
SmoothGallery Security & Risk Analysis
wordpress.org/plugins/smoothgalleryEmbed JonDesign's SmoothGallery into your posts and pages.
Is SmoothGallery Safe to Use in 2026?
Generally Safe
Score 85/100SmoothGallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The smoothgallery plugin, version 1.15.8, presents a mixed security posture. While the attack surface appears limited with no identified unprotected entry points and a lack of known CVEs, significant concerns arise from the static analysis. The presence of dangerous functions like `create_function` and `unserialize` is a red flag, as these can be exploited for code execution if not handled with extreme care. Furthermore, the alarmingly low percentage of properly escaped outputs (2%) strongly suggests a high risk of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website.
Despite the absence of known vulnerabilities in its history, the code itself exhibits several concerning practices. The taint analysis shows flows with unsanitized paths, though no critical or high severity issues were flagged in this specific analysis. The lack of nonce checks and capability checks on potentially sensitive operations, coupled with the high number of file operations, further amplifies the risk. The plugin's reliance on direct SQL queries, with a substantial portion not using prepared statements, also opens it up to SQL injection risks. In conclusion, while the plugin has no recorded public vulnerabilities, the internal code quality and practices present significant potential weaknesses that require immediate attention.
Key Concerns
- Presence of dangerous functions (create_function, unserialize)
- Low percentage of properly escaped output
- Flows with unsanitized paths
- SQL queries not using prepared statements
- No nonce checks
- No capability checks
SmoothGallery Security Vulnerabilities
SmoothGallery Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
SmoothGallery Attack Surface
Shortcodes 2
WordPress Hooks 11
Maintenance & Trust
SmoothGallery Maintenance & Trust
Maintenance Signals
Community Trust
SmoothGallery Alternatives
Social Photo Fetcher
facebook-photo-fetcher
Allows you to automatically create Wordpress photo galleries from Facebook albums. Simple to use and highly customizable.
ThickBox
thickbox
Embed ThickBox into your posts and pages.
Easy Gallery Slider
easy-gallery-slider
Responsive slider uses the images attached to a post or page. Simple to customize and configure.
T&P Gallery Slider
tp-gallery-slider
T&P Gallery Slider for WordPress is an image hover/click gallery as a WordPress plugin.
SimpleGal
simplegal
Create an Image-Gallery in 5 simple Steps. Just add the shortcode to your posts.
SmoothGallery Developer Profile
3 plugins · 280 total installs
How We Detect SmoothGallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smoothgallery/css/jd.gallery.css/wp-content/plugins/smoothgallery/css/ReMooz.css/wp-content/plugins/smoothgallery/js/smoothgallery.jssmoothgallery/style.css?ver=smoothgallery/js/smoothgallery.js?ver=HTML / DOM Fingerprints
jd-galleryjd-controlsjd-captionjd-loadingjd-previewjd-thumbsjd-thumbs-wrapperjd-nav-prev+2 more<!-- Generated by SmoothGallery plugin -->data-smoothgallery-iddata-smoothgallery-themedata-smoothgallery-widthdata-smoothgallery-heightdata-smoothgallery-bordercolordata-smoothgallery-autoplay+6 moreSmoothGallery[smoothgallery]