Plugin Pulse
← Pulse

Photo Gallery by 10Web – Mobile-Friendly Image Gallery

by 10Web · Media

Also makes 7 other plugins · 223.9K+ installs across the portfolio →

Photo Gallery is a powerful image gallery plugin with a list of advanced options for creating responsive image galleries with beautiful lightbox.

How scoring works →
78 Health · B
Maintenance 100/100
Rating quality 89/100
Support 27/100

78 health vs 59 average across 2,206 Media plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

85 / 100

Excellent listing optimization

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 90/100
Listing tuning 100/100
Support resolution 10/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

+286% vs prior 30d
0Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

88.7K

now · peak 365.8K

89.5K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Photo Gallery by 10W · #291 you Photo Gallery by Foo · #299 Robo Gallery · #875 Photo Gallery by Ays · #5250

Rating trend

Star average over time · dips mark rough releases

4.5Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

895per 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

6

releases in the last 12 months

3mo ago

latest release · v1.8.42

380

tagged releases on record

Recent releases

1.8.42 · 3mo ago1.8.41 · 3mo ago1.8.40 · 4mo ago1.8.39 · 6mo ago1.8.38 · 7mo ago1.8.37 · 7mo ago1.8.35 · 1.4y ago1.8.34 · 1.5y ago1.8.33 · 1.5y ago1.8.31 · 1.8y ago1.8.30 · 1.9y ago1.8.29 · 1.9y ago1.8.28 · 2.0y agoVersion1.8.27 · 2.1y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 79% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v1.8 79%
v1.5 11%
Older / other versions 10%

Estimated active installs

The public count shows “100K+”. Our estimate pins where the real number sits.

tracked estimate
100K–200K ≈150K

Refined from the date this plugin crossed into its current band.

Install history · since 2015-08-13 · 1,500 observations

100KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.

Details

Version
1.8.43
Last updated
18d ago
Added
2014-01-30 · 12 yrs old
Requires WP
4.6
Tested up to
7.0.4
Requires PHP

Recent reviews

All reviews on wp.org ↗
  1. matzomanik
    5mo ago

    Die Einstellungsmöglichkeiten für die Galerie sowie auch die Lightbox sind in der kostenlosen Version recht umfangreich. Es lässt sich sogar für die Bilder auch ein Rechtsklick-Schutz sowie ein Wasserzeichen als Text oder Bild (png) einstellen. Das Design ist z.T. nicht ganz aktuell, lässt sich jedoch alles einstellen und anpassen. Das bedeutet jedoch dann etwas Aufwand oder man deaktiviert z.B. in der Lightbox einige Funktionen um einfacher und auch schicker zu halten. This topic was modified 4 months, 1 week ago by matzomanik.

    Read on wp.org ↗
  2. Malae
    6mo ago

    Support issues about PHP notices are dismissed and PHP warnings are not answered.

    Read on wp.org ↗
  3. ludwigarcache
    6mo ago

    What should be simple is overly complicated. The UI is confusing and basic gallery setup takes far too many steps. Not user-friendly at all.

    Read on wp.org ↗
  4. shumustudios
    8mo ago

    I’ve discovered this plugin in 2018 (I think). Now I rebuilt my website, glad to see the plugin is still awesome 😀

    Read on wp.org ↗
  5. megalitosmyr
    9mo ago

    UN plugin sencillo y práctico para crear galerías fotográficas.

    Read on wp.org ↗
  6. powerphot
    11mo ago

    Thank you!

    Read on wp.org ↗
  7. dejanikolic
    11mo ago

    can we expect an update from photogallery soon, it hasn’t been for a long time, and it’s causing me a conflict with the Photograph theme, it’s creating a wrong sitemap

    Read on wp.org ↗
  8. Tomperys
    11mo ago

    Sadly the new developers (after the plugin was bought by 10web) are forcing you to use their lightbox as a fixed component. The original Gallery plugin before 10web took it over, allowed you to use our own lightbox. Well, I had to cancel my subscription and I will find another photo gallery plugin. They dont even care about paying customers….

