
Robo Gallery – Photo & Image Slider Security & Risk Analysis
wordpress.org/plugins/robo-galleryRobo Gallery is a powerful image gallery and photo gallery plugin with advanced features to create responsive galleries with a beautiful lightbox
Is Robo Gallery – Photo & Image Slider Safe to Use in 2026?
Mostly Safe
Score 83/100Robo Gallery – Photo & Image Slider is generally safe to use. 19 past CVEs were resolved.
The robo-gallery plugin version 5.1.2 - 54264 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query preparation (93%) and a significant number of capability checks (23), it also presents notable weaknesses. The presence of 5 unprotected entry points, specifically 4 AJAX handlers and 1 REST API route without permission callbacks, creates a significant attack surface. Furthermore, the use of dangerous functions like `unserialize` without apparent sanitization of its input is a critical concern that could lead to severe vulnerabilities. The plugin's vulnerability history is particularly alarming, with 17 known CVEs, including 1 critical, 2 high, and 14 medium severity vulnerabilities. Common themes in past vulnerabilities include missing authorization, CSRF, information exposure, XSS, and code injection, all of which are serious threats.
While the current static analysis does not report critical or high severity taint flows and there are no currently unpatched CVEs, the historical pattern of critical and high severity vulnerabilities, coupled with the static analysis findings of unprotected entry points and the potential for deserialization vulnerabilities, suggests a high inherent risk. The low percentage of properly escaped output (29%) also raises concerns about potential cross-site scripting vulnerabilities. The plugin's past indicates a recurring struggle with secure coding practices, and the current analysis reveals several critical areas that require immediate attention to mitigate potential exploitation.
Key Concerns
- 4 AJAX handlers without auth checks
- 1 REST API route without permission callbacks
- 2 dangerous functions (unserialize)
- 29% properly escaped output
- 1 critical CVE in history
- 2 high CVEs in history
- 14 medium CVEs in history
- Recurring vulnerability types (Auth, CSRF, XSS, Code Injection)
Robo Gallery – Photo & Image Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
19 total CVEs
Robo Gallery <= 5.1.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'Loading Label' Setting
Robo Gallery <= 5.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Robo Gallery <= 5.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.23 - Authenticated (Admin+) Stored Cross-Site Scripting
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting
Robo Gallery <= 3.2.21 - Authenticated (Author+) Stored Cross-Site Scripting
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Title
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Authenticated (Author+) Stored Cross-Site Scripting via Image Title
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Cross-Site Request Forgery to Post Creation and Limited Data Loss
Robo Gallery <= 3.2.18 - Unauthenticated Information Exposure
Robo Gallery <= 3.2.17 - Authenticated (Author+) Stored Cross-Site Scripting
Robo Gallery <= 3.2.15 - Authenticated(Administrator+) Stored Cross-Site Scripting
Robo Gallery <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes
Robo Gallery <= 3.2.9 - Cross-Site Request Forgery via getPluginStatus
Robo Gallery Plugin <= 3.2.11 - Cross-Site Request Forgery
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.9 - Missing Authorization
Photo Gallery, Images, Slider in Rbs Image Gallery <= 2.0.14 - Remote Code Execution
Robo Gallery – Photo & Image Slider Release Timeline
Robo Gallery – Photo & Image Slider Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Robo Gallery – Photo & Image Slider Attack Surface
AJAX Handlers 4
REST API Routes 2
Shortcodes 1
WordPress Hooks 113
Maintenance & Trust
Robo Gallery – Photo & Image Slider Maintenance & Trust
Maintenance Signals
Community Trust
Robo Gallery – Photo & Image Slider Alternatives
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
photo-gallery
Photo Gallery is a powerful image gallery plugin with a list of advanced options for creating responsive image galleries with beautiful lightbox.
Photo Gallery by Ays – Responsive Image Gallery
gallery-photo-gallery
Photo Gallery is a cool responsive image gallery plugin with beautiful views
Photo gallery lightbox – 📱 mobile friendly gallery plugin –– Story Show Gallery
story-show-gallery
Full screen photo gallery lightbox for delightful display of your photos, with a lot of features, fully customizable, free.
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More
envira-gallery-lite
Envira Gallery is a fast, easy and powerful gallery builder with lightbox, masonry and grid layouts, albums, videos, and responsive displays and more
Robo Gallery – Photo & Image Slider Developer Profile
1 plugin · 40K total installs
How We Detect Robo Gallery – Photo & Image Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/robo-gallery/css/admin/list.css/wp-content/plugins/robo-gallery/js/admin/listing.js/wp-content/plugins/robo-gallery/js/admin/info.js/wp-content/plugins/robo-gallery/css/admin/info.css/wp-content/plugins/robo-gallery/js/admin/listing.js/wp-content/plugins/robo-gallery/js/admin/info.jsrobo-gallery/css/admin/list.css?ver=robo-gallery/js/admin/listing.js?ver=robo-gallery/js/admin/info.js?ver=robo-gallery/css/admin/info.css?ver=HTML / DOM Fingerprints
robo-gallery-shortcodedata-opendata-titledata-closedata-info[robo-gallery id=