VKontakte Photo Gallery Security & Risk Analysis

wordpress.org/plugins/vkontakte-photo-gallery

Plugin allow import photos from social network vkontakte.ru.

10 active installs v1.0 PHP + WP 3.2+ Updated Aug 16, 2011
pagesphotophotospostsvkontakte
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is VKontakte Photo Gallery Safe to Use in 2026?

Generally Safe

Score 85/100

VKontakte Photo Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The vkontakte-photo-gallery plugin v1.0 exhibits a seemingly strong security posture based on the provided static analysis, with no identified entry points requiring authentication, no dangerous functions, and all SQL queries utilizing prepared statements. The absence of vulnerability history also suggests a clean track record. However, a critical concern emerges from the output escaping analysis, where 100% of outputs are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website through unescaped data displayed to users. While the plugin has no known CVEs and a clear code history, this lack of output sanitization represents a significant weakness that could be exploited.

Key Concerns

  • 0% of outputs properly escaped
Vulnerabilities
None known

VKontakte Photo Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

VKontakte Photo Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

VKontakte Photo Gallery Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_print_scripts-post-new.phpvkpg.php:34
actionadmin_print_stylesvkpg.php:40
actionadmin_menuvkpg.php:59
actionmedia_buttonsvkpg.php:61
actionadmin_footervkpg.php:62
actionwp_dashboard_setupvkpg.php:65
actionadmin_print_scripts-index.phpvkpg.php:66
Maintenance & Trust

VKontakte Photo Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedAug 16, 2011
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

VKontakte Photo Gallery Developer Profile

Yaroslav Bogutsky

3 plugins · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect VKontakte Photo Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vkontakte-photo-gallery/css/vkpg.css/wp-content/plugins/vkontakte-photo-gallery/js/vkpg_media_button.js/wp-content/plugins/vkontakte-photo-gallery/js/vkpg_load_news.js/wp-content/plugins/vkontakte-photo-gallery/img/vkpg_paste.png
Script Paths
http://vkontakte.ru/js/api/openapi.jshttp://userapi.com/js/api/openapi.js

HTML / DOM Fingerprints

CSS Classes
vkpg_pastevkpg_groupvkpg_news_listvkpg_type_newsvkpg_paginator_startvkpg_paginator_endvkpg_paginator_totalvkpg_previous_news+1 more
Data Attributes
wait_textall_textplugin_textno_news_texttypestart+1 more
JS Globals
VKbogutsky_copinycopinyWidgetOptionsinitCopinyInlineWidgetCopinyInlineWidget
FAQ

Frequently Asked Questions about VKontakte Photo Gallery