
Boot Slider Security & Risk Analysis
wordpress.org/plugins/boot-sliderBootstrap 5 Slider with customize and awosome ui/ux. Wordpress Full functional. Use Shortcode [boot_slider id=" "] or [boot_slider id=" …
Is Boot Slider Safe to Use in 2026?
Generally Safe
Score 100/100Boot Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "boot-slider" plugin v1.0.1 exhibits a mixed security posture. On the positive side, the plugin does not appear to have any known CVEs in its history, suggesting a generally stable past regarding public vulnerabilities. Furthermore, all detected SQL queries utilize prepared statements, a critical security best practice that mitigates SQL injection risks. The absence of file operations and external HTTP requests also reduces potential attack vectors. However, a significant concern arises from the static analysis indicating that 100% of the 13 output instances are not properly escaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the WordPress environment, impacting users who interact with the plugin's output.
The plugin's attack surface is relatively small with only two entry points (shortcodes) and no unprotected ones. Taint analysis also shows no critical or high-severity issues, which is encouraging. The lack of nonce checks and capability checks, while not ideal, is somewhat mitigated by the limited and seemingly protected entry points. The primary vulnerability lies in the unescaped output, which is a pervasive and potentially severe risk that requires immediate attention. While the plugin has no recorded vulnerability history, this can sometimes indicate a lack of rigorous security testing or obscurity rather than inherent security. Therefore, the plugin's strengths in SQL handling and limited attack surface are overshadowed by the critical flaw of unescaped output.
Key Concerns
- Output is not properly escaped
- Missing nonce checks
- Missing capability checks
Boot Slider Security Vulnerabilities
Boot Slider Release Timeline
Boot Slider Code Analysis
Output Escaping
Boot Slider Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
Boot Slider Maintenance & Trust
Maintenance Signals
Community Trust
Boot Slider Alternatives
Advanced Login Form
advanced-login-form
Advanced Login Form is a more customize wordpress plugin that use for wordpress login page. It also style register and forget password page.
AS Scroll to top
as-scroll-to-top
This plugin will add a nice scroll to top button to your website. It has a nice option panel. you can change button's color button's icon.
Colored Titles for each Post Type
colored-titles-for-each-post-type
This plugin is build to to choose custom colors for each post , custom post type and page. Apply the choosen color on frontend accordingly.
PlugStudio SVG CurrentColor Normalizer
mz-svg-currentcolor-normalizer
Automatically normalizes SVG icons to use currentColor in Elementor while preserving multicolor logos and illustrations.
Social Links Icons
social-links-icons
Simply customize and manage links and icons to more than 25 social networks and add your own social networks!
Boot Slider Developer Profile
5 plugins · 630 total installs
How We Detect Boot Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/boot-slider/assets/css/bootstrap.min.css/wp-content/plugins/boot-slider/assets/css/bt-slider.css/wp-content/plugins/boot-slider/assets/js/bootstrap.min.js/wp-content/plugins/boot-slider/assets/js/bootstrap.min.jsboot-slider/assets/css/bootstrap.min.css?ver=boot-slider/assets/css/bt-slider.css?ver=boot-slider/assets/js/bootstrap.min.js?ver=HTML / DOM Fingerprints
carousel-itemcarousel-captiond-blockw-100d-noned-md-blockcarouselslide+7 moredata-bs-ride="carousel"data-bs-targetdata-bs-slide-todata-bs-slide="prev"data-bs-slide="next"bootstrap<div class="carousel-item"><img src="class="d-block w-100"alt="