Skyboot Portfolio Gallery for Elementor Security & Risk Analysis

wordpress.org/plugins/skyboot-portfolio-gallery

Create a clean portfolio photo gallery on your Elementor website to showcase your work with masonry layouts and filterable image galleries.

1K active installs v1.0.6 PHP 7.4+ WP 5.0+ Updated Oct 2, 2025
elementor-widgetgalleryimage-galleryphoto-gallerywordpress-gallery-plugin
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 28, 2024
Safety Verdict

Is Skyboot Portfolio Gallery for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

Skyboot Portfolio Gallery for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 28, 2024Updated 6mo ago
Risk Assessment

The static analysis of skyboot-portfolio-gallery v1.0.6 reveals a generally strong security posture. The plugin demonstrates good practices by having no identified attack surface points such as AJAX handlers, REST API routes, or shortcodes that lack authentication checks. The code signals also indicate a clean slate regarding dangerous functions, file operations, and external HTTP requests. Furthermore, all SQL queries are properly prepared, and output escaping is almost perfectly implemented, with a very low percentage of outputs potentially unescaped. The capability checks present, while minimal, are a positive sign of security awareness.

However, the vulnerability history presents a significant concern. The presence of one known CVE, even if currently unpatched and of medium severity, indicates that vulnerabilities have been discovered in this plugin. The fact that the last vulnerability was very recent (2024-11-28) and was related to Cross-site Scripting is a red flag. While the current version might not be affected by this specific past vulnerability, it suggests a historical pattern of security weaknesses that warrant vigilance. The lack of explicit nonce checks, while not necessarily a critical flaw given the limited attack surface, could be a minor area for improvement if future versions introduce more interactive elements.

In conclusion, skyboot-portfolio-gallery v1.0.6 exhibits strong defensive coding practices in its current static analysis, with a minimal attack surface and robust SQL and output handling. Nevertheless, the historical vulnerability data, particularly the recent XSS finding, necessitates caution. Users should ensure they are always running the latest version of the plugin as it becomes available to benefit from any patches addressing past issues. Continued monitoring for new vulnerabilities is recommended.

Key Concerns

  • Medium severity vulnerability history
  • Recent vulnerability (2024-11-28)
  • Missing nonce checks
  • Low percentage of unescaped output
Vulnerabilities
1

Skyboot Portfolio Gallery for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-53744medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Elementor Image Gallery Plugin <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 28, 2024 Patched in 1.0.6 (309d)
Code Analysis
Analyzed Mar 16, 2026

Skyboot Portfolio Gallery for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
36 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped37 total outputs
Attack Surface

Skyboot Portfolio Gallery for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwp_enqueue_scriptsinc\assets-enqueue.php:23
actioninitinc\custom-post-register.php:15
actioninitinc\custom-taxonomies.php:48
actionelementor/widgets/registerinc\file-list.php:32
actionadmin_noticesinc\plugin-status.php:16
actionplugins_loadedinc\plugin-status.php:20
Maintenance & Trust

Skyboot Portfolio Gallery for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 2, 2025
PHP min version7.4
Downloads16K

Community Trust

Rating60/100
Number of ratings2
Active installs1K
Developer Profile

Skyboot Portfolio Gallery for Elementor Developer Profile

skybootstrap

3 plugins · 201K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
309 days
View full developer profile
Detection Fingerprints

How We Detect Skyboot Portfolio Gallery for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/skyboot-portfolio-gallery/assets/css/skb-framework.css/wp-content/plugins/skyboot-portfolio-gallery/assets/css/venobox.css/wp-content/plugins/skyboot-portfolio-gallery/assets/css/skyboot-portfolio-style.css/wp-content/plugins/skyboot-portfolio-gallery/assets/css/responsive.css/wp-content/plugins/skyboot-portfolio-gallery/assets/js/modernizr-2.8.3.min.js/wp-content/plugins/skyboot-portfolio-gallery/assets/js/isotope.pkgd.min.js/wp-content/plugins/skyboot-portfolio-gallery/assets/js/jquery.hoverdir.js/wp-content/plugins/skyboot-portfolio-gallery/assets/js/venobox.js
Script Paths
/wp-content/plugins/skyboot-portfolio-gallery/assets/js/modernizr-2.8.3.min.js/wp-content/plugins/skyboot-portfolio-gallery/assets/js/isotope.pkgd.min.js/wp-content/plugins/skyboot-portfolio-gallery/assets/js/jquery.hoverdir.js/wp-content/plugins/skyboot-portfolio-gallery/assets/js/venobox.js
Version Parameters
skyboot-portfolio-gallery/assets/css/venobox.css?ver=skyboot-portfolio-gallery/assets/css/skyboot-portfolio-style.css?ver=skyboot-portfolio-gallery/assets/css/responsive.css?ver=skyboot-portfolio-gallery/assets/js/isotope.pkgd.min.js?ver=skyboot-portfolio-gallery/assets/js/jquery.hoverdir.js?ver=skyboot-portfolio-gallery/assets/js/venobox.js?ver=

HTML / DOM Fingerprints

CSS Classes
skb-portfolio-gallery
Data Attributes
data-portfolio-id
FAQ

Frequently Asked Questions about Skyboot Portfolio Gallery for Elementor