
Image Slider by Ays- Responsive Slider and Carousel Security & Risk Analysis
wordpress.org/plugins/ays-sliderAys image slider is a progressive slider plugin, which is a great way to grab your audience's attention with amazing and entertaining slideshows.
Is Image Slider by Ays- Responsive Slider and Carousel Safe to Use in 2026?
Generally Safe
Score 90/100Image Slider by Ays- Responsive Slider and Carousel has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The ays-slider v2.7.2 plugin exhibits a mixed security posture, with some positive attributes but significant areas of concern. While the plugin demonstrates good practices by utilizing prepared statements for the majority of its SQL queries and incorporating numerous nonce and capability checks, the presence of multiple unprotected AJAX handlers significantly expands its attack surface. The taint analysis, while not revealing critical or high severity vulnerabilities, did identify two flows with unsanitized paths, which warrants further investigation for potential privilege escalation or information disclosure if these paths can be manipulated by an attacker. The plugin's vulnerability history is concerning, with three known CVEs including a high-severity SQL injection vulnerability and medium-severity CSRF and XSS issues. Although no CVEs are currently unpatched, the recurring nature of these vulnerability types suggests a pattern of insecure input handling or insufficient protection against common web attacks. The last vulnerability being so recent further emphasizes the need for ongoing vigilance.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- High severity vulnerability in history
- Medium severity vulnerabilities in history
- Low percentage of properly escaped output
Image Slider by Ays- Responsive Slider and Carousel Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Image Slider by Ays- Responsive Slider and Carousel <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting
Image Slider by Ays <= 2.7.1 - Missing Authorization
Image Slider by Ays- Responsive Slider and Carousel <= 2.7.0 - Cross-Site Request Forgery to Arbitrary Slider Deletion
Image Slider by Ays- Responsive Slider and Carousel < 2.5.0 - SQL Injection
Image Slider by Ays- Responsive Slider and Carousel <= 2.4.9 - Reflected Cross-Site Scripting
Image Slider by Ays- Responsive Slider and Carousel Release Timeline
Image Slider by Ays- Responsive Slider and Carousel Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Image Slider by Ays- Responsive Slider and Carousel Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Image Slider by Ays- Responsive Slider and Carousel Maintenance & Trust
Maintenance Signals
Community Trust
Image Slider by Ays- Responsive Slider and Carousel Alternatives
Ultimate Responsive Image Slider
ultimate-responsive-image-slider
Create stunning responsive sliders in minutes. Drag-and-drop builder, unlimited sliders, mobile-friendly & SEO optimized!
Serious Slider
cryout-serious-slider
Serious Slider is a free highly efficient SEO friendly fully translatable accessibility ready image slider for WordPress. Seriously!
Slider by 10Web – Responsive Image Slider
slider-wd
Slider by 10Web plugin is the perfect slider solution for Wordpress.
Ovation Elements
ovation-elements
Transform your site with captivating sliders. Perfect for beginners and advanced users. Create and customize with our ultimate slider plugin.
WP Slick Slider and Image Carousel
wp-slick-slider-and-image-carousel
A quick, easy way to add and display multiple WP Slick Slider and carousel using a shortcode. Also added Gutenberg block support.
Image Slider by Ays- Responsive Slider and Carousel Developer Profile
18 plugins · 111K total installs
How We Detect Image Slider by Ays- Responsive Slider and Carousel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ays-slider/admin/css/jquery.atwho.css/wp-content/plugins/ays-slider/admin/css/minicolors.css/wp-content/plugins/ays-slider/admin/css/site-settings.css/wp-content/plugins/ays-slider/admin/css/style.css/wp-content/plugins/ays-slider/admin/js/admin.js/wp-content/plugins/ays-slider/admin/js/bootstrap.min.js/wp-content/plugins/ays-slider/admin/js/colorpicker.js/wp-content/plugins/ays-slider/admin/js/jquery.atwho.js+21 more/wp-content/plugins/ays-slider/admin/js/admin.js/wp-content/plugins/ays-slider/admin/js/bootstrap.min.js/wp-content/plugins/ays-slider/admin/js/colorpicker.js/wp-content/plugins/ays-slider/admin/js/jquery.atwho.js/wp-content/plugins/ays-slider/admin/js/jquery.colorbox-min.js/wp-content/plugins/ays-slider/admin/js/jquery.jplayer.min.js+16 moreHTML / DOM Fingerprints
ays-notice-bannerays-logo-container-upgradesld-logoays-upgrade-containerays-sld-logo-container-one-time-textays-btnays-fa-margin-righttoggle_ddmenu+1 moredata-expandedAYS_SLD_ADMIN_URLAYS_SLD_PUBLIC_URL