Photo gallery lightbox – πŸ“± mobile friendly gallery plugin –– Story Show Gallery Security & Risk Analysis

wordpress.org/plugins/story-show-gallery

Full screen photo gallery lightbox for delightful display of your photos, with a lot of features, fully customizable, free.

200 active installs v1.11.0 PHP + WP 3.3+ Updated Jan 15, 2026
image-gallerylightboxphoto-galleryresponsive-gallerywordpress-gallery-plugin
100
A Β· Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Photo gallery lightbox – πŸ“± mobile friendly gallery plugin –– Story Show Gallery Safe to Use in 2026?

Generally Safe

Score 100/100

Photo gallery lightbox – πŸ“± mobile friendly gallery plugin –– Story Show Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "story-show-gallery" v1.11.0 plugin exhibits a generally positive security posture based on the static analysis provided. There are no identified critical or high severity issues within the code, including no dangerous functions, no SQL queries that are not prepared, and no taint flows indicating unsanitized data. The presence of a nonce check suggests awareness of common WordPress security practices, and the absence of file operations or external HTTP requests reduces potential attack vectors.

However, a significant concern arises from the low percentage of properly escaped output (30%). This indicates that a substantial portion of dynamically generated content may be vulnerable to cross-site scripting (XSS) attacks, especially if user-supplied data is not sufficiently sanitized before being displayed. While the attack surface appears minimal with zero identified entry points, this is potentially misleading if the output escaping issue is widespread within the plugin's functionality that isn't explicitly captured as an entry point in this analysis.

The plugin's vulnerability history is also a strong positive, with zero known CVEs. This, combined with the clean code signals, suggests a history of secure development. Despite the promising lack of historical vulnerabilities and apparent secure coding practices, the critical weakness in output escaping warrants caution. The plugin is likely safe from known external threats but remains susceptible to XSS if unescaped output is triggered by user input.

Key Concerns

  • Low percentage of properly escaped output (30%)
Vulnerabilities
None known

Photo gallery lightbox – πŸ“± mobile friendly gallery plugin –– Story Show Gallery Security Vulnerabilities

No known vulnerabilities β€” this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Photo gallery lightbox – πŸ“± mobile friendly gallery plugin –– Story Show Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
6 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

30% escaped20 total outputs
Attack Surface

Photo gallery lightbox – πŸ“± mobile friendly gallery plugin –– Story Show Gallery Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menustory-show-gallery.php:21
actionadmin_initstory-show-gallery.php:22
actionwp_enqueue_scriptsstory-show-gallery.php:947
actionwp_footerstory-show-gallery.php:1045
actionadmin_enqueue_scriptsstory-show-gallery.php:1054
filtershortcode_atts_gallerystory-show-gallery.php:1078
Maintenance & Trust

Photo gallery lightbox – πŸ“± mobile friendly gallery plugin –– Story Show Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 15, 2026
PHP min version
Downloads7K

Community Trust

Rating98/100
Number of ratings7
Active installs200
Developer Profile

Photo gallery lightbox – πŸ“± mobile friendly gallery plugin –– Story Show Gallery Developer Profile

Roman FlΓΆssler

2 plugins Β· 210 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Photo gallery lightbox – πŸ“± mobile friendly gallery plugin –– Story Show Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/story-show-gallery/css/admin-style.css/wp-content/plugins/story-show-gallery/css/gallery.css/wp-content/plugins/story-show-gallery/js/admin-script.js/wp-content/plugins/story-show-gallery/js/frontend-script.js
Script Paths
/wp-content/plugins/story-show-gallery/js/admin-script.js/wp-content/plugins/story-show-gallery/js/frontend-script.js
Version Parameters
story-show-gallery/css/admin-style.css?ver=story-show-gallery/css/gallery.css?ver=story-show-gallery/js/admin-script.js?ver=story-show-gallery/js/frontend-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
ssg-wrapssgh1ssg-textssg-greenssg-crucialssg-expander-imagessg-triossg-important+8 more
HTML Comments
<!-- there are three levels of defaults:// default options. Not mentiond options are falsy. This options are only for setting fields defaults in admin page of SSG -->// WP functions which generate all settings fields --><!-- settings_errors(); -->
Data Attributes
id="ssg-wrap"id="ssgh1"onclick="switchTo(1,1,9)"onclick="switchTo(2,10,19)"onclick="switchTo(3,20,26)"onclick="switchTo(4,27,31)"+4 more
JS Globals
window.storyShowGallery_optionswindow.storyShowGallery_options_defwindow.storyShowGallery_options_imgwindow.storyShowGallery_options_txt
FAQ

Frequently Asked Questions about Photo gallery lightbox – πŸ“± mobile friendly gallery plugin –– Story Show Gallery