{"id":333252,"date":"2026-07-06T18:26:41","date_gmt":"2026-07-06T18:26:41","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/aura-gallery\/"},"modified":"2026-09-18T23:03:28","modified_gmt":"2026-09-18T23:03:28","slug":"square-orb","status":"publish","type":"plugin","link":"https:\/\/kin.wordpress.org\/plugins\/square-orb\/","author":18577422,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.2","stable_tag":"1.1.2","tested":"7.1.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Square Orb","header_author":"writetimothyjohnson","header_description":"Media Gallery with Cloud Import.","assets_banners_color":"453d5c","last_updated":"2026-09-18 23:03:28","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/ko-fi.com\/timothyjohnson618","header_plugin_uri":"https:\/\/awesomediscoveryzone.com\/squareorb\/","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":418,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"writetimothyjohnson","date":"2026-07-06 19:44:08","revision":3598277},"1.1.0":{"tag":"1.1.0","author":"writetimothyjohnson","date":"2026-08-14 04:17:17","revision":3646593},"1.1.1":{"tag":"1.1.1","author":"writetimothyjohnson","date":"2026-09-08 03:31:30","revision":3685830},"1.1.2":{"tag":"1.1.2","author":"writetimothyjohnson","date":"2026-09-18 23:03:28","revision":3702841}},"upgrade_notice":{"1.1.2":"<p>Security hardening and performance update: adds at-rest credential encryption, SSRF protection, CSV formula injection defense, DOM XSS hardening, and local watermark optimization.<\/p>","1.1.1":"<p>Updated plugin links to newly launched documentation site.<\/p>","1.1.0":"<p>Bug fixes, plus performance and accessibility improvements.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3598190,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3598190,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3598190,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3598190,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3598190,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{"blueprint.json":{"filename":"blueprint.json","revision":3702841,"resolution":false,"location":"assets","locale":"","contents":"{\"landingPage\":\"\\\/wp-admin\\\/admin.php?page=square-orb\",\"preferredVersions\":{\"php\":\"8.2\",\"wp\":\"latest\"},\"phpExtensionBundles\":[\"kitchen-sink\"],\"steps\":[{\"step\":\"login\",\"username\":\"admin\",\"password\":\"password\"},{\"step\":\"installPlugin\",\"pluginData\":{\"resource\":\"wordpress.org\\\/plugins\",\"slug\":\"square-orb\"},\"options\":{\"activate\":true}}]}"}},"all_blocks":{"square-orb\/gallery":{"name":"square-orb\/gallery","title":"Square Orb Canvas"}},"tagged_versions":["1.0.0","1.1.0","1.1.1","1.1.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3598190,"resolution":"1","location":"assets","locale":"","width":3144,"height":1984},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3598190,"resolution":"2","location":"assets","locale":"","width":3144,"height":1968},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3598190,"resolution":"3","location":"assets","locale":"","width":3144,"height":8992},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3598190,"resolution":"4","location":"assets","locale":"","width":3144,"height":1968},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3598190,"resolution":"5","location":"assets","locale":"","width":3144,"height":1968}},"screenshots":{"1":"Gallery Grid layout with smart search and category filters.","2":"Full-screen Lightbox with filmstrip, EXIF data, and social sharing.","3":"Global Defaults settings panel.","4":"Cloud import via Google Photos Picker.","5":"Analytics dashboard with engagement telemetry."}},"plugin_section":[],"plugin_tags":[1220,210,604,237,649],"plugin_category":[50],"plugin_contributors":[270378],"plugin_business_model":[],"class_list":["post-333252","plugin","type-plugin","status-publish","hentry","plugin_tags-block","plugin_tags-gallery","plugin_tags-image-gallery","plugin_tags-lightbox","plugin_tags-photo-gallery","plugin_category-media","plugin_contributors-writetimothyjohnson","plugin_committers-writetimothyjohnson"],"banners":{"banner":"https:\/\/ps.w.org\/square-orb\/assets\/banner-772x250.png?rev=3598190","banner_2x":"https:\/\/ps.w.org\/square-orb\/assets\/banner-1544x500.png?rev=3598190","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/square-orb\/assets\/icon.svg?rev=3598190","icon":"https:\/\/ps.w.org\/square-orb\/assets\/icon.svg?rev=3598190","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/square-orb\/assets\/screenshot-1.png?rev=3598190","caption":"Gallery Grid layout with smart search and category filters."},{"src":"https:\/\/ps.w.org\/square-orb\/assets\/screenshot-2.png?rev=3598190","caption":"Full-screen Lightbox with filmstrip, EXIF data, and social sharing."},{"src":"https:\/\/ps.w.org\/square-orb\/assets\/screenshot-3.png?rev=3598190","caption":"Global Defaults settings panel."