
Any Post Slider Security & Risk Analysis
wordpress.org/plugins/any-post-sliderShort Description: Simple post slider plugin for WordPress.
Is Any Post Slider Safe to Use in 2026?
Mostly Safe
Score 78/100Any Post Slider is generally safe to use. 1 past CVE were resolved.
The 'any-post-slider' v1.0.5 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices, with a very high percentage of properly escaped output, no dangerous functions, no file operations, and no external HTTP requests. SQL queries are exclusively prepared, and a good number of nonce and capability checks are present. However, a significant concern arises from its attack surface. The presence of an unprotected AJAX handler represents a direct entry point that could be exploited by unauthenticated users. While taint analysis shows no immediately apparent flows, this does not entirely negate the risk associated with unprotected input points.
The plugin's vulnerability history is a substantial red flag. It has a known CVE, which is currently unpatched and classified as medium severity, specifically relating to Cross-Site Scripting (XSS). The fact that this vulnerability is recent and unaddressed strongly suggests a lack of ongoing maintenance and a heightened risk of exploitation. This, combined with the unprotected AJAX handler, paints a picture of a plugin that, despite some good internal coding practices, has critical external vulnerabilities that are not being remediated.
Key Concerns
- Unpatched Medium Severity CVE (XSS)
- Unprotected AJAX handler in attack surface
- Bundled Select2 library
Any Post Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Any Post Slider <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'post_type' Shortcode Attribute
Any Post Slider Release Timeline
Any Post Slider Code Analysis
Bundled Libraries
Output Escaping
Any Post Slider Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Any Post Slider Maintenance & Trust
Maintenance Signals
Community Trust
Any Post Slider Alternatives
Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News
blog-designer-pack
News & Blog plugin for post grid, post slider, post carousel, post filter, masonry, ticker & list category posts using shortcode, Elementor & Divi.
Post Grid
post-grid
Post Grid is a powerful WordPress plugin for creating customizable post grid layouts with advanced query options, allowing users to display posts dyna …
Ultimate Post Kit Addons for Elementor
ultimate-post-kit
Build your blogs and news sites with a feature-rich Elementor addon, offering 100+ elements for engaging layouts.
AnWP Post Grid and Post Carousel Slider for Elementor
anwp-post-grid-for-elementor
Easily create awesome post grids and post carousel sliders. Different widget types, powerful filters, "load more" button and many customizab …
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget
post-grid-carousel-ultimate
The easiest and most useful plugin to display blog posts, pages, or custom posts in beautiful post layouts like post grid, post carousel & post slider
Any Post Slider Developer Profile
13 plugins · 11K total installs
How We Detect Any Post Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/any-post-slider/admin/css/select2.min.css/wp-content/plugins/any-post-slider/admin/css/any-post-slider-admin.css/wp-content/plugins/any-post-slider/admin/js/select2.min.js/wp-content/plugins/any-post-slider/admin/js/any-post-slider-admin.js/wp-content/plugins/any-post-slider/admin/js/select2.min.js/wp-content/plugins/any-post-slider/admin/js/any-post-slider-admin.jsany-post-slider/admin/css/select2.min.css?ver=any-post-slider/admin/css/any-post-slider-admin.css?ver=any-post-slider/admin/js/select2.min.js?ver=any-post-slider/admin/js/any-post-slider-admin.js?ver=HTML / DOM Fingerprints
aps-slider-settingdata-aps-nonceaps_admin_js_obj