ratings9
Active installs100
Developer Profile

ReFlex Gallery » WordPress Photo Gallery Developer Profile

hahncgdev

2 plugins · 110 total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
2724 days
View full developer profile
Detection Fingerprints

How We Detect ReFlex Gallery » WordPress Photo Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reflex-gallery/scripts/jquery-migrate.js/wp-content/plugins/reflex-gallery/scripts/flexslider/jquery.flexslider-min.js/wp-content/plugins/reflex-gallery/scripts/prettyphoto/jquery.prettyPhoto.js/wp-content/plugins/reflex-gallery/scripts/galleryManagerNoOverlay.js/wp-content/plugins/reflex-gallery/scripts/galleryManagerNoSocial.js/wp-content/plugins/reflex-gallery/scripts/galleryManagerNoOverlayNoSocial.js/wp-content/plugins/reflex-gallery/scripts/galleryManager.js/wp-content/plugins/reflex-gallery/scripts/flexslider/flexslider.css+4 more
Script Paths
reflex-gallery/scripts/jquery-migrate.jsreflex-gallery/scripts/flexslider/jquery.flexslider-min.jsreflex-gallery/scripts/prettyphoto/jquery.prettyPhoto.jsreflex-gallery/scripts/galleryManagerNoOverlay.jsreflex-gallery/scripts/galleryManagerNoSocial.jsreflex-gallery/scripts/galleryManagerNoOverlayNoSocial.js+2 more
Version Parameters
reflex-gallery/scripts/jquery-migrate.js?ver=reflex-gallery/scripts/flexslider/jquery.flexslider-min.js?ver=reflex-gallery/scripts/prettyphoto/jquery.prettyPhoto.js?ver=reflex-gallery/scripts/galleryManagerNoOverlay.js?ver=reflex-gallery/scripts/galleryManagerNoSocial.js?ver=reflex-gallery/scripts/galleryManagerNoOverlayNoSocial.js?ver=reflex-gallery/scripts/galleryManager.js?ver=reflex-gallery/styles/default.css?ver=reflex-gallery/admin/scripts/TablePagination/tablePager.css?ver=reflex-gallery/scripts/prettyphoto/prettyPhoto.css?ver=reflex-gallery/admin/scripts/MediaUpload/image-uploader.js?ver=

HTML / DOM Fingerprints

CSS Classes
reflex-gallery
Data Attributes
data-reflex-gallery-id
JS Globals
ReflexDBgalleryManager
Shortcode Output
[ReflexGallery
FAQ

Frequently Asked Questions about ReFlex Gallery » WordPress Photo Gallery