Easy Backstretch Security & Risk Analysis

wordpress.org/plugins/easy-backstretch

A simple and easy way to use Backstretch jQuery plugin in basic, slideshow and block level mode.

300 active installs v1.0 PHP + WP 3.6+ Updated May 14, 2014
backstretchfullwidth-slideshowresponsive-backgroundslideshow
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Backstretch Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Backstretch has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'easy-backstretch' v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by not exposing any direct attack surface through AJAX, REST API, shortcodes, or cron events. Furthermore, all identified SQL queries are correctly using prepared statements, and there are no recorded vulnerabilities or CVEs, suggesting a generally stable codebase historically. However, a significant concern arises from the complete lack of output escaping. With 24 total outputs and 0% properly escaped, this presents a high risk for cross-site scripting (XSS) vulnerabilities. Any data processed or displayed by the plugin could potentially be injected with malicious scripts, impacting users who interact with the affected pages. The absence of nonce and capability checks, while not directly exploitable given the limited attack surface, indicates a lack of robust security layering that could become an issue if new entry points are introduced in future versions.

Key Concerns

  • All output is unescaped
  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

Easy Backstretch Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Easy Backstretch Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped24 total outputs
Attack Surface

Easy Backstretch Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initeasy-backstretch.php:47
actionadmin_menueasy-backstretch.php:53
actionwp_print_scriptseasy-backstretch.php:355
actionwp_footereasy-backstretch.php:362
Maintenance & Trust

Easy Backstretch Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedMay 14, 2014
PHP min version
Downloads10K

Community Trust

Rating80/100
Number of ratings10
Active installs300
Developer Profile

Easy Backstretch Developer Profile

Marco Galasso

1 plugin · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Backstretch

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-backstretch/

HTML / DOM Fingerprints

CSS Classes
easy-backstretch
HTML Comments
Easy Backstretch ImagesEasy Backstretch Settings
FAQ

Frequently Asked Questions about Easy Backstretch