Easy Slider Security & Risk Analysis

wordpress.org/plugins/easy-slider-revolution

Create a responsive slider where the content and button for each slide.

2K active installs v1.1.3 PHP + WP 5.1+ Updated Jan 26, 2026
content-slidereasy-sliderimage-slidersliderslider-with-button
100
A · Safe
CVEs total1
Unpatched0
Last CVEApr 21, 2023
Safety Verdict

Is Easy Slider Safe to Use in 2026?

Generally Safe

Score 100/100

Easy Slider has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 21, 2023Updated 2mo ago
Risk Assessment

The "easy-slider-revolution" plugin, version 1.1.3, exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries, a high percentage of properly escaped output, and the presence of nonce and capability checks. Furthermore, the absence of identified dangerous functions, file operations, external HTTP requests, and untainted flows is encouraging.

However, the presence of one historical medium severity Cross-Site Scripting (XSS) vulnerability, even though currently patched, warrants attention. This indicates a past weakness that could potentially be reintroduced if similar coding patterns are present. While the current version has no identified critical or high severity vulnerabilities and a limited attack surface, the past XSS vulnerability suggests that vigilance is required to ensure input sanitization and output escaping remain robust across all functionalities.

In conclusion, this version of "easy-slider-revolution" appears to be relatively secure, with strengths in its use of secure coding practices and a limited attack surface. The main concern stems from its vulnerability history, specifically the past XSS flaw, which necessitates ongoing monitoring and thorough code reviews to prevent future occurrences. The plugin's strengths outweigh its weaknesses in this specific version's analysis, but the historical context is important for a complete risk assessment.

Key Concerns

  • Past medium severity XSS vulnerability
Vulnerabilities
1

Easy Slider Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-28622medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Easy Slider Revolution <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via esrcpt_slider_allow_iframes_filter

Apr 21, 2023 Patched in 1.1.0 (446d)
Code Analysis
Analyzed Mar 16, 2026

Easy Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
315 escaped
Nonce Checks
2
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

97% escaped324 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
esrcpt_slider_sa_reorder_slides_page (admin\easy-slider-admin.php:1818)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Easy Slider Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[easy-slider-revolution] front\easy-slider-frontend.php:14
WordPress Hooks 16
filtermce_external_pluginsadmin\easy-slider-admin.php:243
filtermce_buttonsadmin\easy-slider-admin.php:244
actionadmin_initadmin\easy-slider-admin.php:257
filtermce_external_pluginsadmin\easy-slider-admin.php:261
filtermce_buttonsadmin\easy-slider-admin.php:267
actionadmin_enqueue_scriptseasy_slider_revolution.php:28
actioniniteasy_slider_revolution.php:29
actionpost_row_actionseasy_slider_revolution.php:30
actionadd_meta_boxeseasy_slider_revolution.php:31
actionsave_posteasy_slider_revolution.php:32
filtermanage_es_slider_posts_columnseasy_slider_revolution.php:33
filtermanage_es_slider_posts_custom_columneasy_slider_revolution.php:34
actionadmin_headeasy_slider_revolution.php:36
actionadmin_footereasy_slider_revolution.php:37
actionadmin_menueasy_slider_revolution.php:39
filterwp_kses_allowed_htmleasy_slider_revolution.php:40
Maintenance & Trust

Easy Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 26, 2026
PHP min version
Downloads45K

Community Trust

Rating100/100
Number of ratings3
Active installs2K
Developer Profile

Easy Slider Developer Profile

Trident Technolabs

5 plugins · 3K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
226 days
View full developer profile
Detection Fingerprints

How We Detect Easy Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-slider-revolution/admin/css/easy-slider-admin.css/wp-content/plugins/easy-slider-revolution/admin/js/easy-slider-admin.js/wp-content/plugins/easy-slider-revolution/front/css/easy-slider-frontend.css/wp-content/plugins/easy-slider-revolution/front/js/easy-slider-frontend.js
Script Paths
/wp-content/plugins/easy-slider-revolution/admin/js/easy-slider-admin.js/wp-content/plugins/easy-slider-revolution/front/js/easy-slider-frontend.js
Version Parameters
easy-slider-revolution/admin/css/easy-slider-admin.css?ver=easy-slider-revolution/admin/js/easy-slider-admin.js?ver=easy-slider-revolution/front/css/easy-slider-frontend.css?ver=easy-slider-revolution/front/js/easy-slider-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
esrcpt-slider-wrapperesrcpt-slider-itemesrcpt-slider-imageesrcpt-slider-contentesrcpt-slider-button
HTML Comments
<!-- EASY SLIDER PLUGIN --><!-- EASY SLIDER PLUGIN CONTENT --><!-- EASY SLIDER PLUGIN JS -->
Data Attributes
data-slider-iddata-slide-durationdata-loopdata-nav-arrowsdata-pagination
JS Globals
easySliderFrontend
Shortcode Output
[easy_slider]
FAQ

Frequently Asked Questions about Easy Slider