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 1.8.42 Fixed: Security fix. 1.8.42
  2. Version 1.8.41 Fixed: Security fix. 1.8.41
  3. Version 1.8.40 Fixed: Security fix. 1.8.40
  4. Version 1.8.39 Fixed: Security fix. 1.8.39
  5. Version 1.8.38 Fixed: Security fix. 1.8.38
  6. Version 1.8.37 Fixed: Security fix. 1.8.37

Known vulnerabilities

via Wordfence Intelligence

65 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-06-05 CVE-2026-9829 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.8.41 Patched in 1.8.42
  2. 2026-06-04 CVE-2026-49771 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.8.41 Patched in 1.8.42
  3. 2026-05-27 CVE-2026-7048 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.8.40 Patched in 1.8.41
  4. 2026-02-08 CVE-2026-32330 Cross-Site Request Forgery (CSRF) Affects <= 1.8.37 Patched in 1.8.38
  5. 2026-01-21 CVE-2026-1036 Missing Authorization Affects <= 1.8.36 Patched in 1.8.37
  6. 2025-12-25 CVE-2026-27360 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.38 Patched in 1.8.39
  7. 2025-04-11 CVE-2025-2269 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.34 Patched in 1.8.35
  8. 2025-03-10 CVE-2025-0613 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.33 Patched in 1.8.34
  9. 2025-03-02 CVE-2024-13124 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.32 Patched in 1.8.33
  10. 2024-11-14 CVE-2024-10704 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.30 Patched in 1.8.31
  11. 2024-11-04 CVE-2024-9878 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.30 Patched in 1.8.31
  12. 2024-10-03 CVE-2024-8670 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.28 Patched in 1.8.29
  13. 2024-09-23 CVE-2024-44043 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.27 Patched in 1.8.28
  14. 2024-06-06 CVE-2024-5481 Path Traversal: '.../...//' Affects <= 1.8.23 Patched in 1.8.24
  15. 2024-06-06 CVE-2024-5426 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.23 Patched in 1.8.24
  16. 2024-05-27 CVE-2024-35628 Missing Authorization Affects <= 1.8.25 Patched in 1.8.26
  17. 2024-04-25 CVE-2024-33586 Missing Authorization Affects <= 1.8.20 Patched in 1.8.21
  18. 2024-04-05 CVE-2024-2296 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.21 Patched in 1.8.22
  19. 2024-03-26 CVE-2024-29809 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.21 Patched in 1.8.22
  20. 2024-03-26 CVE-2024-29832 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.21 Patched in 1.8.22
  21. 2024-03-26 CVE-2024-29808 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.21 Patched in 1.8.22
  22. 2024-03-26 CVE-2024-29810 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.21 Patched in 1.8.22
  23. 2024-01-19 CVE-2024-0221 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 1.8.19 Patched in 1.8.20
  24. 2023-12-21 CVE-2023-6924 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.18 Patched in 1.8.19
  25. 2023-06-02 CVE-2023-33995 Missing Authorization Affects < 1.8.16 Patched in 1.8.16
  26. 2023-03-21 CVE-2023-1427 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 1.8.14 Patched in 1.8.15
  27. 2022-11-28 CVE-2022-4058 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.2 Patched in 1.8.3
  28. 2022-11-26 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 1.8.7 Patched in 1.8.8
  29. 2022-11-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.0 Patched in 1.8.1
  30. 2022-08-10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.7.0 Patched in 1.7.1
  31. 2022-07-01 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.6.8 Patched in 1.6.9
  32. 2022-06-28 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.6.7 Patched in 1.6.8
  33. 2022-06-16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.6.6 Patched in 1.6.7
  34. 2022-05-16 CVE-2022-1394 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.6.4 Patched in 1.6.4
  35. 2022-04-11 CVE-2022-1281 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.6.3 Patched in 1.6.3
  36. 2022-04-11 CVE-2022-1282 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.6.3 Patched in 1.6.3
  37. 2022-02-15 CVE-2022-0169 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.6.0 Patched in 1.6.0
  38. 2021-07-19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.5.78 Patched in 1.5.79
  39. 2021-07-18 CVE-2021-24363 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 1.5.75 Patched in 1.5.75
  40. 2021-07-18 CVE-2021-24362 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.5.75 Patched in 1.5.75
  41. 2021-05-12 CVE-2021-24310 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.5.67 Patched in 1.5.67
  42. 2021-04-19 CVE-2021-46889 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.5.68 Patched in 1.5.69
  43. 2021-04-19 CVE-2021-24291 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.5.69 Patched in 1.5.69
  44. 2021-04-19 CVE-2021-31693 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.5.68 Patched in 1.5.69
  45. 2021-02-23 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.5.68 Patched in 1.5.69
  46. 2021-02-03 CVE-2021-25041 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.5.68 Patched in 1.5.68
  47. 2020-05-15 CVE-2021-24139 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.5.55 Patched in 1.5.55
  48. 2020-02-25 CVE-2020-9335 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.5.45 Patched in 1.5.46
  49. 2019-09-08 CVE-2019-16118 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.5.34 Patched in 1.5.35
  50. 2019-09-08 CVE-2019-16119 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.5.35 Patched in 1.5.35
  51. 2019-09-08 CVE-2019-16117 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.5.35 Patched in 1.5.35
  52. 2019-07-26 CVE-2019-14313 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.5.31 Patched in 1.5.31
  53. 2019-05-15 CVE-2019-14798 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 1.5.24 Patched in 1.5.25
  54. 2019-05-13 CVE-2019-14797 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.5.22 Patched in 1.5.23
  55. 2017-12-14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.3.67 Patched in 1.3.67
  56. 2017-08-20 CVE-2017-12977 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.3.51 Patched in 1.3.51
  57. 2017-06-16 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 1.3.43 Patched in 1.3.43
  58. 2017-05-02 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.3.38 Patched in 1.3.38
  59. 2015-03-13 CVE-2015-2324 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.2.13 Patched in 1.2.13
  60. 2015-02-12 CVE-2014-9312 Unrestricted Upload of File with Dangerous Type Affects < 1.2.6 Patched in 1.2.6
  61. 2015-01-28 CVE-2015-1394 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.2.11 Patched in 1.2.11
  62. 2015-01-23 CVE-2015-1393 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.2.11 Patched in 1.2.11
  63. 2015-01-12 CVE-2015-1055 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.2.8 Patched in 1.2.8
  64. 2014-10-01 CVE-2014-6315 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.1.30 Patched in 1.1.31
  65. 2014-05-07 CVE-2015-9380 Cross-Site Request Forgery (CSRF) Affects < 1.2.42 Patched in 1.2.42

