Social Photo Gallery Security & Risk Analysis

wordpress.org/plugins/social-photo-gallery

Social Photo Gallery allow Polaroid image gallery.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Dec 7, 2016
albumgalleryimagesphoto-gallerywoocommerce
63
C · Use Caution
CVEs total1
Unpatched1
Last CVENov 13, 2019
Download
Safety Verdict

Is Social Photo Gallery Safe to Use in 2026?

Use With Caution

Score 63/100

Social Photo Gallery has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Nov 13, 2019Updated 9yr ago
Risk Assessment

The "social-photo-gallery" v1.0 plugin exhibits a mixed security posture, with some encouraging signs but significant underlying risks. While the plugin demonstrates good practice by heavily utilizing prepared statements for its SQL queries and has a seemingly limited attack surface with no directly unprotected entry points identified in static analysis, critical concerns emerge from its output escaping and taint analysis. The complete absence of output escaping is a severe vulnerability that exposes users to Cross-Site Scripting (XSS) attacks. Coupled with a high number of taint flows with unsanitized paths, particularly those flagged with high severity, this indicates a strong possibility of malicious data being processed and reflected to users without proper sanitization. The plugin's vulnerability history, including a known high severity CVE related to code injection, further exacerbates these concerns. The presence of an unpatched high severity vulnerability, even if from 2019, suggests a lack of ongoing maintenance and a potential for exploitation. The outdated bundled jQuery library is another minor concern that could be leveraged in conjunction with other vulnerabilities. Overall, the plugin's current state poses a considerable risk due to severe output handling issues and a history of exploitable vulnerabilities.

Key Concerns

  • Unescaped output found
  • High severity taint flows
  • Unpatched CVE found
  • Bundled outdated library (jQuery v1.6.1)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
1

Social Photo Gallery Security Vulnerabilities

CVEs by Year

1 CVE in 2019 · unpatched
2019
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2019-14467high · 7.8Improper Control of Generation of Code ('Code Injection')

Social Photo Gallery <= 1.0 - Remote Code Execution

Nov 13, 2019Unpatched
Code Analysis
Analyzed Mar 17, 2026

Social Photo Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
18 prepared
Unescaped Output
62
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
9
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery1.6.1

SQL Query Safety

90% prepared20 total queries

Output Escaping

0% escaped62 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

8 flows8 with unsanitized paths
album_gallery_func (gallery.php:3)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Social Photo Gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[social-photo-gallery] socialphotogallery.php:20
WordPress Hooks 5
actionadmin_enqueue_scriptssocialphotogallery.php:16
actionwp_enqueue_scriptssocialphotogallery.php:17
actionadmin_menusocialphotogallery.php:18
actionadmin_initsocialphotogallery.php:19
actioninitsocialphotogallery.php:21
Maintenance & Trust

Social Photo Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedDec 7, 2016
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Social Photo Gallery Developer Profile

Infoway LLC

2 plugins · 20 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Photo Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-photo-gallery/admin/css/datetimepicker-all.css/wp-content/plugins/social-photo-gallery/admin/css/socialphotogallery.css/wp-content/plugins/social-photo-gallery/admin/js/socialphotogallery.js/wp-content/plugins/social-photo-gallery/css/socialphotogallery.css/wp-content/plugins/social-photo-gallery/js/socialphotogallery.js/wp-content/plugins/social-photo-gallery/js/jquery-1.6.1.min.js
Script Paths
http://ajax.googleapis.com/ajax/libs/jquery/1.4/jquery.min.jshttp://ajax.googleapis.com/ajax/libs/jqueryui/1.7.2/jquery-ui.min.js

HTML / DOM Fingerprints

CSS Classes
theme-options-table
JS Globals
ajaxurl
Shortcode Output
[social-photo-gallery]
FAQ

Frequently Asked Questions about Social Photo Gallery