
TinyWebGallery wrapper Security & Risk Analysis
wordpress.org/plugins/tinywebgallery-wrapperThis plugin includes TinyWebGallery as shortcode in an advanced iframe and offers a TWG random image widget.
Is TinyWebGallery wrapper Safe to Use in 2026?
Generally Safe
Score 85/100TinyWebGallery wrapper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tinywebgallery-wrapper v2.4 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin has a very small attack surface with only one entry point (a shortcode), and importantly, no unprotected entry points were identified. The code also adheres to secure practices regarding SQL queries, exclusively using prepared statements, and includes a nonce check. There are no identified dangerous functions or external HTTP requests, which are significant strengths.
However, a notable concern arises from the low percentage of properly escaped output (13%). This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamic content may not be adequately neutralized before being displayed in the browser. While the taint analysis shows no critical or high severity issues, the lack of proper output escaping on a large number of outputs means that XSS vulnerabilities could still be present and exploitable.
The complete absence of recorded vulnerabilities, including CVEs, is a strong positive signal, suggesting a history of secure development and maintenance. Nevertheless, the low output escaping rate is a critical weakness that overshadows the otherwise positive indicators. The plugin's strengths lie in its limited attack surface and secure SQL handling, but the unescaped output presents a tangible and potentially exploitable risk that requires attention.
Key Concerns
- Low percentage of properly escaped output
TinyWebGallery wrapper Security Vulnerabilities
TinyWebGallery wrapper Release Timeline
TinyWebGallery wrapper Code Analysis
Output Escaping
TinyWebGallery wrapper Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
TinyWebGallery wrapper Maintenance & Trust
Maintenance Signals
Community Trust
TinyWebGallery wrapper Alternatives
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Advanced iFrame
advanced-iframe
Include content the way YOU like in an iframe that can hide and modify elements, does auto-height, forward parameters and does many, many more...
Gallery Box
gallery-box
You can create awesome image, portfolio, audio, video and i-frame gellery with lots of effects By this plugin.
EWSEL Lightbox For Galleries
ewsel-lightbox-for-galleries
Makes the WordPress galleries use a lightbox script called ColorBox to display the fullsize images.
PiwigoPress
piwigopress
From any open API Piwigo gallery, swiftly include your photos in Posts/Pages and/or add randomized thumbnails and menus in your sidebar.
TinyWebGallery wrapper Developer Profile
2 plugins · 40K total installs
How We Detect TinyWebGallery wrapper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tinywebgallery-wrapper/css/twg.cssHTML / DOM Fingerprints
errordivdata-twg-urldata-twg-securitykeydata-twg-widthdata-twg-heightdata-twg-frameborderdata-twg-scrolling+11 more<div class="errordiv">An invalid security key was specified. Please use at least the following shortcode:<br>[twg securitykey="<your security key - see settings>"]</div>