Plugin Pulse
← Pulse

Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery

by Syed Balkhi · Media

Also makes 95 other plugins · 21.6M+ installs across the portfolio →

The most popular gallery plugin that lets you create galleries and albums in seconds.

M WP Mayor reviewed this plugin NextGEN Gallery: Display, Share, and Sell Your Photos Read review ↗
How scoring works →
82 Health · B
Maintenance 100/100
Rating quality 84/100
Support 49/100

82 health vs 59 average across 2,206 Media plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

87 / 100

Excellent listing optimization

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 86/100
Listing tuning 100/100
Support resolution 35/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

+179% vs prior 30d
7.4KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

594.6K

now · peak 669.9K

595.2K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Photo Gallery, Slide · #160 you Photo Gallery by 10W · #291 Photo Gallery by Foo · #299 Robo Gallery · #875

Rating trend

Star average over time · dips mark rough releases

4.3Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

2Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

14

releases in the last 12 months

2mo ago

latest release · v4.2.3

44

tagged releases on record

Recent releases

4.2.3 · 2mo ago4.2.2 · 3mo ago4.2.1 · 3mo ago4.2.0 · 4mo ago4.1.3 · 5mo ago4.1.2 · 5mo ago4.1.1 · 6mo ago4.1.0 · 6mo ago4.0.5 · 6mo ago4.0.4 · 7mo ago4.0.3 · 8mo ago4.0.2 · 8mo ago4.0.1 · 9mo ago4.0.0 · 9mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v4.2 42%
v3.59 16%
v4.0 5.1%
Older / other versions 37%

Estimated active installs

The public count shows “300K+”. Our estimate pins where the real number sits.

tracked estimate
300K–400K ≈370K

Refined from the date this plugin crossed into its current band.

Install history · since 2015-09-06 · 1,500 observations

300KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.

Details

Version
4.4.0
Last updated
4d ago
Added
2007-04-23 · 19 yrs old
Requires WP
5.5.4
Tested up to
7.1
Requires PHP
7.4

Recent reviews

All reviews on wp.org ↗
  1. airkagi
    2mo ago

    I think this is a must-have product. I’ve been using it since around 2018, and it has improved tremendously over the years. I especially love the new interface and the photo management system. Uploading photos is now much faster and easier, making my workflow much more efficient. I came from building websites with HTML before switching to WordPress, so I really appreciate everything this software automates. For me, it’s been a game changer. If you’ve always used WordPress, you may take some of these features for granted, but coming from a more manual workflow, I can truly appreciate how much time it saves. This has become one of my favorite programs because it has stood the test of time. It continues to improve with every update, and I rely on it regularly. I highly recommend it to anyone looking for a reliable, well-supported platform. — ThePhotoGuy.us

    Read on wp.org ↗
  2. scratchy101
    3mo ago

    This is actually a downgrade as the whole look and feel of Nexgen is gone. Managing Albums now truncates the names of the Galleries shown in a grid, instead of the full names in a list in Nexgen. Many users are reporting problems with this update, such as HTML links in descriptions are now broken as well as back-end editing of albums and galleries.

    Read on wp.org ↗
  3. webweaverToo
    4mo ago

    I have been using NextGEN gallery since 2011. It’s been a brilliant plugin. Having just installed the latest version on a new website I’m building, all I can say is DO NOT “UPGRADE” TO v4. It’s awful – horrible new interface (which I guess you could get used to) but much worse – I could not get it to work on my WP build at all. It just would not show any galleries on the “Manage galleries” page, however many new test galleries I made and however many times I refreshed. Useless. Fortunately I found a post in the forums that told me to go to plugins > nextgen-gallery > advanced Scroll to the bottom of that page where you’ll see Previous Versions where you can download v3.59.12. I have uninstalled v4 and installed v3.59.12 instead, which works fine. Phew. I’ll never be “upgrading” to v4, that’s for sure.

    Read on wp.org ↗
  4. oleg5korolevskiy
    6mo ago

    Спасибо создателю этого плагина за старую версию.

    Read on wp.org ↗
  5. gahlii
    6mo ago

    I’ve been using NextGEN Galleries for a long time across multiple websites and I have over 300 Galleries. It was always my first choice for albums and galleries. But since v4, everything has changed — and not in a good way. For the last 2–3 weeks I’ve been really dissatisfied. At first I assumed it would get fixed quickly, but it hasn’t. Instead, it’s been incredibly frustrating to use. I’m constantly running into error messages, and it features were removed without any clear announcement or proper transition. I can’t recommend this plugin to anyone. It’s a shame, because it used to be reliable — but v4 has been a major step backwards.

