
WebPlus Gallery on WordPress Security & Risk Analysis
wordpress.org/plugins/webplus-galleryCreating a WordPress gallery is quick and easy.
Is WebPlus Gallery on WordPress Safe to Use in 2026?
Generally Safe
Score 85/100WebPlus Gallery on WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The webplus-gallery plugin v1.5.2 presents a mixed security posture. On the positive side, the plugin exhibits good practices regarding SQL queries, exclusively using prepared statements, and there is no recorded vulnerability history, including CVEs. The taint analysis also shows no critical or high severity flows with unsanitized paths, which is a strong indicator of code hygiene in sensitive areas. However, significant concerns arise from the identified attack surface. The presence of two AJAX handlers without authentication checks creates a direct pathway for unauthenticated users to interact with potentially sensitive plugin functionality, representing a notable security risk. Furthermore, a substantial portion of output (54%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly on the page. The lack of any nonce checks on these AJAX handlers exacerbates the risk associated with them.
While the plugin avoids dangerous functions and external HTTP requests, the absence of capability checks on AJAX handlers is a critical oversight. This, coupled with the unescaped output, suggests that while the core data handling might be secure (no raw SQL), the presentation and interaction layers have significant weaknesses. The vulnerability history being clean is a good sign, but it cannot entirely mitigate the immediate risks identified in the static analysis. The plugin needs immediate attention to secure its AJAX endpoints and improve output sanitization to reduce its overall risk profile.
Key Concerns
- AJAX handlers without auth checks
- Large percentage of unescaped output
- AJAX handlers without nonce checks
- AJAX handlers without capability checks
WebPlus Gallery on WordPress Security Vulnerabilities
WebPlus Gallery on WordPress Release Timeline
WebPlus Gallery on WordPress Code Analysis
Output Escaping
WebPlus Gallery on WordPress Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 26
Maintenance & Trust
WebPlus Gallery on WordPress Maintenance & Trust
Maintenance Signals
Community Trust
WebPlus Gallery on WordPress Alternatives
Image Gallery Block – Create and display photo gallery/photo album.
3d-image-gallery
Image Gallery Block helps you create responsive photo galleries, masonry layouts, and 3D sliders. Offers professional layouts and lightbox effects.
Gallery – Photo Albums Plugin
easy-media-gallery
Image Gallery – Photo Albums Plugin is the easiest tool to create image gallery, photo albums, portfolio and also photo slider.
Gallery Images Ape
gallery-images-ape
Image gallery, responsive photo gallery grid, customizable image slider, simple interface, links, video links and lightbox, custom themes, thumbnails
Gallery Thumbnails Block
gallery-thumbnails-block
A simple gallery block with thumbnails navigation.
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
WebPlus Gallery on WordPress Developer Profile
2 plugins · 1K total installs
How We Detect WebPlus Gallery on WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webplus-gallery/js/lightslider/src/css/lightslider.css/wp-content/plugins/webplus-gallery/js/lightslider/src/js/lightslider.js/wp-content/plugins/webplus-gallery/js/webplusgallery.js/wp-content/plugins/webplus-gallery/css/jquery-ui.css/wp-content/plugins/webplus-gallery/css/style.css/wp-content/plugins/webplus-gallery/js/upload.js/wp-content/plugins/webplus-gallery/js/lightslider/src/js/lightslider.js/wp-content/plugins/webplus-gallery/js/webplusgallery.js/wp-content/plugins/webplus-gallery/js/upload.jsHTML / DOM Fingerprints
webplusGalleryWrapwebplusGalleryli-item-pic-boxdata-typedata-thumbdata-src<div class="webplusGalleryWrap"><div class="webplusGallery" data-type="<img src=" alt="