Creative Image Slider – Responsive Slider Plugin Security & Risk Analysis

wordpress.org/plugins/creative-image-slider

Creative Image Slider is a responsive jQuery image slider with amazing visual effects.

200 active installs v2.6.0 PHP + WP 3.6+ Updated Jul 8, 2024
image-slidersliderslider-pluginslideshowwordpress-slider
92
A · Safe
CVEs total1
Unpatched0
Last CVEMar 28, 2024
Safety Verdict

Is Creative Image Slider – Responsive Slider Plugin Safe to Use in 2026?

Generally Safe

Score 92/100

Creative Image Slider – Responsive Slider Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 28, 2024Updated 1yr ago
Risk Assessment

The creative-image-slider plugin version 2.6.0 exhibits a generally good security posture, with a low number of entry points and no identified unprotected handlers or routes. The majority of SQL queries utilize prepared statements, and the presence of both nonce and capability checks on several functions is a positive sign. However, there are areas for concern, particularly regarding output escaping. With only 22% of outputs properly escaped, there's a significant risk of Cross-Site Scripting (XSS) vulnerabilities, which aligns with the plugin's vulnerability history. Furthermore, the presence of two flows with unsanitized paths, while not classified as critical or high severity in the taint analysis, suggests potential for vulnerabilities related to file handling or path traversal if these flows are triggered by user input without sufficient sanitization.

The plugin's vulnerability history includes one medium severity CVE for Cross-Site Scripting, indicating a recurring pattern of input sanitization issues. While this vulnerability is reported as currently unpatched, it's important to note that the "currently unpatched" count is zero, which could imply a recent patch or a misunderstanding in the provided data. Regardless, the historical presence of XSS vulnerabilities reinforces the concern raised by the low output escaping rate. The use of the Select2 library, if not kept up-to-date, could also present a risk, although no specific vulnerabilities related to it are mentioned.

In conclusion, creative-image-slider v2.6.0 has strengths in its limited attack surface and diligent use of prepared statements for SQL. However, the low percentage of properly escaped output and the history of XSS vulnerabilities are significant weaknesses that require immediate attention. The identified unsanitized paths also warrant further investigation. Addressing these issues would greatly improve the plugin's overall security.

Key Concerns

  • Low output escaping rate (22%)
  • Flows with unsanitized paths (2)
  • Historical medium XSS vulnerability
  • Bundled library (Select2) - potential outdated risk
Vulnerabilities
1

Creative Image Slider – Responsive Slider Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-30447medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Creative Image Slider – Responsive Slider Plugin <= 2.1.3 - Reflected Cross-Site Scripting

Mar 28, 2024 Patched in 2.5.0 (7d)
Code Analysis
Analyzed Mar 16, 2026

Creative Image Slider – Responsive Slider Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
52 prepared
Unescaped Output
367
103 escaped
Nonce Checks
7
Capability Checks
7
File Operations
3
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

98% prepared53 total queries

Output Escaping

22% escaped470 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

9 flows2 with unsanitized paths
wpcis_render_slider (includes\display-functions.php:249)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Creative Image Slider – Responsive Slider Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[creativeslider] includes\display-functions.php:27
WordPress Hooks 6
actionadmin_print_scriptscreativeimageslider.php:71
actionadmin_print_stylescreativeimageslider.php:72
actionadmin_initcreativeimageslider.php:74
actionadmin_menuincludes\admin-page.php:91
actionadmin_initincludes\admin-page.php:92
actionwidgets_initincludes\creativeimageslider_widget.php:77
Maintenance & Trust

Creative Image Slider – Responsive Slider Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJul 8, 2024
PHP min version
Downloads65K

Community Trust

Rating70/100
Number of ratings18
Active installs200
Developer Profile

Creative Image Slider – Responsive Slider Plugin Developer Profile

Creative-Solutions

4 plugins · 4K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
1211 days
View full developer profile
Detection Fingerprints

How We Detect Creative Image Slider – Responsive Slider Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/creative-image-slider/css/admin.css/wp-content/plugins/creative-image-slider/js/admin.js/wp-content/plugins/creative-image-slider/css/creativecss-ui.css/wp-content/plugins/creative-image-slider/css/colorpicker.css/wp-content/plugins/creative-image-slider/css/layout.css/wp-content/plugins/creative-image-slider/assets/css/main.css/wp-content/plugins/creative-image-slider/assets/css/creative_buttons.css/wp-content/plugins/creative-image-slider/js/colorpicker.js+5 more
Script Paths
/wp-content/plugins/creative-image-slider/js/admin.js/wp-content/plugins/creative-image-slider/js/colorpicker.js/wp-content/plugins/creative-image-slider/assets/js/mousewheel.js/wp-content/plugins/creative-image-slider/assets/js/easing.js/wp-content/plugins/creative-image-slider/js/creativeimageslider.js
Version Parameters
creative-image-slider/css/admin.css?ver=creative-image-slider/js/admin.js?ver=creative-image-slider/css/creativecss-ui.css?ver=creative-image-slider/css/colorpicker.css?ver=creative-image-slider/css/layout.css?ver=creative-image-slider/assets/css/main.css?ver=creative-image-slider/assets/css/creative_buttons.css?ver=creative-image-slider/js/colorpicker.js?ver=creative-image-slider/assets/js/mousewheel.js?ver=creative-image-slider/assets/js/easing.js?ver=creative-image-slider/js/creativeimageslider.js?ver=creative-image-slider/css/ui-lightness/jquery-ui-1.10.1.custom.css?ver=creative-image-slider/css/options_styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpcis-styles1wpcis-script1wpcis-styles2wpcis-styles3wpcis-styles4wpcis-styles5wpcis-styles6wpcis-script2+4 more
Data Attributes
data-wpcis-sliderdata-wpcis-slider-effectdata-wpcis-slider-transitiondata-wpcis-slider-widthdata-wpcis-slider-heightdata-wpcis-slider-autoplay+3 more
JS Globals
wpcis_admin_opt
Shortcode Output
[creativeimageslider[creativeimageslider id=
FAQ

Frequently Asked Questions about Creative Image Slider – Responsive Slider Plugin