    Read on wp.org ↗
  6. bobwey1
    7mo ago

    We have used NextGEN Gallery for years. Website has 50 galleries, with over 4500 images. Whenever there’s been a problem, Supoort has responded promptly, with resolution and/or suggestions. Haven’t switched from NextGEN to Imagely because I’m comfortable with the NextGEN format and feel that Imagely is too drastic a change.

    Read on wp.org ↗
  7. tinuzz
    7mo ago

    I’m a long time Nextgen gallery user, so the latest major update under the Imagely brand came as quite the shock. Generally, the esthetic changes aren’t bad, but it’s pretty buggy and important functionality has been removed. I’m not going to list all the problems here, but if things do not improve over the next couple of updates, I’m seriously going to look for alternatives.

    Read on wp.org ↗
  8. macsuibhne
    7mo ago

    Despite some flaws this used to be a good plugin. However, since the 4.0 update it’s pretty much unusable. Just have a look through the support pages and you’ll see absolutely no response from the developers and anything critical is being deleted completely. The plugin is hugely buggy now. Some of the most basic things you’d expect to find in a gallery plugin are missing, like being able to set maximum dimensions and quality. Any photo you upload to the free version now are saved and displayed at their original resolution. And that’s just one example! I’ve been using NextGen for close to a decade and I’ve even bought the pro version multiple times but now it’s time to move on. About 5 years ago I contacted support about a problem with displaying galleries. The reply was that it was a known issue and was to be fixed in the near future. 5 years later and it still hasn’t been fixed. So do I expect the absolute catastrophe of the 4.0 update to be fixed? Not a chance!

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 4.2.2 Added: Google Photos integration — import images directly from your Google Photos account into NextGEN galleries. Added: Dropbox integration — import images from Dropbox into NextGEN galleries. 4.2.2
  2. Version 4.2.1 Fixed: Security hardening across the plugin to better protect site data and reinforce permission checks. We recommend updating. Fixed: Edit Image crop tool now uses the correct aspect ratio from your gallery’s thumbnail 4.2.1
  3. Version 4.2.0 Fixed: Publishing galleries and albums from the Imagely Lightroom plugin could fail with a generic processing error after a recent update Fixed: Albums created by Imagely Lightroom could appear empty on the front end wit 4.2.0
  4. Version 4.1.3 Fixed: Imagely admin no longer hammered the REST API with repeated settings requests when browsing Galleries and Albums (column visibility auto-save). 4.1.3
  5. Version 4.1.2 Added: Duplicate pricelists individually or in bulk from the Ecommerce tab with confirmation modal Added: Column visibility on “Manage Galleries” and “Manage Albums” tables is now saved and restored when returning to the 4.1.2
  6. Version 4.1.1 Fixed: PNG and WEBP watermarks no longer lose transparency when applied to images Fixed: Fatal error when using NextGen Gallery with older Pro add-on versions that reference the legacy C_NextGen_Settings class Fixed: Sin 4.1.1

