Responsive Lightbox2 Security & Risk Analysis

wordpress.org/plugins/responsive-lightbox2

Add responsive lightbox effect to your images, pop up photos and photo gallery in lightbox

300 active installs v1.0.4 PHP + WP 3.0+ Updated Nov 14, 2022
galleryimageslightboxphotosresponsive
84
B · Generally Safe
CVEs total2
Unpatched0
Last CVENov 22, 2022
Safety Verdict

Is Responsive Lightbox2 Safe to Use in 2026?

Mostly Safe

Score 84/100

Responsive Lightbox2 is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.

2 known CVEsLast CVE: Nov 22, 2022Updated 3yr ago
Risk Assessment

The plugin "responsive-lightbox2" v1.0.4 exhibits a mixed security posture. Static analysis reveals good practices such as 100% of SQL queries using prepared statements and no dangerous functions or file operations being detected. However, there are concerning signals. The lack of nonce checks and capability checks across all entry points, including its single shortcode, is a significant weakness. This indicates a potential for privilege escalation or unauthorized actions if an attacker can trigger these entry points. The output escaping is also not perfect, with 22% of outputs not properly escaped, which could lead to cross-site scripting vulnerabilities.

The vulnerability history for this plugin is a key concern. It has a total of two known medium severity CVEs, both related to Cross-site Scripting (XSS). While there are currently no unpatched vulnerabilities, the pattern of past XSS issues, especially when combined with insufficient input sanitization and output escaping, suggests a recurring area of weakness. The lack of taint analysis results also makes it difficult to fully assess the risk of unsanitized data flowing to sensitive sinks.

In conclusion, while the plugin demonstrates some positive security attributes like prepared SQL statements, the absence of robust authentication and authorization checks on its entry points, coupled with a history of XSS vulnerabilities and imperfect output escaping, presents a notable risk. The potential for attackers to exploit the shortcode without proper validation is a primary concern, and the past XSS issues highlight the need for vigilant code review and testing of input handling.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Improper output escaping (22%)
  • History of medium severity CVEs (XSS)
Vulnerabilities
2

Responsive Lightbox2 Security Vulnerabilities

CVEs by Year

1 CVE in 2020
2020
1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2022-3987medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Lightbox2 <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 22, 2022 Patched in 1.0.4 (427d)
WF-d45a4b0b-bb98-4c35-a743-c434946002a2-responsive-lightbox2medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Lightbox2 <= 1.0.2 - Cross-Site Scripting

Aug 14, 2020 Patched in 1.0.3 (1257d)
Code Analysis
Analyzed Mar 16, 2026

Responsive Lightbox2 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped9 total outputs
Attack Surface

Responsive Lightbox2 Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[lightbox2] main.php:40
WordPress Hooks 7
actionwp_enqueue_scriptsmain.php:31
filterplugin_action_linksmain.php:36
actionplugins_loadedmain.php:38
actionadmin_menumain.php:39
filterwidget_textmain.php:42
filterthe_excerptmain.php:43
filterthe_contentmain.php:44
Maintenance & Trust

Responsive Lightbox2 Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 14, 2022
PHP min version
Downloads10K

Community Trust

Rating74/100
Number of ratings3
Active installs300
Developer Profile

Responsive Lightbox2 Developer Profile

Noor Alam

25 plugins · 157K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
450 days
View full developer profile
Detection Fingerprints

How We Detect Responsive Lightbox2

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-lightbox2/js/lightbox.js/wp-content/plugins/responsive-lightbox2/css/lightbox.css
Script Paths
/wp-content/plugins/responsive-lightbox2/js/lightbox.js
Version Parameters
responsive-lightbox2/js/lightbox.js?ver=responsive-lightbox2/css/lightbox.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-lightbox
Shortcode Output
<a hrefdata-lightbox=
FAQ

Frequently Asked Questions about Responsive Lightbox2