},{"src":"https:\/\/ps.w.org\/square-orb\/assets\/screenshot-4.png?rev=3598190","caption":"Cloud import via Google Photos Picker."},{"src":"https:\/\/ps.w.org\/square-orb\/assets\/screenshot-5.png?rev=3598190","caption":"Analytics dashboard with engagement telemetry."}],"raw_content":"<!--section=description-->\n<p>Check out the <a href=\"https:\/\/awesomediscoveryzone.com\/squareorb\/demo-galleries\/\">live demos<\/a> and <a href=\"https:\/\/squareorb-docs.awesomediscoveryzone.com\/\">full documentation<\/a> on the official Square Orb site.<\/p>\n\n<p>Square Orb is a gallery plugin for WordPress. Display images and videos in responsive galleries with a full-screen lightbox experience, cloud import from Google Photos and Adobe Lightroom, and an optional engagement analytics dashboard.<\/p>\n\n<p><strong>Key Features:<\/strong><\/p>\n\n<ul>\n<li>5 layout options: Grid, Masonry, Justified Row, Carousel, and Interactive Map<\/li>\n<li>Full-screen lightbox with 11 transition styles, slideshow, filmstrip, EXIF data, and social sharing<\/li>\n<li>Dynamic Gutenberg block inspector \u2014 settings automatically show\/hide based on the selected layout<\/li>\n<li>Cloud media import from Google Photos and Adobe Lightroom<\/li>\n<li>Smart search and category filter system<\/li>\n<li>Drag-and-drop media reordering in the block editor<\/li>\n<li>Watermarking engine with auto-stamp on upload<\/li>\n<li>Optional engagement analytics dashboard (opt-in, off by default)<\/li>\n<li>Gutenberg block and shortcode (<code>[square_orb ids=\"1,2,3\"]<\/code>) support<\/li>\n<li>Transient caching for high-performance page delivery<\/li>\n<\/ul>\n\n<p><strong>External Services<\/strong><\/p>\n\n<p>This plugin optionally connects to the following third-party services. These connections are only established when you actively configure and use the corresponding features.<\/p>\n\n<ul>\n<li><p><strong>Google Photos API<\/strong> \u2014 Used to authenticate your Google account and import media items into your WordPress Media Library. Data transmitted: OAuth 2.0 authorization codes and access tokens issued by Google. <a href=\"https:\/\/policies.google.com\/privacy\">Google Privacy Policy<\/a> | <a href=\"https:\/\/policies.google.com\/terms\">Google Terms of Service<\/a><\/p><\/li>\n<li><p><strong>Google Vision API<\/strong> \u2014 Used optionally to auto-tag imported images via AI label detection. Data transmitted: Base64-encoded image content sent to Google's Vision API. This feature requires a separate Google Cloud API key and is disabled by default. <a href=\"https:\/\/policies.google.com\/privacy\">Google Privacy Policy<\/a><\/p><\/li>\n<li><p><strong>Adobe Lightroom API<\/strong> \u2014 Used to authenticate your Adobe account and import media from Adobe Lightroom into your WordPress Media Library. Data transmitted: OAuth 2.0 authorization codes and access tokens issued by Adobe. <a href=\"https:\/\/www.adobe.com\/privacy\/policy.html\">Adobe Privacy Policy<\/a> | <a href=\"https:\/\/www.adobe.com\/legal\/terms.html\">Adobe Terms of Service<\/a><\/p><\/li>\n<li><p><strong>Leaflet.js (Bundled locally)<\/strong> \u2014 Used to render the Interactive Map gallery layout. The JavaScript and CSS assets are bundled directly within the plugin's assets directory; no third-party CDN or external service is contacted. <a href=\"https:\/\/leafletjs.com\/\">Leaflet<\/a><\/p><\/li>\n<li><p><strong>Chart.js (Bundled locally)<\/strong> \u2014 Used to render the analytics chart on the admin Analytics tab. The JavaScript asset is bundled directly within the plugin's assets directory; no third-party CDN or external service is contacted. <a href=\"https:\/\/www.chartjs.org\/\">Chart.js<\/a><\/p><\/li>\n<li><p><strong>Engagement Telemetry<\/strong> \u2014 Off by default. When explicitly enabled by the site administrator in Square Orb \u2192 Global \u2192 Enable Engagement Telemetry, the plugin records anonymous view counts and dwell times per gallery image. All data is stored locally in your WordPress database only. No data is transmitted to any external server. No personally identifiable information (PII) is ever collected.<\/p><\/li>\n<\/ul>\n\n<h3>Quick Start<\/h3>\n\n<p>A simple first gallery is usually just a few images from your Media Library. Start with the default grid layout, choose a few images, and publish the page. If you want a more curated experience later, add filters, smart search, or cloud imports.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>square-orb<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install directly through the WordPress Plugins screen.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> menu in WordPress.<\/li>\n<li>Navigate to <strong>Square Orb<\/strong> in the admin sidebar to configure global display settings.<\/li>\n<li>To import from Google Photos or Adobe Lightroom, enter your API credentials on the <strong>Authentication<\/strong> tab.