
Card flip image slideshow Security & Risk Analysis
wordpress.org/plugins/card-flip-image-slideshowThis Card flip image slideshow script utilizes CSS3 transform to rotate images with unhinge animation.
Is Card flip image slideshow Safe to Use in 2026?
Use With Caution
Score 63/100Card flip image slideshow has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The security posture of the card-flip-image-slideshow plugin v1.5 shows a mixed bag of good practices and significant concerns. On the positive side, the plugin has a very small attack surface with only one shortcode and no AJAX handlers or REST API routes identified. The plugin also demonstrates good SQL hygiene with 88% of queries using prepared statements and includes some nonce checks. However, the low percentage of properly escaped output (19%) is a major red flag, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of capability checks for its single entry point (the shortcode) also presents a potential risk, as any authenticated user could potentially trigger its functionality, and the lack of input sanitization for any output is concerning.
The vulnerability history is particularly worrying, with one currently unpatched medium severity CVE for XSS. This, combined with the static analysis findings of poor output escaping, strongly suggests a recurring pattern of XSS vulnerabilities. The fact that the last vulnerability was in the future (2025-07-04) and is unpatched indicates a critical maintenance and patching oversight. While the plugin avoids dangerous functions and file operations, the critical weakness in output sanitization, coupled with the unpatched XSS vulnerability, makes this plugin a significant security risk.
Key Concerns
- Unpatched CVE
- Low percentage of properly escaped output
- Missing capability checks on entry points
Card flip image slideshow Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Card flip image slideshow <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Card flip image slideshow Code Analysis
SQL Query Safety
Output Escaping
Card flip image slideshow Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Card flip image slideshow Maintenance & Trust
Maintenance Signals
Community Trust
Card flip image slideshow Alternatives
Easy image slideshow
easy-image-slideshow
This is a lightweight JavaScript slideshow with manual navigation option. You can use this slideshow, if you need the manual navigation image gallery.
FP Responsive Slider
fp-responsive-slider
This plugin will display image as slideshow with several effects. You can manage the options from FP Resposive Slider's Settings page or from wid …
Smart Slider 3
smart-slider-3
Responsive slider plugin to create sliders in visual editor easily. Build beautiful image slider, layer slider, video slider, post slider, and more.
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Simple Lightbox
simple-lightbox
The highly customizable lightbox for WordPress
Card flip image slideshow Developer Profile
52 plugins · 19K total installs
How We Detect Card flip image slideshow
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/card-flip-image-slideshow/card-flip-image-slideshow.css/wp-content/plugins/card-flip-image-slideshow/card-flip-image-slideshow.jscard-flip-image-slideshow/card-flip-image-slideshow.css?ver=card-flip-image-slideshow/card-flip-image-slideshow.js?ver=HTML / DOM Fingerprints
cardflip-widget<!-- DO NOT DELETE THIS FILE -->cardflip_adminscripts