Crisp Slider Security & Risk Analysis

wordpress.org/plugins/crisp-slider

A free responsive WordPress slider plugin to display images in a basic slider or a carousel with custom options and free support.

10 active installs v1.0 PHP + WP 4.0+ Updated Aug 26, 2017
banner-rotatorcarouselgalleryimage-sliderresponsive-slider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Crisp Slider Safe to Use in 2026?

Generally Safe

Score 85/100

Crisp Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "crisp-slider" v1.0 plugin exhibits a generally strong security posture due to its lack of critical code signals like dangerous functions, raw SQL queries, and external HTTP requests. The presence of nonce and capability checks, along with the absence of known CVEs, further contributes to this positive outlook. However, a significant concern arises from the moderate rate of output escaping, with only 55% of outputs being properly handled. This could potentially leave the plugin vulnerable to cross-site scripting (XSS) attacks if user-supplied data is directly rendered in the output without sufficient sanitization for the remaining 45% of outputs.

While the plugin boasts a small attack surface with only one shortcode and no unprotected entry points, the unescaped output remains the primary area of risk. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting a history of responsible development or a lack of past exploitation. Nevertheless, the 45% of unescaped outputs represent a tangible risk that should not be overlooked. Developers should prioritize addressing this by ensuring all outputs are properly escaped to prevent potential XSS vulnerabilities and maintain a robust security profile.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Crisp Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Crisp Slider Release Timeline

v1.0Current
Code Analysis
Analyzed Apr 16, 2026

Crisp Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
98
121 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

55% escaped219 total outputs
Attack Surface

Crisp Slider Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[crispslider] inc/crisp-slider-shortcode.php:504
WordPress Hooks 15
actionwp_enqueue_scriptscrispslider.php:55
actionwp_enqueue_scriptscrispslider.php:56
actionadmin_enqueue_scriptscrispslider.php:59
actionadmin_enqueue_scriptscrispslider.php:60
actioninitcrispslider.php:63
actioninitcrispslider.php:64
actioninitcrispslider.php:65
actionplugins_loadedcrispslider.php:72
actioninitcrispslider.php:75
actionwidgets_initcrispslider.php:78
actionadd_meta_boxesinc/crisp-slider-metabox.php:8
actionsave_postinc/crisp-slider-metabox.php:653
actionadmin_enqueue_scriptsinc/gallery.php:16
actionadd_meta_boxesinc/gallery.php:32
actionsave_postinc/gallery.php:73
Maintenance & Trust

Crisp Slider Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedAug 26, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Crisp Slider Developer Profile

Patrick

3 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Crisp Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/crisp-slider/js/jquery.bxslider.min.js/wp-content/plugins/crisp-slider/js/admin/crisp-script-admin.js/wp-content/plugins/crisp-slider/css/jquery.bxslider.css/wp-content/plugins/crisp-slider/css/crisp-slider-style.css/wp-content/plugins/crisp-slider/css/admin/crisp-style-admin.css/wp-content/plugins/crisp-slider/js/admin/gallery-metabox.js/wp-content/plugins/crisp-slider/css/admin/gallery-metabox.css
Script Paths
/wp-content/plugins/crisp-slider/js/jquery.bxslider.min.js/wp-content/plugins/crisp-slider/js/admin/crisp-script-admin.js/wp-content/plugins/crisp-slider/js/admin/gallery-metabox.js
Version Parameters
crisp-slider/js/jquery.bxslider.min.js?ver=crisp-slider/js/admin/crisp-script-admin.js?ver=crisp-slider/css/jquery.bxslider.css?ver=crisp-slider/css/crisp-slider-style.css?ver=crisp-slider/css/admin/crisp-style-admin.css?ver=crisp-slider/js/admin/gallery-metabox.js?ver=crisp-slider/css/admin/gallery-metabox.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Crisp Slider