<\/li>\n<li>Insert the Square Orb block in the Gutenberg editor, or use the shortcode: <code>[square_orb ids=\"1,2,3\"]<\/code>.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20set%20up%20google%20photos%20import%3F\"><h3>How do I set up Google Photos import?<\/h3><\/dt>\n<dd><p>Navigate to <strong>Square Orb \u2192 Authentication<\/strong>, enter your Google OAuth Client ID and Secret, then click \"Connect to Google Photos\". See the <a href=\"https:\/\/squareorb-docs.awesomediscoveryzone.com\/cloud-integration\/create-a-google-oauth-client-id-and-secret\/\">full step-by-step Google Photos setup guide<\/a> on our documentation portal.<\/p><\/dd>\n<dt id=\"how%20do%20i%20set%20up%20adobe%20lightroom%20import%3F\"><h3>How do I set up Adobe Lightroom import?<\/h3><\/dt>\n<dd><p>Navigate to <strong>Square Orb \u2192 Authentication<\/strong>, enter your Adobe Client ID and Secret, then click \"Connect to Lightroom\".<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20collect%20any%20user%20data%3F\"><h3>Does this plugin collect any user data?<\/h3><\/dt>\n<dd><p>No, by default. The engagement telemetry system is <strong>off by default<\/strong> and must be explicitly enabled by the site administrator in Square Orb \u2192 Global \u2192 Enable Engagement Telemetry. When enabled, it records anonymous view counts and dwell times per gallery image, stored locally in your WordPress database only. No data is ever transmitted to any external server, and no personally identifiable information (PII) is collected.<\/p><\/dd>\n<dt id=\"can%20i%20use%20the%20gallery%20on%20multiple%20pages%3F\"><h3>Can I use the gallery on multiple pages?<\/h3><\/dt>\n<dd><p>Yes. Each Gutenberg block or shortcode instance is independently configured. You can also enable the \"Enforce Central Global Uniformity\" switch on the Global Defaults tab to apply the same styling across all gallery instances site-wide.<\/p><\/dd>\n<dt id=\"how%20do%20i%20display%20the%20gallery%20on%20archive%20or%20shop%20pages%3F\"><h3>How do I display the gallery on archive or shop pages?<\/h3><\/dt>\n<dd><p>Use the <code>square_orb_enqueue_assets<\/code> filter to force asset enqueuing on non-singular pages:<\/p>\n\n<pre><code>add_filter( 'square_orb_enqueue_assets', '__return_true' );\n<\/code><\/pre><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>Security: Added authenticated at-rest encryption (AES-256-CBC with HMAC-SHA256) for stored OAuth access tokens, refresh tokens, client secrets, and API keys.<\/li>\n<li>Security: Disabled option autoloading for all sensitive credentials to eliminate memory exposure on frontend requests.<\/li>\n<li>Security: Added strict host whitelist validation for Google Photos import URLs to prevent SSRF and token exfiltration.<\/li>\n<li>Security: Added binary MIME type verification for cloud imported media prior to file creation and media library sideloading.<\/li>\n<li>Security: Masked client secrets and API keys in the admin authentication tab to prevent shoulder surfing and DOM scraping.<\/li>\n<li>Security: Scoped client-side access token passing exclusively to the Cloud Import tab for authorized users.<\/li>\n<li>Security: Sanitized analytics CSV export against CSV formula injection (CWE-1236).<\/li>\n<li>Security: Hardened lightbox video embeds and Leaflet map markers against DOM XSS via safe DOM construction and protocol validation.<\/li>\n<li>Performance: Optimized watermark image stamping to resolve local upload paths directly from the filesystem, avoiding redundant HTTP loopback requests.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Updated links within the plugin to point to a newly launched support site with complete documentation.<\/li>\n<\/ul>","raw_excerpt":"A feature-rich gallery block with lightbox, cloud import, smart search, and analytics.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/kin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/333252","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/kin.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/kin.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=333252"}],"author":[{"embeddable":true,"href":"https:\/\/kin.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/writetimothyjohnson"}],"wp:attachment":[{"href":"https:\/\/kin.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=333252"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/kin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=333252"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/kin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=333252"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/kin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=333252"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/kin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=333252"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/kin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=333252"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}