
ThickBox Security & Risk Analysis
wordpress.org/plugins/thickboxEmbed ThickBox into your posts and pages.
Is ThickBox Safe to Use in 2026?
Generally Safe
Score 85/100ThickBox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Thickbox plugin version 1.6.1 exhibits a mixed security posture. On one hand, the static analysis shows no known critical vulnerabilities in its history and a complete absence of AJAX handlers, REST API routes, shortcodes, and cron events that could serve as direct entry points. Furthermore, all detected SQL queries are properly prepared, and there are no external HTTP requests, which are positive security indicators. However, significant concerns arise from the output escaping. With 100% of its outputs not being properly escaped, this plugin presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis also reveals flows with unsanitized paths, although they are not classified as critical or high severity. The presence of file operations without explicit authentication or capability checks is also a potential area of concern, especially when combined with unescaped output. While the plugin has no recorded CVEs, the lack of output escaping is a fundamental security flaw that could lead to exploitable issues.
Key Concerns
- Unescaped output across all outputs
- Flows with unsanitized paths
- File operation without explicit auth check
ThickBox Security Vulnerabilities
ThickBox Code Analysis
Output Escaping
Data Flow Analysis
ThickBox Attack Surface
WordPress Hooks 8
Maintenance & Trust
ThickBox Maintenance & Trust
Maintenance Signals
Community Trust
ThickBox Alternatives
Social Photo Fetcher
facebook-photo-fetcher
Allows you to automatically create Wordpress photo galleries from Facebook albums. Simple to use and highly customizable.
Easy Gallery Slider
easy-gallery-slider
Responsive slider uses the images attached to a post or page. Simple to customize and configure.
SmoothGallery
smoothgallery
Embed JonDesign's SmoothGallery into your posts and pages.
T&P Gallery Slider
tp-gallery-slider
T&P Gallery Slider for WordPress is an image hover/click gallery as a WordPress plugin.
SimpleGal
simplegal
Create an Image-Gallery in 5 simple Steps. Just add the shortcode to your posts.
ThickBox Developer Profile
3 plugins · 280 total installs
How We Detect ThickBox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/thickbox/thickbox/thickbox.css/wp-content/plugins/thickbox/thickbox/thickbox.js/wp-content/plugins/thickbox/smoothbox/smoothbox.css/wp-content/plugins/thickbox/smoothbox/smoothbox.js/wp-content/plugins/thickbox/thickbox/thickbox.php?action=tcss/wp-content/plugins/thickbox/thickbox/thickbox.php?action=tjs/wp-content/plugins/thickbox/thickbox/thickbox.php?action=scss/wp-content/plugins/thickbox/thickbox/thickbox.php?action=sjsver=ver=1.6.1HTML / DOM Fingerprints
TB_overlayTB_windowTB_ajaxContentTB_closeWindow<!-- ThickBox --><!-- /ThickBox --><!-- WordPress ThickBox plugin --><!-- Copyright (C) 2008-2012 Christian Schenk -->+48 moredata-thickbox-titledata-thickbox-captionthickboxtb_pathToImagetb_make_thickboxtb_removetb_show