
WPZOOM Portfolio Lite – Filterable Portfolio Plugin Security & Risk Analysis
wordpress.org/plugins/wpzoom-portfolioPortfolio plugin for WordPress. Create filterable portfolio grids with masonry layouts and lightbox. Ideal for photographers, designers, agencies.
Is WPZOOM Portfolio Lite – Filterable Portfolio Plugin Safe to Use in 2026?
Generally Safe
Score 99/100WPZOOM Portfolio Lite – Filterable Portfolio Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of wpzoom-portfolio v1.4.20 reveals a generally strong security posture with excellent adherence to secure coding practices. The plugin demonstrates a complete absence of dangerous functions, utilizes prepared statements for all SQL queries, and exhibits a high rate of proper output escaping. Furthermore, the presence of nonce and capability checks on all identified entry points (AJAX handlers, REST API routes, shortcodes, and cron events) is commendable. The absence of any identified taint flows with unsanitized paths or critical/high severity issues further reinforces this positive assessment.
However, the plugin's vulnerability history presents a significant concern. With two previously disclosed medium severity vulnerabilities, both related to Cross-Site Scripting (XSS), and the most recent one being very recent (2024-08-30), this indicates a recurring pattern of input sanitization or output escaping weaknesses. While there are currently no unpatched CVEs, the history suggests that past vulnerabilities have required attention, and a close watch on future updates and disclosures is warranted. The attack surface is relatively small, and crucially, all entry points appear to be protected, which mitigates immediate risks from the identified entry points.
In conclusion, wpzoom-portfolio v1.4.20 exhibits strengths in its current implementation, particularly in its defensive coding practices for new vulnerabilities. The absence of readily apparent critical issues in static analysis is a positive sign. Nevertheless, the historical prevalence of medium-severity XSS vulnerabilities necessitates vigilance. Users should ensure they are on the latest version and be aware of the plugin's past security record. The lack of unpatched vulnerabilities in the history is a strong positive, but the pattern of past issues warrants a slightly reduced score for a balanced assessment.
Key Concerns
- History of 2 medium severity CVEs (XSS)
- Recent vulnerability (2024-08-30)
WPZOOM Portfolio Lite – Filterable Portfolio Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WPZOOM Portfolio Lite – Filterable Portfolio Plugin <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute
WPZOOM Portfolio <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WPZOOM Portfolio Lite – Filterable Portfolio Plugin Code Analysis
SQL Query Safety
Output Escaping
WPZOOM Portfolio Lite – Filterable Portfolio Plugin Attack Surface
AJAX Handlers 1
REST API Routes 1
Shortcodes 2
WordPress Hooks 44
Scheduled Events 1
Maintenance & Trust
WPZOOM Portfolio Lite – Filterable Portfolio Plugin Maintenance & Trust
Maintenance Signals
Community Trust
WPZOOM Portfolio Lite – Filterable Portfolio Plugin Alternatives
Visual Portfolio, Photo Gallery & Post Grid
visual-portfolio
Modern photo gallery and portfolio plugin with advanced layouts editor. Clean gallery styles with powerful settings in the Gutenberg block.
Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery
gallery-videos
Gallery is a user-friendly plugin to display user or hashtag-based gallery feeds as a responsive customizable gallery.
PowerFolio – Portfolio & Image Gallery for Elementor
portfolio-elementor
A powerful portfolio and gallery plugin for WP, Elementor and Gutenberg. Create portfolio and image galleries in seconds using any page builder!
Sight – Professional Image Gallery and Portfolio
sight
Introducing Sight — a fast & simple way to create professional looking portfolios and neatly stunning image and video galleries — all with zero co …
Filter Gallery
filter-gallery
Build a responsive filter gallery for your portfolio. Organize images with filters in a stunning grid or masonry layout easily.
WPZOOM Portfolio Lite – Filterable Portfolio Plugin Developer Profile
24 plugins · 337K total installs
How We Detect WPZOOM Portfolio Lite – Filterable Portfolio Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpzoom-portfolio/assets/js/editor-init-masonry.js/wp-content/plugins/wpzoom-portfolio/build/index.asset.php/wp-content/plugins/wpzoom-portfolio/build/style-index.css/wp-content/plugins/wpzoom-portfolio/build/index.js/wp-content/plugins/wpzoom-portfolio/build/editor.csswpzoom-portfolio/assets/js/editor-init-masonry.jswpzoom-portfolio/build/index.jswpzoom-portfolio/style.css?ver=wpzoom-portfolio/assets/js/editor-init-masonry.js?ver=wpzoom-portfolio/build/index.js?ver=wpzoom-portfolio/build/editor.css?ver=wpzoom-portfolio/build/style-index.css?ver=HTML / DOM Fingerprints
wpzoom-blocksdata-wpzoom-portfoliowpzoomPortfolioBlock[wpzoom_portfolio[/wpzoom_portfolio]