Xpand Image Gallery Security & Risk Analysis

wordpress.org/plugins/xpand-image-gallery

The greatest expandable gallery for your wordpress website, seamless visualization, totally responsive... A unique way to show your images!

40 active installs v1.0.1 PHP + WP 3.5.1+ Updated Apr 13, 2015
expandablegallerygridimagesxpand
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Xpand Image Gallery Safe to Use in 2026?

Generally Safe

Score 85/100

Xpand Image Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The xpand-image-gallery plugin v1.0.1 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, and file operations is commendable. All SQL queries are properly prepared, and the presence of capability checks indicates some level of access control. However, the plugin has a concerning percentage of outputs that are not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if malicious data is introduced into these unescaped outputs. The lack of nonce checks, while not directly linked to a high attack surface in this analysis, is a common best practice for securing WordPress actions and could be a potential area for future exploitation if new attack vectors emerge.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the static analysis findings, suggests that in its current version, the plugin has not been publicly identified as having exploitable vulnerabilities. The lack of taint flows with unsanitized paths further supports this. Despite the strengths, the unescaped output is a notable weakness that requires attention, as it represents a direct, albeit potential, attack vector. The limited attack surface and absence of critical code signals are positive indicators, but the unescaped outputs prevent a conclusion of complete security.

Key Concerns

  • Outputs are not properly escaped
  • No nonce checks on entry points
Vulnerabilities
None known

Xpand Image Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Xpand Image Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
5 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped10 total outputs
Attack Surface

Xpand Image Gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[gallery] XpandGalleryLite.php:115
WordPress Hooks 3
actionadmin_menuXpandGalleryLite.php:13
actionadmin_initXpandGalleryLite.php:14
actionwp_enqueue_scriptsXpandGalleryLite.php:112
Maintenance & Trust

Xpand Image Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedApr 13, 2015
PHP min version
Downloads6K

Community Trust

Rating96/100
Number of ratings4
Active installs40
Developer Profile

Xpand Image Gallery Developer Profile

heyestudio

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Xpand Image Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xpand-image-gallery/img/heybanner.jpg/wp-content/plugins/xpand-image-gallery/img/xpgallerybanner.jpg
Script Paths
/wp-content/plugins/xpand-image-gallery/js/modernizr.custom.js/wp-content/plugins/xpand-image-gallery/js/grid.js
Version Parameters
xpand-image-gallery/css/style.css?ver=xpand-image-gallery/js/modernizr.custom.js?ver=xpand-image-gallery/js/grid.js?ver=

HTML / DOM Fingerprints

CSS Classes
xpg-color-picker
HTML Comments
<!-- BEGIN SETTINGS FORM (HTML) --><!-- END --><!-- Option -- Gallery Preview Height --><!-- Option -- Gallery Animation Speed -->+1 more
Data Attributes
name="xpgalLinkLove"name="xpgalPreviewHeight"name="xpgalAnimSpeed"name="xpgalWidgetBar"name="xpgalBgColor"name="xpgalTxtColor"+4 more
Shortcode Output
<div class="wrap">
FAQ

Frequently Asked Questions about Xpand Image Gallery