
Shutter Reloaded Plus Security & Risk Analysis
wordpress.org/plugins/shutter-reloaded-plusDarkens the current page and displays an image (like Lightbox, Thickbox, etc.), but is a lot smaller (8KB) and faster.
Is Shutter Reloaded Plus Safe to Use in 2026?
Generally Safe
Score 85/100Shutter Reloaded Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the shutter-reloaded-plus plugin v0.6 exhibits a seemingly strong security posture regarding potential entry points and direct code vulnerabilities. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed to unauthenticated users. The absence of dangerous functions, raw SQL queries (all use prepared statements), file operations, and external HTTP requests further contributes to a positive initial assessment. The presence of nonce checks and capability checks also indicates an awareness of basic WordPress security practices.
However, a significant concern arises from the output escaping. With 37 total outputs and 0% properly escaped, this plugin presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed by the plugin without proper sanitization and escaping can be exploited by attackers to inject malicious scripts, leading to session hijacking, data theft, or defacement. The fact that the vulnerability history is clean is encouraging but does not mitigate the immediate risk posed by the unescaped output.
In conclusion, while the plugin appears to have a secure attack surface and avoids common pitfalls like raw SQL and dangerous functions, the complete lack of output escaping is a critical weakness. This single oversight can be a gateway for severe XSS attacks. The clean vulnerability history is a positive sign, suggesting the developers may be responsive to security issues if reported, but the current state demands immediate attention to the output sanitization.
Key Concerns
- 0% output escaping
Shutter Reloaded Plus Security Vulnerabilities
Shutter Reloaded Plus Code Analysis
Output Escaping
Data Flow Analysis
Shutter Reloaded Plus Attack Surface
WordPress Hooks 5
Maintenance & Trust
Shutter Reloaded Plus Maintenance & Trust
Maintenance Signals
Community Trust
Shutter Reloaded Plus Alternatives
Shutter Reloaded
shutter-reloaded
Darkens the current page and displays an image (like Lightbox, Thickbox, etc.), but is a lot smaller (10KB) and faster.
FancyBox
fancy-box
Enables fancybox on all image links including BMP, GIF, JPG, JPEG, and PNG links.
Slimbox
slimbox
Enables slimbox 2.03 on all image links including BMP, GIF, JPG, JPEG, and PNG links.
Slimbox Plugin
slimbox-plugin
Plugin used to overlay images on the current page into neat Javascript-powered overlay popups.
Add LightBox & Title
add-lightbox-title
This plugin for WordPress automatically add the rel="lightbox[ID-OF-THE-POST]" and recovers the image title.
Shutter Reloaded Plus Developer Profile
1 plugin · 200 total installs
How We Detect Shutter Reloaded Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shutter-reloaded-plus/shutter-reloaded.css/wp-content/plugins/shutter-reloaded-plus/shutter-reloaded.js//connect.facebook.net/en_US/all.js#xfbml=1&appId=490336411021291HTML / DOM Fingerprints
shutterset_shuttersetshutterSettingsshutterSettingsshutterAddLoadshutterReloaded