
Block Slider – Responsive Image Slider, Video Slider & Post Slider Security & Risk Analysis
wordpress.org/plugins/block-sliderCreate Responsive Sliders using WordPress Blocks. Image slider, video slider, YouTube slider, post slider, product slider, WooCommerce slider & more.
Is Block Slider – Responsive Image Slider, Video Slider & Post Slider Safe to Use in 2026?
Use With Caution
Score 63/100Block Slider – Responsive Image Slider, Video Slider & Post Slider has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The block-slider plugin v2.2.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries by exclusively using prepared statements, and the taint analysis shows no concerning flows. The plugin also appears to handle output escaping reasonably well, with a significant majority of outputs being properly escaped. However, there are significant concerns that overshadow these strengths. The plugin exposes a critical attack vector with a single unprotected REST API route, making it vulnerable to unauthorized access and manipulation. Furthermore, the absence of any nonce or capability checks across all entry points is a major security flaw, leaving the plugin susceptible to various attacks if a vulnerable endpoint is discovered. The vulnerability history, including a recently disclosed medium-severity CVE that remains unpatched, highlights a pattern of security weaknesses, specifically related to missing authorization, that have been present in the plugin's development. This historical context, combined with the current lack of authorization checks, suggests a recurring issue that requires immediate attention. While the plugin has some good coding habits, the identified vulnerabilities, particularly the unprotected REST API and the complete lack of authorization controls, place it at a considerable risk. The presence of an unpatched CVE further exacerbates this risk, making it imperative for users to update or mitigate the plugin's exposure.
Key Concerns
- Unprotected REST API route
- No nonce checks found
- No capability checks found
- Unpatched CVE (medium severity)
- Bundled outdated library (Freemius v1.0)
- Low output escaping rate
Block Slider – Responsive Image Slider, Video Slider & Post Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Block Slider <= 2.2.3 - Missing Authorization
Block Slider – Responsive Image Slider, Video Slider & Post Slider Release Timeline
Block Slider – Responsive Image Slider, Video Slider & Post Slider Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Block Slider – Responsive Image Slider, Video Slider & Post Slider Attack Surface
REST API Routes 1
WordPress Hooks 12
Maintenance & Trust
Block Slider – Responsive Image Slider, Video Slider & Post Slider Maintenance & Trust
Maintenance Signals
Community Trust
Block Slider – Responsive Image Slider, Video Slider & Post Slider Alternatives
Serious Slider
cryout-serious-slider
Serious Slider is a free highly efficient SEO friendly fully translatable accessibility ready image slider for WordPress. Seriously!
Slider by 10Web – Responsive Image Slider
slider-wd
Slider by 10Web plugin is the perfect slider solution for Wordpress.
Ovation Elements
ovation-elements
Transform your site with captivating sliders. Perfect for beginners and advanced users. Create and customize with our ultimate slider plugin.
MaxSlider
maxslider
MaxSlider is a free WordPress slider plugin that lets you create responsive sliders for your website. Shortcode and Visual Composer support included.
Super Simple Slider
super-simple-slider
A lightweight, easy-to-use slider plugin.
Block Slider – Responsive Image Slider, Video Slider & Post Slider Developer Profile
8 plugins · 48K total installs
How We Detect Block Slider – Responsive Image Slider, Video Slider & Post Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-slider/dist/admin/admin.js/wp-content/plugins/block-slider/dist/admin/admin.css/wp-content/plugins/block-slider/dist/frontend/frontend.js/wp-content/plugins/block-slider/dist/blocks-library/block-slider/block-slider-frontend.css/wp-content/plugins/block-slider/dist/blocks-library/block-slider/block-slider.js/wp-content/plugins/block-slider/dist/blocks-library/block-slider/block-slider-editor.css/wp-content/plugins/block-slider/blocks/block-slider/dist/admin/admin.jsdist/frontend/frontend.jsdist/blocks-library/block-slider/block-slider-frontend.cssdist/blocks-library/block-slider/block-slider.jsdist/blocks-library/block-slider/block-slider-editor.cssHTML / DOM Fingerprints
wp-block-cakewp-block-sliderdata-block-slider-idblockslider