
Client Scroller Widget Security & Risk Analysis
wordpress.org/plugins/client-scroller-widgetEasily create responsive & lightweight clientele slider in your sidebars.Install it Free today!
Is Client Scroller Widget Safe to Use in 2026?
Generally Safe
Score 85/100Client Scroller Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "client-scroller-widget" plugin version 1.5 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and its SQL queries are 100% prepared, indicating good practices in database interaction. Furthermore, the absence of external HTTP requests and bundled libraries reduces potential attack vectors. However, the static analysis reveals significant concerns. The presence of the `create_function` is a strong indicator of potential security risks, as it can lead to arbitrary code execution if not handled with extreme care and sanitization. Additionally, a concerning 38% of output is not properly escaped, which can open the door to cross-site scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks on entry points (though the attack surface is zero in this report) is a red flag, suggesting potential vulnerabilities if the entry points were to expand or change without proper security considerations.
Key Concerns
- Use of dangerous function 'create_function'
- Significant percentage of unescaped output
- Zero nonce checks
- Zero capability checks
Client Scroller Widget Security Vulnerabilities
Client Scroller Widget Code Analysis
Dangerous Functions Found
Output Escaping
Client Scroller Widget Attack Surface
WordPress Hooks 3
Maintenance & Trust
Client Scroller Widget Maintenance & Trust
Maintenance Signals
Community Trust
Client Scroller Widget Alternatives
No alternatives data available yet.
Client Scroller Widget Developer Profile
2 plugins · 90 total installs
How We Detect Client Scroller Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/client-scroller-widget/css/client-scroller-widget.css/wp-content/plugins/client-scroller-widget/js/client-scroller-widget.js/wp-content/plugins/client-scroller-widget/js/client-scroller-widget.jsclient-scroller-widget/css/client-scroller-widget.css?ver=client-scroller-widget/js/client-scroller-widget.js?ver=HTML / DOM Fingerprints
client-scroller-widgetclient-scroller-images-orderclient-scroller-widget-number-only-inputdata-effectdata-directional-navdata-button-navdata-themedata-responsivedata-pause-hover+2 moreclient_scroller_widget_params