
Simple Slideshow Security & Risk Analysis
wordpress.org/plugins/cvmh-simple-slideshowAdd a slideshow on your site.
Is Simple Slideshow Safe to Use in 2026?
Generally Safe
Score 85/100Simple Slideshow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cvmh-simple-slideshow plugin v1.2.15 exhibits a mixed security posture. While it has a clean vulnerability history with no recorded CVEs, indicating a generally stable past, the static analysis reveals several areas for concern. The presence of an unprotected AJAX handler significantly increases the attack surface, providing a direct entry point for malicious actors without proper authentication. Furthermore, the plugin heavily relies on raw SQL queries without prepared statements, which is a critical vulnerability that could lead to SQL injection attacks. The low percentage of properly escaped output suggests that user-supplied data might be reflected directly in the output, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. Although there are no critical taint flows or dangerous functions identified, the combination of these weaknesses, particularly the unprotected AJAX handler and un-prepared SQL queries, presents a moderate to high risk that requires attention.
Key Concerns
- Unprotected AJAX handler present
- 100% of SQL queries use raw statements
- Low percentage of properly escaped output
Simple Slideshow Security Vulnerabilities
Simple Slideshow Release Timeline
Simple Slideshow Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple Slideshow Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
Simple Slideshow Maintenance & Trust
Maintenance Signals
Community Trust
Simple Slideshow Alternatives
WP-Cycle
wp-cycle
This plugin creates an image slideshow in your theme, using the jQuery Cycle plugin. You can upload/delete images via the administration panel, and di …
Slideshow
slideshow
A shortcode for displaying a slideshow of image attachments for a post.
All-In-One Slideshow
all-in-one-slideshow
All-In-One Slideshow plugin implements jCycle, Easing and Cufon scripts into the highly customizable slideshow gallery.
WP-Cycle Plus Captions
wp-cycle-plus-captions
The WP-Cycle Plus Captions plugin allows you to upload images from your computer, which will then be used to generate a jQuery Cycle Plugin slideshow.
Simple Content Slider / Slideshow
simple-content-slider
A simple and responsive content slider and slideshow plug-in for jQuery with features like touch and CSS3 transitions.
Simple Slideshow Developer Profile
5 plugins · 180 total installs
How We Detect Simple Slideshow
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cvmh-simple-slideshow/assets/css/admin.min.css/wp-content/plugins/cvmh-simple-slideshow/assets/js/admin.min.js../../assets/js/admin.min.js../../assets/css/admin.min.csscvmh-slideshow-admin.min.js?ver=cvmh-slideshow-admin.min.css?ver=HTML / DOM Fingerprints
cvmh_slideshow_admindata-cvmh_slideshow_widthdata-cvmh_slideshow_heightdata-cvmh_slideshow_durationdata-cvmh_slideshow_show_navcvmhTranslate