Acquaint Slick Slider Security & Risk Analysis

wordpress.org/plugins/acquaint-slick-slider

This plugin has multiple slick images and carousel using shortcode.Its has so many customizable features.

10 active installs v1.0.0 PHP + WP 3.0.1+ Updated Jan 25, 2017
carouselgalleryimagessliderslideshow
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Acquaint Slick Slider Safe to Use in 2026?

Generally Safe

Score 85/100

Acquaint Slick Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'acquaint-slick-slider' plugin v1.0.0 presents a mixed security posture. While it demonstrates good practices in handling SQL queries with prepared statements and avoids external HTTP requests, significant concerns arise from its attack surface and code signals. The presence of an unprotected AJAX handler is a critical vulnerability, allowing unauthenticated users to potentially interact with sensitive plugin functionality. Furthermore, the use of the `unserialize` function is a known risk, as it can lead to remote code execution if data passed to it is not properly validated and sanitized. The taint analysis showing flows with unsanitized paths, though not reaching critical or high severity in this analysis, highlights a potential for vulnerabilities if these flows were to interact with dangerous functions or external input. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting the developers may be diligent, but it does not mitigate the inherent risks identified in the static analysis of this specific version. Overall, while the plugin has some strengths, the unprotected AJAX handler and the use of `unserialize` necessitate immediate attention.

Key Concerns

  • Unprotected AJAX handler
  • Dangerous function: unserialize
  • Unsanitized paths in taint flows
  • Missing nonce checks
  • Missing capability checks
  • Low output escaping coverage (42%)
Vulnerabilities
None known

Acquaint Slick Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Acquaint Slick Slider Code Analysis

Dangerous Functions
4
Raw SQL Queries
0
0 prepared
Unescaped Output
72
53 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$AQSS_Gallery_Settings = unserialize(get_post_meta( $PostId, $AQSS_Gallery_Settings_Key, true));acq-slick-slider-settings-meta-box.php:7
unserialize$AQSS_Gallery_Settings = unserialize(get_post_meta( $AQSS_Id, $AQSS_Gallery_Settings_Key, true));acq-slick-slider-short-code.php:21
unserialize$AQSS_AllPhotosDetails = unserialize(base64_decode(get_post_meta( $post->ID, 'aqs_all_photos_detailsacq-slick-slider.php:211
unserialize$RPGP_AllPhotosDetails = unserialize(base64_decode(get_post_meta( get_the_ID(), 'aqs_all_photos_detaaqss-layout.php:16

Output Escaping

42% escaped125 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ajax_get_thumbnail_aqs (acq-slick-slider.php:315)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Acquaint Slick Slider Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 1

authwp_ajax_uris_get_thumbnailacq-slick-slider.php:79

Shortcodes 2

[AQSS] acq-slick-slider-short-code.php:7
[rpggallery] acq-slick-slider.php:56
WordPress Hooks 16
actionadmin_print_scripts-post.phpacq-slick-slider.php:52
actionadmin_print_scripts-post-new.phpacq-slick-slider.php:53
actionwp_enqueue_scriptsacq-slick-slider.php:68
actionplugins_loadedacq-slick-slider.php:70
actioninitacq-slick-slider.php:71
actionadd_meta_boxesacq-slick-slider.php:73
actionadmin_initacq-slick-slider.php:74
actionsave_postacq-slick-slider.php:76
actionsave_postacq-slick-slider.php:77
filtermanage_edit-aqs_gallery_columnsacq-slick-slider.php:167
actionmanage_aqs_gallery_posts_custom_columnacq-slick-slider.php:168
actionplugins_loadedincludes\class-acq-slick-slider.php:139
actionadmin_enqueue_scriptsincludes\class-acq-slick-slider.php:154
actionadmin_enqueue_scriptsincludes\class-acq-slick-slider.php:155
actionwp_enqueue_scriptsincludes\class-acq-slick-slider.php:170
actionwp_enqueue_scriptsincludes\class-acq-slick-slider.php:171
Maintenance & Trust

Acquaint Slick Slider Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedJan 25, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Acquaint Slick Slider Developer Profile

itcoderr

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Acquaint Slick Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acquaint-slick-slider/css/slick.css/wp-content/plugins/acquaint-slick-slider/css/slick-theme.css/wp-content/plugins/acquaint-slick-slider/js/slick.js/wp-content/plugins/acquaint-slick-slider/js/aqs-multiple-media-uploader.js/wp-content/plugins/acquaint-slick-slider/js/custom.js/wp-content/plugins/acquaint-slick-slider/js/jscolor.js/wp-content/plugins/acquaint-slick-slider/css/aqs-meta.css/wp-content/plugins/acquaint-slick-slider/css/font-awesome/css/font-awesome.min.css+3 more
Script Paths
js/slick.jsjs/aqs-multiple-media-uploader.jsjs/custom.jsjs/jscolor.jsjs/aqss-color-picker.jstooltip/jquery.darktooltip.min.js
Version Parameters
acquaint-slick-slider/js/slick.js?ver=acquaint-slick-slider/js/aqs-multiple-media-uploader.js?ver=acquaint-slick-slider/js/custom.js?ver=acquaint-slick-slider/js/jscolor.js?ver=acquaint-slick-slider/js/aqss-color-picker.js?ver=

HTML / DOM Fingerprints

CSS Classes
aqs_galleryaqs-gallery-shortcode
Data Attributes
data-id
JS Globals
AQSS_TEXT_DOMAIN
Shortcode Output
[AQSS id=
FAQ

Frequently Asked Questions about Acquaint Slick Slider