Gallery2 Image Block Security & Risk Analysis

wordpress.org/plugins/wp-gallery2-image-block

Widget to display your Gallery 2 Image Block on your WordPress sidebar

10 active installs v0.6.4 PHP + WP 2.8+ Updated Unknown
gallery2image-blockimageswidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gallery2 Image Block Safe to Use in 2026?

Generally Safe

Score 100/100

Gallery2 Image Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The wp-gallery2-image-block v0.6.4 plugin exhibits a mixed security posture. On the positive side, static analysis shows no critical vulnerabilities related to dangerous functions, SQL injection (all queries use prepared statements), file operations, or external HTTP requests. Furthermore, there is no recorded vulnerability history, suggesting a potentially stable codebase. However, a significant concern is the complete lack of output escaping. With 39 total outputs identified and 0% properly escaped, this presents a high risk of cross-site scripting (XSS) vulnerabilities. Any user-supplied data that is displayed to other users without proper sanitization could be exploited. Additionally, the absence of nonce and capability checks on any identified entry points (though none are listed) means that even if entry points existed, they could be vulnerable if not properly secured. The lack of taint analysis results is also noteworthy, as it prevents a deeper understanding of potential data flow risks.

Key Concerns

  • Output escaping is completely missing
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Gallery2 Image Block Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gallery2 Image Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
39
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped39 total outputs
Attack Surface

Gallery2 Image Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initwp-gallery2-image-block.php:96
Maintenance & Trust

Gallery2 Image Block Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedUnknown
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Gallery2 Image Block Developer Profile

Matt Rude

4 plugins · 150 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gallery2 Image Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-gallery2-image-block/languages/wp-gallery2-image-block_en_US.mo

HTML / DOM Fingerprints

CSS Classes
Gallery2_Block
Data Attributes
id="gallery2-image-block"name="gallery2-image-block"
FAQ

Frequently Asked Questions about Gallery2 Image Block