Known vulnerabilities

via Wordfence Intelligence

44 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-03 CVE-2026-28141 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.3 Patched in 4.2.4
  2. 2026-05-20 CVE-2026-9059 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.2.1 Patched in 4.2.1
  3. 2026-05-19 CVE-2026-6566 Authorization Bypass Through User-Controlled Key Affects <= 4.2.0 Patched in 4.2.1
  4. 2026-03-17 CVE-2026-1463 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 4.0.4 Patched in 4.0.5
  5. 2025-12-17 CVE-2025-13641 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 3.59.12 Patched in 4.0.0
  6. 2025-07-03 CVE-2025-2537 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.59.11 Patched in 3.59.12
  7. 2025-05-19 CVE-2024-5878 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.59.4 Patched in 3.59.5
  8. 2025-02-04 CVE-2024-10545 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.59.8 Patched in 3.59.9
  9. 2024-12-03 CVE-2024-5020 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.59.4 Patched in 3.59.5
  10. 2024-11-04 CVE-2024-6393 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.39.4 Patched in 3.39.5
  11. 2024-07-22 CVE-2024-39627 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.59.3 Patched in 3.59.4
  12. 2024-06-22 CVE-2024-5442 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.59.2 Patched in 3.59.3
  13. 2024-04-26 CVE-2024-2744 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.59 Patched in 3.59.1
  14. 2024-04-05 CVE-2024-3097 Missing Authorization Affects <= 3.59 Patched in 3.59.1
  15. 2023-11-23 CVE-2023-48328 Cross-Site Request Forgery (CSRF) Affects <= 3.37 Patched in 3.39
  16. 2023-09-25 CVE-2023-3279 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.38 Patched in 3.39
  17. 2023-09-25 CVE-2023-3155 Files or Directories Accessible to External Parties Affects <= 3.37 Patched in 3.39
  18. 2023-09-25 CVE-2023-3154 Deserialization of Untrusted Data Affects <= 3.38 Patched in 3.39
  19. 2023-02-14 CVE-2022-38468 Cross-Site Request Forgery (CSRF) Affects <= 3.28 Patched in 3.29
  20. 2020-12-17 CVE-2020-35942 Cross-Site Request Forgery (CSRF) Affects <= 3.4.7 Patched in 3.5.0
  21. 2020-12-17 CVE-2020-35943 Cross-Site Request Forgery (CSRF) Affects <= 3.4.7 Patched in 3.5.0
  22. 2019-08-27 CVE-2019-14314 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.2.11 Patched in 3.2.11
  23. 2019-02-25 Missing Authorization Affects < 3.1.7 Patched in 3.1.7
  24. 2019-02-04 Deserialization of Untrusted Data Affects <= 3.1.5 Patched in 3.1.6
  25. 2018-03-02 CVE-2018-7586 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.2.46 Patched in 2.2.50
  26. 2018-02-14 CVE-2018-1000172 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.44 Patched in 2.2.45
  27. 2017-02-17 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.1.77 Patched in 2.1.79
  28. 2016-11-15 CVE-2016-10889 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.1.56 Patched in 2.1.57
  29. 2016-11-15 CVE-2016-6565 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 2.1.56 Patched in 2.1.57
  30. 2015-12-23 CVE-2015-9228 Unrestricted Upload of File with Dangerous Type Affects <= 2.1.10 Patched in 2.1.15
  31. 2015-09-14 CVE-2015-9229 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.1.15 Patched in 2.1.23
  32. 2015-08-31 CVE-2015-9537 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.1.9 Patched in 2.1.10
  33. 2015-08-28 CVE-2015-9538 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 2.1.10 Patched in 2.1.15
  34. 2015-08-28 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.1.7 Patched in 2.1.9
  35. 2015-03-25 CVE-2015-1784 Cross-Site Request Forgery (CSRF) Affects < 2.0.77.3 Patched in 2.0.77.3
  36. 2015-03-25 CVE-2015-1785 Unrestricted Upload of File with Dangerous Type Affects < 2.0.77.3 Patched in 2.0.77.3
  37. 2014-05-20 Unrestricted Upload of File with Dangerous Type Affects <= 2.0.65 Patched in 2.0.66
  38. 2014-02-18 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.0 Patched in 2.0.7
  39. 2013-06-13 CVE-2013-3684 Unrestricted Upload of File with Dangerous Type Affects <= 1.9.12 Patched in 1.9.13
  40. 2013-02-14 CVE-2013-0291 Exposure of Sensitive Information to an Unauthorized Actor Affects 1.9.10 - 1.9.11 Patched in 2.0.0
  41. 2012-11-09 CVE-2012-3414 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.6 Patched in 1.9.7
  42. 2012-06-14 CVE-2012-3414 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.7 Patched in 1.9.8
  43. 2010-04-06 CVE-2010-1186 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.5.2 Patched in 1.5.2
  44. 2008-06-07 CVE-2008-7175 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.0 Patched in 1.9.1

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 76 languages, 5 at 90% or more

Dutch 100%
Dutch (Formal) 100%
Slovak 100%
Czech 99%
English (UK) 99%
Polish 81%
Spanish (Chile) 76%
Spanish (Spain) 76%
Russian 66%
Italian 65%
Spanish (Colombia) 65%
Spanish (Ecuador) 65%
Spanish (Venezuela) 65%
Swedish 61%
Norwegian (Bokmål) 53%
Ukrainian 52%
French (France) 45%
Croatian 43%
Bosnian 42%
Danish 42%
English (Australia) 42%
English (Canada) 42%
English (New Zealand) 42%
Greek 42%

Plus 52 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-07-24 400K+ → 300K+ down after 595 days in tier
  2. 2024-12-06 500K+ → 400K+ down after 483 days in tier
  3. 2023-08-11 600K+ → 500K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/nextgen-gallery" width="480" height="300" style="border:0" loading="lazy" title="Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery — Plugin Pulse"></iframe>
Preview card ↗

Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery: 300K+ active installs, 4.3★ (4,339 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/nextgen-gallery