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 62 languages, 9 at 90% or more

Dutch 100%
Dutch (Formal) 100%
Polish 100%
Russian 97%
Spanish (Chile) 90%
Spanish (Colombia) 90%
Spanish (Ecuador) 90%
Spanish (Spain) 90%
Spanish (Venezuela) 90%
Spanish (Mexico) 89%
French (France) 48%
Swedish 42%
English (Australia) 33%
Dutch (Belgium) 21%
Ukrainian 21%
German 17%
English (New Zealand) 13%
Italian 12%
German (Switzerland) 10%
Czech 6%
Hindi 4%
Arabic 3%
Azerbaijani 3%
Catalan 3%

Plus 38 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-06-15 200K+ → 100K+ down after 1255 days in tier
  2. 2023-01-07 300K+ → 200K+ down after 3 days in tier
  3. 2023-01-04 200K+ → 300K+ up after 1 days in tier
  4. 2023-01-03 300K+ → 200K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Photo Gallery by 10Web – Mobile-Friendly Image Gallery into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/photo-gallery" width="480" height="300" style="border:0" loading="lazy" title="Photo Gallery by 10Web – Mobile-Friendly Image Gallery — Plugin Pulse"></iframe>
Preview card ↗

Photo Gallery by 10Web – Mobile-Friendly Image Gallery: 100K+ active installs, 4.5★ (1,581 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/photo-gallery