
TZ Plus Gallery Security & Risk Analysis
wordpress.org/plugins/tz-plus-galleryTZ Plus Gallery - Display WordPress albums, social gallery like Facebook, Flickr, Instagram and Google+.
Is TZ Plus Gallery Safe to Use in 2026?
High Risk
Score 42/100TZ Plus Gallery carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The tz-plus-gallery plugin exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for nearly all SQL queries and a limited attack surface, significant concerns arise from its vulnerability history and code analysis signals. The presence of two unpatched medium severity CVEs, specifically Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF), coupled with a recent vulnerability discovery date, suggests a pattern of introducing exploitable flaws. The taint analysis further highlights potential risks with two high-severity flows exhibiting unsanitized paths, indicating that user-supplied data could potentially be processed in an unsafe manner, although the specific impact is not detailed as critical.
While the plugin has a small attack surface with no direct unprotected entry points and a decent percentage of output escaping, the high-severity taint flows and the existing CVEs are significant red flags. The fact that capability checks are present on only two instances and there are no nonce checks on the identified entry points (even though they are currently protected by authorization) could become a problem if authorization mechanisms are bypassed or changed in future versions. The plugin's strengths lie in its SQL handling and limited attack surface, but these are overshadowed by the active, unpatched vulnerabilities and the potential for XSS and CSRF attacks indicated by the vulnerability history and taint analysis. A cautious approach is recommended until these vulnerabilities are addressed.
Key Concerns
- 2 Unpatched Medium CVEs
- 2 High Severity Taint Flows
- No Nonce Checks on Entry Points
- Only 2 Capability Checks
TZ Plus Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
TZ PlusGallery <= 1.5.5 - Authenticated (Editor+) Stored Cross-Site Scripting
TZ PlusGallery <= 1.5.5 - Cross-Site Request Forgery
TZ Plus Gallery Release Timeline
TZ Plus Gallery Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TZ Plus Gallery Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
TZ Plus Gallery Maintenance & Trust
Maintenance Signals
Community Trust
TZ Plus Gallery Alternatives
Slideshow Gallery LITE
slideshow-gallery
Feature content in a JavaScript powered slideshow gallery showcase on your WordPress website.
OG Tags
og-tags
OG Tags includes the tags necessary to integrate your website to Facebook with almost no configuration. Automatic. Simple.
NextGEN Gallery ColorBoxer
nextgen-gallery-colorboxer
One-click ColorBox lightbox integration with NextGEN Gallery. Only loads when a gallery shortcode is present.
NextGEN Gallery Search
nextgen-gallery-search-galleries
Search a gallery within the NextGEN galleries including description search.
NG Gallery Optimizer Modified
ng-gallery-optimizer-modified
Improves your site's page load speed by preventing NextGEN's scripts & css from loading on posts and pages without galleries.
TZ Plus Gallery Developer Profile
7 plugins · 1K total installs
How We Detect TZ Plus Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tz-plus-gallery/css/admin.style.css/wp-content/plugins/tz-plus-gallery/css/tz_gallery_admin.css/wp-content/plugins/tz-plus-gallery/css/component.css/wp-content/plugins/tz-plus-gallery/js/modernizr.custom.js/wp-content/plugins/tz-plus-gallery/js/classie.js/wp-content/plugins/tz-plus-gallery/js/modalEffects.js/wp-content/plugins/tz-plus-gallery/js/tz_gallery_custom.js/wp-content/plugins/tz-plus-gallery/css/bootstrap-tabs.css+1 more/wp-content/plugins/tz-plus-gallery/js/modernizr.custom.js/wp-content/plugins/tz-plus-gallery/js/classie.js/wp-content/plugins/tz-plus-gallery/js/modalEffects.js/wp-content/plugins/tz-plus-gallery/js/tz_gallery_custom.js/wp-content/plugins/tz-plus-gallery/js/bootstrap-tab.jstz-plus-gallery/css/admin.style.css?ver=tz-plus-gallery/css/tz_gallery_admin.css?ver=tz-plus-gallery/css/component.css?ver=tz-plus-gallery/js/modernizr.custom.js?ver=tz-plus-gallery/js/classie.js?ver=tz-plus-gallery/js/modalEffects.js?ver=tz-plus-gallery/js/tz_gallery_custom.js?ver=tz-plus-gallery/css/bootstrap-tabs.css?ver=tz-plus-gallery/js/bootstrap-tab.js?ver=HTML / DOM Fingerprints
tz-tabstz_supporttz_documentgo-prodata-toggleinlineIdimgpath