Before After Image Slider (AMP) Security & Risk Analysis

wordpress.org/plugins/before-after-image-slider-amp

This plugin makes it easy to create a before and after image comparison slider, using AMP technology. It's a quick method of implementing the rel …

10 active installs v1.0.0 PHP + WP 4.0+ Updated Unknown
amp-image-sliderbefore-aftercomparisionimage-comparepre-after
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Before After Image Slider (AMP) Safe to Use in 2026?

Generally Safe

Score 100/100

Before After Image Slider (AMP) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "before-after-image-slider-amp" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by not utilizing dangerous functions, file operations, or external HTTP requests. All SQL queries are properly prepared, and all output is correctly escaped, indicating a commitment to preventing common web vulnerabilities. The absence of any recorded CVEs further reinforces its current secure state.

However, there are a few areas that warrant attention. The plugin lacks nonce checks and capability checks on its entry points. While the attack surface appears limited to a single shortcode and there are no unprotected AJAX handlers or REST API routes, the absence of these checks means that any user, regardless of their role or privilege level, could potentially trigger the functionality of the shortcode. This is a potential concern, as it could lead to unintended actions or information disclosure if the shortcode's execution involves sensitive operations or data.

Taint analysis shows no identified issues, which is a positive indicator. The vulnerability history is also clean, suggesting consistent security focus from the developers or a lack of historical issues. Despite the lack of nonce and capability checks being a notable weakness, the overall security of this plugin appears to be good due to its adherence to other security best practices and its clean vulnerability history. The developers should consider implementing nonce and capability checks to further harden the plugin.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Before After Image Slider (AMP) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Before After Image Slider (AMP) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped17 total outputs
Attack Surface

Before After Image Slider (AMP) Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[jozz-ampimageslider] index.php:84
WordPress Hooks 4
actionadmin_menuindex.php:14
actionadmin_initindex.php:25
actionwp_enqueue_scriptsindex.php:91
actionadmin_enqueue_scriptsindex.php:108
Maintenance & Trust

Before After Image Slider (AMP) Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.0
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Before After Image Slider (AMP) Developer Profile

James Osborne

3 plugins · 120 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Before After Image Slider (AMP)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/before-after-image-slider-amp/css/style.css
Script Paths
/wp-content/plugins/before-after-image-slider-amp/media-uploader.js

HTML / DOM Fingerprints

CSS Classes
amp-image-slider
Data Attributes
data-custom-attribute-for-amp-image-slider-id
JS Globals
jozzampimageslider_media_uploader_enqueuejozzampimageslider_plugin_settings_linkjozzampimageslider_shortcodejozzampimageslider_custom_settings_startjozzampimageslider_field
Shortcode Output
<amp-image-slider<amp-img
FAQ

Frequently Asked Questions about Before After Image Slider (AMP)