Team Circle Image Slider With Lightbox Security & Risk Analysis

wordpress.org/plugins/circle-image-slider-with-lightbox

Team Circle Image Silder With Lightbox is beautiful responsive circle thumbnail image slider with responsive lightbox.Add any number of images from ad …

300 active installs v1.0.20 PHP + WP 3.5+ Updated Dec 19, 2025
team-galleryteam-sliderwordpress-circle-gallery-sliderwordpress-circle-sliderwordpress-circle-slider-lightbox
96
A · Safe
CVEs total4
Unpatched0
Last CVEApr 7, 2025
Safety Verdict

Is Team Circle Image Slider With Lightbox Safe to Use in 2026?

Generally Safe

Score 96/100

Team Circle Image Slider With Lightbox has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: Apr 7, 2025Updated 3mo ago
Risk Assessment

The "circle-image-slider-with-lightbox" plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, exclusively using prepared statements, and includes a reasonable number of nonce and capability checks. The absence of unpatched CVEs is also a significant strength. However, the static analysis reveals concerning areas. A substantial 16% of output is not properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities, especially given its vulnerability history. The taint analysis, while reporting no critical or high severity issues, did identify three flows with unsanitized paths, which, when combined with the low output escaping percentage, warrants caution. The vulnerability history, featuring four medium severity CVEs including SQL Injection, CSRF, and XSS, indicates past weaknesses that, while currently patched, suggest a recurring need for vigilance in these areas.

Overall, the plugin has made progress in security, particularly with SQL handling and the patching of past vulnerabilities. Nevertheless, the prevalence of unsanitized paths in taint flows and the low percentage of properly escaped output present tangible risks. The historical pattern of vulnerabilities also suggests that developers should maintain a high level of scrutiny for potential XSS, SQL Injection, and CSRF flaws. While the current state is not critical, ongoing monitoring and attention to output sanitization are crucial to maintain a secure posture.

Key Concerns

  • Low percentage of properly escaped output
  • Taint analysis shows unsanitized paths
  • History of medium severity vulnerabilities
Vulnerabilities
4

Team Circle Image Slider With Lightbox Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2023
2023
1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2019-25223medium · 4.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Team Circle Image Slider With Lightbox <= 1.0.4 - Authenticated (Admin+) SQL Injection

Apr 7, 2025 Patched in 1.0.5 (1d)
CVE-2015-10130medium · 5.3Cross-Site Request Forgery (CSRF)

Team Circle Image Slider With Lightbox 1.0 - Cross-Site Request Forgery

Mar 12, 2024 Patched in 1.0.1 (1d)
CVE-2023-2604medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Team Circle Image Slider With Lightbox <= 1.0.17 - Reflected Cross-Site Scripting

May 9, 2023 Patched in 1.0.18 (259d)
CVE-2022-0648medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Team Circle Image Slider With Lightbox <= 1.0.15 - Reflected Cross-Site Scripting

Feb 21, 2022 Patched in 1.0.16 (701d)
Code Analysis
Analyzed Mar 16, 2026

Team Circle Image Slider With Lightbox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
13 prepared
Unescaped Output
256
47 escaped
Nonce Checks
5
Capability Checks
10
File Operations
10
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared13 total queries

Output Escaping

16% escaped303 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
circle_thumbnail_slider_with_lightbox_image_management_func (circle-image-slider-with-lightbox.php:829)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Team Circle Image Slider With Lightbox Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_mass_upload_cirl_slidercircle-image-slider-with-lightbox.php:22

Shortcodes 1

[print_circle_slider_plus_lightbox] circle-image-slider-with-lightbox.php:18
WordPress Hooks 10
filterwidget_textcircle-image-slider-with-lightbox.php:13
actionadmin_menucircle-image-slider-with-lightbox.php:14
actionwp_enqueue_scriptscircle-image-slider-with-lightbox.php:17
actionadmin_noticescircle-image-slider-with-lightbox.php:19
actionplugins_loadedcircle-image-slider-with-lightbox.php:20
filteruser_has_capcircle-image-slider-with-lightbox.php:21
filtermap_meta_capcircle-image-slider-with-lightbox.php:27
filterwidget_text_contentcircle-image-slider-with-lightbox.php:3397
filterthe_contentcircle-image-slider-with-lightbox.php:3398
filterrender_blockcircle-image-slider-with-lightbox.php:3409
Maintenance & Trust

Team Circle Image Slider With Lightbox Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 19, 2025
PHP min version
Downloads26K

Community Trust

Rating80/100
Number of ratings4
Active installs300
Developer Profile

Team Circle Image Slider With Lightbox Developer Profile

Nks

19 plugins · 23K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
350 days
View full developer profile
Detection Fingerprints

How We Detect Team Circle Image Slider With Lightbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/circle-image-slider-with-lightbox/css/owl.carousel.css/wp-content/plugins/circle-image-slider-with-lightbox/css/style.css/wp-content/plugins/circle-image-slider-with-lightbox/css/owl.theme.css/wp-content/plugins/circle-image-slider-with-lightbox/js/owl.carousel.js/wp-content/plugins/circle-image-slider-with-lightbox/js/main.js/wp-content/plugins/circle-image-slider-with-lightbox/js/lightbox.js
Script Paths
/wp-content/plugins/circle-image-slider-with-lightbox/js/owl.carousel.js/wp-content/plugins/circle-image-slider-with-lightbox/js/main.js/wp-content/plugins/circle-image-slider-with-lightbox/js/lightbox.js
Version Parameters
circle-image-slider-with-lightbox/css/owl.carousel.css?ver=circle-image-slider-with-lightbox/css/style.css?ver=circle-image-slider-with-lightbox/css/owl.theme.css?ver=circle-image-slider-with-lightbox/js/owl.carousel.js?ver=circle-image-slider-with-lightbox/js/main.js?ver=circle-image-slider-with-lightbox/js/lightbox.js?ver=

HTML / DOM Fingerprints

CSS Classes
owl-themeowl-carousel
JS Globals
jQuery
Shortcode Output
[print_circle_slider_plus_lightbox
FAQ

Frequently Asked Questions about Team Circle Image Slider With Lightbox