
WP Flow Plus Security & Risk Analysis
wordpress.org/plugins/wp-imageflow2Flow style gallery with Lightbox popups. Uses images from the Wordpress Media Library or an uploaded directory of images.
Is WP Flow Plus Safe to Use in 2026?
Generally Safe
Score 97/100WP Flow Plus has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-imageflow2 plugin, version 5.2.7, presents a mixed security posture. While it exhibits good practices by having no unprotected entry points and a single nonce and capability check, several areas raise concerns. The static analysis reveals a significant risk with SQL queries; all four detected queries do not utilize prepared statements, which is a major vulnerability. Additionally, the output escaping is poorly implemented, with only 31% of outputs being properly escaped, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis shows all five analyzed flows have unsanitized paths, although they are not currently classified as critical or high severity. This suggests potential for XSS or other input validation issues that could be exploited.
The vulnerability history shows a past pattern of three medium severity CVEs, primarily related to Cross-Site Scripting. While there are no currently unpatched vulnerabilities, the historical prevalence of XSS issues, coupled with the current lack of proper output escaping and unsanitized input flows, strongly suggests that new XSS vulnerabilities are likely to exist or could be easily introduced. The plugin's strengths lie in its limited attack surface and the presence of some authentication checks. However, the significant reliance on raw SQL and inadequate output sanitization overshadow these strengths, making it a moderate security risk.
Key Concerns
- Raw SQL queries without prepared statements
- Low percentage of properly escaped output
- All analyzed flows have unsanitized paths
- History of XSS vulnerabilities
WP Flow Plus Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WP Flow Plus <= 5.2.5 - Authenticated (Author+) Stored Cross-Site Scripting
WP Flow Plus <= 5.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Flow Plus <= 5.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Flow Plus Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Flow Plus Attack Surface
Shortcodes 2
WordPress Hooks 28
Maintenance & Trust
WP Flow Plus Maintenance & Trust
Maintenance Signals
Community Trust
WP Flow Plus Alternatives
Gallerya
gallerya
Change the native post gallery to be displayed as a slider with lightbox support.
Smart Slider 3
smart-slider-3
Responsive slider plugin to create sliders in visual editor easily. Build beautiful image slider, layer slider, video slider, post slider, and more.
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider
ml-slider
Slider, gallery, carousel plugin for WordPress. Build your image slider, video slider, post slider, YouTube slider, or WooCommerce product slider.
Firelight Lightbox
easy-fancybox
Formerly Easy Fancybox. The most popular WordPress lightbox plugin. Simple, fast, and responsive. Opens images, videos, PDFs, and custom popups.
Lightbox & Modal Popup WordPress Plugin – FooBox
foobox-image-lightbox
A responsive image lightbox for WordPress galleries, WordPress attachments & FooGallery
WP Flow Plus Developer Profile
2 plugins · 4K total installs
How We Detect WP Flow Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-imageflow2/css/screen.css/wp-content/plugins/wp-imageflow2/js/imageflowplus.js/wp-content/plugins/wp-imageflow2/js/wpif2_utility.js/wp-content/plugins/wp-imageflow2/js/imageflowplus.js/wp-content/plugins/wp-imageflow2/js/wpif2_utility.jswp-imageflow2/style.css?ver=wp-imageflow2/ie8.css?ver=wp-imageflow2/js/imageflowplus.js?ver=wp-imageflow2/js/wpif2_utility.js?ver=HTML / DOM Fingerprints
<!-- WP Flow Plus requires at least WordPress 2.8.4 -->** Nothing needs to be done for now **** Merge default options with the saved values **** Determine the path to a gallery specified by url **+9 moredata-wpif2-image-linkwpif2_flowplus