Bamboo Slides Security & Risk Analysis

wordpress.org/plugins/bamboo-slides

With three different animation styles, Bamboo Slides allows you to incorporate a cool looking interactive banner or slideshow into any page – no codin …

50 active installs v1.9.8 PHP + WP 3.0.1+ Updated Mar 2, 2018
bannersshortcodesslidersslidesslideshows
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bamboo Slides Safe to Use in 2026?

Generally Safe

Score 85/100

Bamboo Slides has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "bamboo-slides" plugin v1.9.8 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the complete reliance on prepared statements for SQL queries are significant strengths. The plugin also avoids common risky practices like file operations, external HTTP requests, and the bundling of libraries. Furthermore, the attack surface is remarkably small, with no unprotected entry points detected in AJAX handlers or REST API routes. This indicates a conscientious development effort focused on minimizing potential vulnerabilities.

However, a critical weakness lies in the complete lack of output escaping. With 7 total outputs identified and 0% properly escaped, this creates a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any data processed by the plugin and then displayed to users, even if originating from trusted sources, could be manipulated to inject malicious scripts. The absence of nonce and capability checks, while less critical given the small attack surface and no unprotected entry points detected, still represents a missed opportunity to further harden the plugin, especially concerning the shortcode functionality.

In conclusion, while the plugin demonstrates good practices in areas like SQL handling and attack surface minimization, the pervasive issue of unescaped output poses a serious and direct threat. The vulnerability history being clean is positive, but it does not mitigate the immediate risk presented by the unescaped output. Addressing the output escaping is paramount to improving the plugin's security.

Key Concerns

  • 0% of outputs properly escaped
  • 0 nonce checks detected
  • 0 capability checks detected
Vulnerabilities
None known

Bamboo Slides Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bamboo Slides Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

Bamboo Slides Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bamboo-slides] bamboo-slides.php:167
WordPress Hooks 4
actioninitbamboo-slides.php:20
actionadmin_initbamboo-slides.php:83
actionsave_postbamboo-slides.php:115
actionwp_enqueue_scriptsbamboo-slides.php:146
Maintenance & Trust

Bamboo Slides Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedMar 2, 2018
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Bamboo Slides Developer Profile

Bamboo Manchester

5 plugins · 110 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bamboo Slides

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bamboo-slides/bamboo-slides.css/wp-content/plugins/bamboo-slides/jquery.velocity.min.js/wp-content/plugins/bamboo-slides/bamboo-slides.min.js
Script Paths
/wp-content/plugins/bamboo-slides/jquery.velocity.min.js/wp-content/plugins/bamboo-slides/bamboo-slides.min.js
Version Parameters
bamboo-slides/bamboo-slides.css?ver=bamboo-slides/jquery.velocity.min.js?ver=bamboo-slides/bamboo-slides.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
bamboo-slidealigned-leftaligned-centeraligned-rightvertical-aligned-topvertical-aligned-middlevertical-aligned-bottom
Data Attributes
alignmentvertical_alignmentlink_url
Shortcode Output
[bamboo-slides]
FAQ

Frequently Asked Questions about Bamboo Slides