Srizon Responsive Flickr Gallery Basic Security & Risk Analysis

wordpress.org/plugins/srizon-flickr-gallery-basic

This Plugin is designed to show your flickr photos into your WordPress site either as an album or as a gallery (A collection of albums).

30 active installs v1.1.1 PHP + WP 4.1+ Updated Dec 21, 2018
albumflickrgalleryphoto-albumphoto-gallery
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Srizon Responsive Flickr Gallery Basic Safe to Use in 2026?

Generally Safe

Score 85/100

Srizon Responsive Flickr Gallery Basic has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "srizon-flickr-gallery-basic" plugin v1.1.1 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and having no known historical vulnerabilities, significant concerns arise from its attack surface and output handling. The plugin exposes four unprotected AJAX handlers, which are prime targets for unauthorized actions if not properly secured. This lack of authentication on such a critical entry point is a notable weakness. Furthermore, a low percentage (16%) of output escaping indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts through various plugin functionalities. The taint analysis, while showing no critical or high severity flows, did identify two flows with unsanitized paths, which could potentially lead to issues if they interact with user-supplied data that isn't subsequently sanitized or escaped. Overall, the absence of historical vulnerabilities is a positive sign, suggesting a generally careful development approach, but the current static analysis reveals critical areas needing immediate attention, particularly the unprotected AJAX endpoints and the widespread lack of output escaping.

Key Concerns

  • Unprotected AJAX handlers
  • Low percentage of properly escaped output
  • Flows with unsanitized paths
Vulnerabilities
None known

Srizon Responsive Flickr Gallery Basic Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Srizon Responsive Flickr Gallery Basic Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
53
10 escaped
Nonce Checks
5
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery

Output Escaping

16% escaped63 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
<album-settings-form> (admin\forms\album-settings-form.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Srizon Responsive Flickr Gallery Basic Attack Surface

Entry Points6
Unprotected4

AJAX Handlers 4

authwp_ajax_srz_flickr_save_album_listadmin\srizon-flickr-common-back.php:93
authwp_ajax_srz_flickr_remove_album_listadmin\srizon-flickr-common-back.php:104
authwp_ajax_srz_flickr_save_gallery_listadmin\srizon-flickr-common-back.php:116
authwp_ajax_srz_flickr_remove_gallery_listadmin\srizon-flickr-common-back.php:127

Shortcodes 2

[srzflalbum] site\srizon-flickr-album-front.php:49
[srzflgallery] site\srizon-flickr-gallery-front.php:50
WordPress Hooks 5
actionadmin_menuadmin\srizon-flickr-common-back.php:2
actioninitadmin\srizon-flickr-common-back.php:3
actionwp_enqueue_scriptssite\srizon-flickr-front.php:2
actioninitsite\srizon-flickr-front.php:16
actionplugins_loadedsrizon-flickr-gallery.php:15
Maintenance & Trust

Srizon Responsive Flickr Gallery Basic Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 21, 2018
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs30
Developer Profile

Srizon Responsive Flickr Gallery Basic Developer Profile

afzal_du

3 plugins · 40 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Srizon Responsive Flickr Gallery Basic

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/srizon-flickr-gallery-basic/admin/resources/admin.css/wp-content/plugins/srizon-flickr-gallery-basic/admin/resources/admin.js
Script Paths
/wp-content/plugins/srizon-flickr-gallery-basic/admin/resources/admin.js
Version Parameters
srizon-flickr-gallery-basic/admin/resources/admin.css?ver=srizon-flickr-gallery-basic/admin/resources/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
srzflickradmin
Data Attributes
srzflickr-icon.png
JS Globals
srz_flickr_get_resource_url
FAQ

Frequently Asked Questions about Srizon Responsive Flickr Gallery Basic