
WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes Security & Risk Analysis
wordpress.org/plugins/wp-books-galleryWordPress Book Gallery will build a mobile-friendly book gallery, book showcase, or book library in a few minutes.
Is WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes Safe to Use in 2026?
Generally Safe
Score 98/100WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wp-books-gallery plugin v4.7.8 exhibits a mixed security posture. While it has a relatively small attack surface and a decent number of nonce and capability checks, there are notable areas of concern stemming from its code signals and vulnerability history. The presence of the `unserialize` function, especially without explicit checks on the data being unserialized, is a significant risk that could lead to remote code execution if an attacker can control the serialized data. Additionally, the taint analysis revealing flows with unsanitized paths, including one of high severity, points to potential vulnerabilities where external input is not properly validated or escaped before being used in a sensitive operation.
The plugin's vulnerability history shows a past medium-severity CVE, with the last reported vulnerability in February 2023. While there are no currently unpatched CVEs, the previous CSRF vulnerability highlights a historical tendency to have exploitable weaknesses. The fact that the last vulnerability was not critical or high might suggest good patching practices, but the underlying causes of past vulnerabilities, like CSRF, often indicate a need for robust input validation and authorization checks. The plugin's SQL query practice of using prepared statements 43% of the time is a weakness, as a significant portion of its database interactions are not protected against SQL injection.
In conclusion, while the plugin has some strengths in terms of its limited attack surface and the presence of security checks, the identified risks, particularly the use of `unserialize` and unsanitized taint flows, along with less-than-ideal SQL preparation, necessitate caution. The historical CVE, though medium, serves as a reminder of past security lapses. Users should be aware of these potential vulnerabilities and ensure the plugin is updated to the latest version, although this specific version is v4.7.8, and the history indicates no *currently* unpatched CVEs for it. The mixed results suggest that while not acutely dangerous, it's not a plugin to be deployed without careful consideration and monitoring.
Key Concerns
- Dangerous function: unserialize detected
- Taint analysis: high severity flow with unsanitized path
- SQL queries: 57% not using prepared statements
- Output escaping: 47% not properly escaped
- Bundled library: Freemius v1.0 (potentially outdated)
WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Books Gallery <= 4.8.0 - Missing Authorization to Unauthenticated Settings Update via 'permalink_structure' Parameter
WordPress Books Gallery <= 4.4.8 - Cross-Site Request Forgery leading to Plugin Settings Changes
WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes Release Timeline
WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes Attack Surface
Shortcodes 1
WordPress Hooks 23
Maintenance & Trust
WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes Maintenance & Trust
Maintenance Signals
Community Trust
WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes Alternatives
RS WP Book Showcase – A Complete Book Catalogue & Library System
rs-wp-books-showcase
Premier WordPress book gallery plugin, offering advanced search options and multiple layouts for effortless book showcasing.
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce
woo-product-feed-pro
Most popular WooCommerce product feed plugin supporting Google shopping feed, meta/facebook feed, bing product feed & more.
Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels
webappick-product-feed-for-woocommerce
Create WooCommerce product feeds for Google Shopping, Facebook, TikTok & 220+ channels. 2026 compliant. 6 formats. Trusted by 70,000+ stores.
Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces
best-woocommerce-feed
Generate WooCommerce product feeds for 200+ marketplaces. Sell on Google Shopping, Facebook, Instagram, Amazon, eBay, TikTok and more.
WP Review Slider
wp-facebook-reviews
Use the official Facebook API to show off your review and recommendations in a slider or grid! A simple and easy way to display your Twitter and Faceb …
WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes Developer Profile
14 plugins · 8K total installs
How We Detect WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-books-gallery/assets/css/frontend.css/wp-content/plugins/wp-books-gallery/assets/css/magnific-popup.css/wp-content/plugins/wp-books-gallery/assets/js/frontend.js/wp-content/plugins/wp-books-gallery/assets/js/jquery.magnific-popup.min.js/wp-content/plugins/wp-books-gallery/assets/js/wow.min.js/wp-content/plugins/wp-books-gallery/assets/js/jquery.ddslick.min.jsassets/js/frontend.jsassets/js/jquery.magnific-popup.min.jsassets/js/wow.min.jsassets/js/jquery.ddslick.min.jswp-books-gallery/assets/css/frontend.css?ver=wp-books-gallery/assets/js/frontend.js?ver=wp-books-gallery/assets/js/jquery.magnific-popup.min.js?ver=wp-books-gallery/assets/js/wow.min.js?ver=wp-books-gallery/assets/js/jquery.ddslick.min.js?ver=HTML / DOM Fingerprints
wbg-gallery-itemwbg-gallery-item-imagewbg-gallery-item-titlewbg-gallery-item-authorwbg-gallery-item-pricewbg-gallery-item-buttonwbg-no-imagewbg-admin-book-cover-list<!-- Donate us link to plugin description --><!-- rewrite_rules upon plugin activation --><!-- include your custom post type on category and tags pages --><!-- Add Columns to logo list table -->+2 moredata-wbg-imgdata-wbg-titledata-wbg-authordata-wbg-pricedata-wbg-buttondata-wbg-idWBG_ASSETSWBG_CLS_PRFXWBG_VERSION[wp_books_gallery]