WP Media Stories Security & Risk Analysis

wordpress.org/plugins/wp-media-stories

Easy to use WordPress Media Photo Gallery. Don't just add photos! Make Stories!

0 active installs v0.1.1 PHP 5.6+ WP 3.0.1+ Updated Mar 16, 2022
galleryimage-gallerywordpress-gallerywordpress-gallery-pluginwp-media-stories
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Media Stories Safe to Use in 2026?

Generally Safe

Score 85/100

WP Media Stories has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The wp-media-stories plugin, in version 0.1.1, demonstrates a generally strong security posture, particularly for its current release. The static analysis reveals no critical or high severity code signals, including dangerous functions, unsanitized taint flows, or file operations. The plugin also utilizes prepared statements for all SQL queries, which is a best practice for preventing SQL injection vulnerabilities. Furthermore, a significant majority of output is properly escaped, and the presence of nonce and capability checks indicates an effort to implement basic security controls.

However, there are a few areas that warrant attention for future development. The plugin has a small attack surface consisting of two shortcodes, and while there are currently no reported vulnerabilities, a lack of comprehensive authentication checks on these entry points could become a concern as the plugin evolves or if new vulnerabilities are discovered. The bundled TinyMCE library, if not kept up-to-date, could also present a potential risk. Overall, this plugin appears to be developed with security in mind for its current state, but continued vigilance and adherence to best practices, especially regarding authentication and library management, will be crucial for maintaining a secure environment.

Key Concerns

  • Small attack surface without explicit auth checks
  • Bundled library (TinyMCE) potential risk if not updated
Vulnerabilities
None known

WP Media Stories Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Media Stories Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
67 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

89% escaped75 total outputs
Attack Surface

WP Media Stories Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[wp_media_story_inline] includes\class-shortcodes.php:42
[wp_media_story_galleries] includes\class-shortcodes.php:43
WordPress Hooks 15
actioninitincludes\class-admin.php:51
actionadd_meta_boxesincludes\class-admin.php:53
actionsave_postincludes\class-admin.php:54
actionadmin_enqueue_scriptsincludes\class-admin.php:56
actionadmin_enqueue_scriptsincludes\class-admin.php:57
actionwpms_metabox_settingsincludes\class-admin.php:59
actionwpms_save_metaincludes\class-admin.php:60
filterthe_contentincludes\class-template.php:42
actionwp_enqueue_scriptsincludes\class-template.php:45
actionwp_enqueue_scriptsincludes\class-template.php:46
actioninitincludes\editors\gutenberg.php:13
actioninitwp-media-stories.php:200
actionall_admin_noticeswp-media-stories.php:263
actionadmin_initwp-media-stories.php:266
actionplugins_loadedwp-media-stories.php:409
Maintenance & Trust

WP Media Stories Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMar 16, 2022
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WP Media Stories Developer Profile

SuitePlugins

17 plugins · 2K total installs

90
trust score
Avg Security Score
86/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect WP Media Stories

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-media-stories/assets/css/wp-media-stories.css/wp-content/plugins/wp-media-stories/assets/js/wp-media-stories.js
Script Paths
/wp-content/plugins/wp-media-stories/assets/js/wp-media-stories.js
Version Parameters
wp-media-stories/assets/css/wp-media-stories.css?ver=wp-media-stories/assets/js/wp-media-stories.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-media-stories
HTML Comments
Copyright (c) 2018 WP Media Stories (email : info@wpmediastories.com)
JS Globals
WP_Media_Stories
FAQ

Frequently Asked Questions about WP Media Stories