Creative Clans Slide Show Security & Risk Analysis

wordpress.org/plugins/creative-clans-slide-show

A free widget to use the Creative Clans Slide Show in your Wordpress website.

200 active installs v1.3.4 PHP + WP 2.7+ Updated Apr 22, 2015
creative-clansflashpresentationslideshowwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Creative Clans Slide Show Safe to Use in 2026?

Generally Safe

Score 85/100

Creative Clans Slide Show has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin "creative-clans-slide-show" v1.3.4 presents a mixed security posture. While the absence of known CVEs and the use of prepared statements for SQL queries are positive indicators, significant concerns arise from the static analysis. The complete lack of output escaping on all identified outputs (151 total) is a critical flaw that could lead to Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the presence of file operations and external HTTP requests without apparent proper sanitization or authentication checks poses a risk of unauthorized file manipulation or external service compromise. The taint analysis, though limited, revealed a flow with an unsanitized path, indicating a potential for directory traversal or similar issues, even without a critical severity rating assigned. The plugin's vulnerability history is clean, suggesting diligent patching or a lack of past exploitation, but this does not negate the immediate risks identified in the current code. In conclusion, while the plugin benefits from a clean CVE record, the critical vulnerability in output escaping and potential risks from unsanitized file and network operations necessitate immediate attention.

Key Concerns

  • All outputs are unescaped
  • Flow with unsanitized path
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Creative Clans Slide Show Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Creative Clans Slide Show Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
151
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
10
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped151 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<creativeclans-slideshow-proxy> (creativeclans-slideshow-proxy.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Creative Clans Slide Show Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initcreativeclans-slideshow-widget.php:433
Maintenance & Trust

Creative Clans Slide Show Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedApr 22, 2015
PHP min version
Downloads51K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Creative Clans Slide Show Developer Profile

tonnaer

2 plugins · 900 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Creative Clans Slide Show

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/creative-clans-slide-show/
Script Paths
/wp-content/plugins/creative-clans-slide-show/creativeclans-slideshow-widget.js
Version Parameters
creative-clans-slide-show/creativeclans-slideshow-widget.js?ver=creative-clans-slide-show/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
widget_creativeclans_slideshow
Data Attributes
data-ccss-widget-numberdata-ccss-widthdata-ccss-heightdata-ccss-backgroundcolordata-ccss-loopsdata-ccss-wait+43 more
JS Globals
window.creativeClansSlideShow
FAQ

Frequently Asked Questions about Creative Clans Slide Show