Any Post Slider Security & Risk Analysis

wordpress.org/plugins/any-post-slider

Short Description: Simple post slider plugin for WordPress.

50 active installs v1.0.5 PHP 8.0+ WP 6.0+ Updated Mar 24, 2026
carouselcustom-post-type-sliderspost-gridpost-sliderssliders
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEMar 20, 2026
Safety Verdict

Is Any Post Slider Safe to Use in 2026?

Mostly Safe

Score 78/100

Any Post Slider is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Mar 20, 2026Updated 1mo ago
Risk Assessment

The 'any-post-slider' v1.0.5 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices, with a very high percentage of properly escaped output, no dangerous functions, no file operations, and no external HTTP requests. SQL queries are exclusively prepared, and a good number of nonce and capability checks are present. However, a significant concern arises from its attack surface. The presence of an unprotected AJAX handler represents a direct entry point that could be exploited by unauthenticated users. While taint analysis shows no immediately apparent flows, this does not entirely negate the risk associated with unprotected input points.

The plugin's vulnerability history is a substantial red flag. It has a known CVE, which is currently unpatched and classified as medium severity, specifically relating to Cross-Site Scripting (XSS). The fact that this vulnerability is recent and unaddressed strongly suggests a lack of ongoing maintenance and a heightened risk of exploitation. This, combined with the unprotected AJAX handler, paints a picture of a plugin that, despite some good internal coding practices, has critical external vulnerabilities that are not being remediated.

Key Concerns

  • Unpatched Medium Severity CVE (XSS)
  • Unprotected AJAX handler in attack surface
  • Bundled Select2 library
Vulnerabilities
1 published

Any Post Slider Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-1899medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Any Post Slider <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'post_type' Shortcode Attribute

Mar 20, 2026Unpatched
Version History

Any Post Slider Release Timeline

v1.0.5Current1 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Apr 16, 2026

Any Post Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
373 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

99% escaped378 total outputs
Attack Surface
1 unprotected

Any Post Slider Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_aps_get_terms_by_post_typeincludes/class-any-post-slider.php:186

Shortcodes 1

[aps_slider] public/class-any-post-slider-public.php:113
WordPress Hooks 11
actionplugins_loadedincludes/class-any-post-slider.php:163
actionadmin_enqueue_scriptsincludes/class-any-post-slider.php:178
actionadmin_enqueue_scriptsincludes/class-any-post-slider.php:179
actionsave_postincludes/class-any-post-slider.php:180
actionadd_meta_boxesincludes/class-any-post-slider.php:182
actioninitincludes/class-any-post-slider.php:183
actionmanage_any_post_slider_posts_custom_columnincludes/class-any-post-slider.php:184
filtermanage_any_post_slider_posts_columnsincludes/class-any-post-slider.php:185
actionwp_enqueue_scriptsincludes/class-any-post-slider.php:201
actionwp_enqueue_scriptsincludes/class-any-post-slider.php:202
actioninitincludes/class-any-post-slider.php:203
Maintenance & Trust

Any Post Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 24, 2026
PHP min version8.0
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

Any Post Slider Developer Profile

IT Path Solutions

13 plugins · 11K total installs

80
trust score
Avg Security Score
89/100
Avg Patch Time
77 days
View full developer profile
Detection Fingerprints

How We Detect Any Post Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/any-post-slider/admin/css/select2.min.css/wp-content/plugins/any-post-slider/admin/css/any-post-slider-admin.css/wp-content/plugins/any-post-slider/admin/js/select2.min.js/wp-content/plugins/any-post-slider/admin/js/any-post-slider-admin.js
Script Paths
/wp-content/plugins/any-post-slider/admin/js/select2.min.js/wp-content/plugins/any-post-slider/admin/js/any-post-slider-admin.js
Version Parameters
any-post-slider/admin/css/select2.min.css?ver=any-post-slider/admin/css/any-post-slider-admin.css?ver=any-post-slider/admin/js/select2.min.js?ver=any-post-slider/admin/js/any-post-slider-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
aps-slider-setting
Data Attributes
data-aps-nonce
JS Globals
aps_admin_js_obj
FAQ

Frequently Asked Questions about Any Post Slider