
Crelly Slider Security & Risk Analysis
wordpress.org/plugins/crelly-sliderA free responsive slider that supports layers. Add texts, images, videos and beautify them with transitions and animations.
Is Crelly Slider Safe to Use in 2026?
Use With Caution
Score 63/100Crelly Slider has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The Crelly Slider plugin version 1.4.7 presents a mixed security posture. While it demonstrates good practices such as a majority of SQL queries using prepared statements and a reasonable number of capability checks and nonce checks for its entry points, several concerning signals emerge from the static analysis. Specifically, the presence of 5 flows with unsanitized paths and 4 high-severity taint flows indicate potential avenues for attackers to manipulate the application. This, coupled with a historical pattern of vulnerabilities including Cross-Site Scripting, SQL Injection, and Authorization Bypass, paints a picture of a plugin that, despite some security efforts, has previously been susceptible to significant risks. The fact that there is still one unpatched CVE as of January 2025 is a critical red flag, suggesting that known vulnerabilities may still be exploitable.
Key Concerns
- Currently unpatched CVE
- High severity taint flows
- Flows with unsanitized paths
- Historical high severity vulnerabilities
- Output escaping is not consistently applied
Crelly Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Crelly Slider <= 1.4.6 - Authenticated (Admin+) Stored Cross-Site Scripting
Crelly Slider <= 1.4.5 - Authenticated (Subscriber+) Insecure Direct Object Reference
Crelly Slider <= 1.4.6 - Authenticated (Admin+) Stored Cross-Site Scripting
Crelly Slider <= 1.3.4 - Arbitrary File Upload
Crelly Slider <= 1.1.1 - SQL Injection
Crelly Slider Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Crelly Slider Attack Surface
AJAX Handlers 9
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Crelly Slider Maintenance & Trust
Maintenance Signals
Community Trust
Crelly Slider Alternatives
View Transitions
view-transitions
Adds smooth transitions between navigations to your WordPress site.
Cinematic 3D Parallax Touch Slider
cinematic
Responsive 3D Parallax Touch Slider. The most realistic mobile 3D layer photo animation in the market.
Motion
motion
Motion WordPress Plugin provide user friendly solution to beautiful CSS3 animations.
Simple Text Slider
simple-text-slider
A simple text slider plugin for several vertical textslider via shortcode.
Page slideshow
page-slideshow
With Page Slideshow you can create individual, responsive and sortable slideshows. Uses performance-friendly CSS3 transitions.
Crelly Slider Developer Profile
1 plugin · 10K total installs
How We Detect Crelly Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/crelly-slider/wordpress/css/admin.css/wp-content/plugins/crelly-slider/wordpress/css/common.css/wp-content/plugins/crelly-slider/wordpress/css/frontend.css/wp-content/plugins/crelly-slider/wordpress/css/slider.css/wp-content/plugins/crelly-slider/wordpress/css/slides.css/wp-content/plugins/crelly-slider/wordpress/js/admin.js/wp-content/plugins/crelly-slider/wordpress/js/common.js/wp-content/plugins/crelly-slider/wordpress/js/frontend.js+4 more/wp-content/plugins/crelly-slider/wordpress/js/admin.js/wp-content/plugins/crelly-slider/wordpress/js/common.js/wp-content/plugins/crelly-slider/wordpress/js/frontend.js/wp-content/plugins/crelly-slider/wordpress/js/slider.js/wp-content/plugins/crelly-slider/wordpress/js/slides.jscrelly-slider/wordpress/css/admin.css?ver=crelly-slider/wordpress/css/common.css?ver=crelly-slider/wordpress/css/frontend.css?ver=crelly-slider/wordpress/css/slider.css?ver=crelly-slider/wordpress/css/slides.css?ver=crelly-slider/wordpress/js/admin.js?ver=crelly-slider/wordpress/js/common.js?ver=crelly-slider/wordpress/js/frontend.js?ver=crelly-slider/wordpress/js/slider.js?ver=crelly-slider/wordpress/js/slides.js?ver=HTML / DOM Fingerprints
cs-admincs-no-jscs-messagecs-message-errorcs-message-okcs-message-waitcs-message-warningcs-logo+16 moredata-idcrellyslider_localecrellyslider_currentSliderNonce