Membros Details Slide Security & Risk Analysis

wordpress.org/plugins/employees-details-slides

Member's information is displayed by slide plugin. It is a very useful small plugin. nice design and simple.

0 active installs v1.0.0 PHP 7.2+ WP 5.2+ Updated Oct 30, 2021
employee-displayemployee-managementemployee-slideremployees-details-slidesmembers
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Membros Details Slide Safe to Use in 2026?

Generally Safe

Score 85/100

Membros Details Slide has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The 'employees-details-slides' plugin version 1.0.0 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and SQL queries not using prepared statements are strong indicators of secure coding practices. Furthermore, the presence of nonce and capability checks on its entry points is commendable, as is the high percentage of properly escaped output. The plugin also has no recorded vulnerability history, which further strengthens its security profile.

However, a few areas warrant attention. While there are no critical or high severity taint flows detected, the analysis of taint flows was limited to 0. This could mean that either the analysis tool is not comprehensive enough or that the code is genuinely clean in this regard. The presence of 3 entry points (2 AJAX handlers and 1 shortcode) is a moderate attack surface. While all appear to have some form of protection (nonce/capability checks), the 2 AJAX handlers being unprotected in terms of authentication checks (stated as 0 without auth checks in the provided data) is a potential concern. Although the total entry points are low, any unprotected entry point can be a significant risk. Therefore, while the plugin is strong in many aspects, the potential for weaknesses in authentication checks on AJAX handlers and the limited scope of taint analysis should be considered.

In conclusion, 'employees-details-slides' v1.0.0 appears to be a relatively secure plugin, especially given its clean vulnerability history and strong implementation of basic security measures like prepared statements and output escaping. The main areas for improvement would be to ensure robust authentication checks are in place for all AJAX handlers and to potentially conduct a more thorough taint analysis if possible. The current risk level is low, but these points could be addressed to further enhance its security.

Key Concerns

  • AJAX handlers without auth checks
  • Limited taint flow analysis scope
Vulnerabilities
None known

Membros Details Slide Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Membros Details Slide Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Membros Details Slide Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
45
343 escaped
Nonce Checks
3
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped388 total outputs
Attack Surface

Membros Details Slide Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_cmb2_oembed_handlermetabox/includes/CMB2_Ajax.php:51
noprivwp_ajax_cmb2_oembed_handlermetabox/includes/CMB2_Ajax.php:52

Shortcodes 1

[employee_info] init.php:128
WordPress Hooks 49
actioninitinit.php:33
actionwp_enqueue_scriptsinit.php:35
actioncmb2_admin_initmetabox/example-functions.php:105
actioncmb2_admin_initmetabox/example-functions.php:470
actioncmb2_admin_initmetabox/example-functions.php:500
actioncmb2_admin_initmetabox/example-functions.php:564
actioncmb2_admin_initmetabox/example-functions.php:633
actioncmb2_admin_initmetabox/example-functions.php:674
actioncmb2_initmetabox/example-functions.php:777
filterwp_prepare_attachment_for_jsmetabox/includes/CMB2.php:1558
actionadmin_enqueue_scriptsmetabox/includes/CMB2.php:1576
actioncmb2_save_options-page_fieldsmetabox/includes/CMB2_Ajax.php:54
filterget_post_metadatametabox/includes/CMB2_Ajax.php:147
filterupdate_post_metadatametabox/includes/CMB2_Ajax.php:150
filtercmb2_show_onmetabox/includes/CMB2_Hookup.php:79
actionedit_form_topmetabox/includes/CMB2_Hookup.php:115
actionedit_form_before_permalinkmetabox/includes/CMB2_Hookup.php:119
actionedit_form_after_titlemetabox/includes/CMB2_Hookup.php:123
actionedit_form_after_editormetabox/includes/CMB2_Hookup.php:127
actionadd_meta_boxesmetabox/includes/CMB2_Hookup.php:131
actionadd_meta_boxesmetabox/includes/CMB2_Hookup.php:134
actionadd_attachmentmetabox/includes/CMB2_Hookup.php:135
actionedit_attachmentmetabox/includes/CMB2_Hookup.php:136
actionsave_postmetabox/includes/CMB2_Hookup.php:137
actionpre_get_postsmetabox/includes/CMB2_Hookup.php:144
actionadd_meta_boxes_commentmetabox/includes/CMB2_Hookup.php:152
actionedit_commentmetabox/includes/CMB2_Hookup.php:153
filtermanage_edit-comments_columnsmetabox/includes/CMB2_Hookup.php:156
actionmanage_comments_custom_columnmetabox/includes/CMB2_Hookup.php:157
filtermanage_edit-comments_sortable_columnsmetabox/includes/CMB2_Hookup.php:158
actionpre_get_postsmetabox/includes/CMB2_Hookup.php:159
actionshow_user_profilemetabox/includes/CMB2_Hookup.php:168
actionedit_user_profilemetabox/includes/CMB2_Hookup.php:169
actionuser_new_formmetabox/includes/CMB2_Hookup.php:170
actionpersonal_options_updatemetabox/includes/CMB2_Hookup.php:172
actionedit_user_profile_updatemetabox/includes/CMB2_Hookup.php:173
actionuser_registermetabox/includes/CMB2_Hookup.php:174
filtermanage_users_columnsmetabox/includes/CMB2_Hookup.php:177
filtermanage_users_custom_columnmetabox/includes/CMB2_Hookup.php:178
filtermanage_users_sortable_columnsmetabox/includes/CMB2_Hookup.php:179
actionpre_get_postsmetabox/includes/CMB2_Hookup.php:180
actionpre_get_postsmetabox/includes/CMB2_Hookup.php:226
actioncreated_termmetabox/includes/CMB2_Hookup.php:230
actionedited_termsmetabox/includes/CMB2_Hookup.php:231
actiondelete_termmetabox/includes/CMB2_Hookup.php:232
actioncmb2_do_oembedmetabox/includes/helper-functions.php:131
filteris_protected_metametabox/includes/rest-api/CMB2_REST.php:144
actioninitmetabox/init.php:86
actioncmb2_admin_initmetabox/metabox-config.php:3
Maintenance & Trust

Membros Details Slide Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 30, 2021
PHP min version7.2
Downloads858

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Membros Details Slide Developer Profile

Md Jakir Hossen

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Membros Details Slide

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/employees-details-slides/css/slick-custom.css/wp-content/plugins/employees-details-slides/css/slick.css/wp-content/plugins/employees-details-slides/js/slick.custom.js/wp-content/plugins/employees-details-slides/js/slick.min.js
Script Paths
/wp-content/plugins/employees-details-slides/js/slick.min.js/wp-content/plugins/employees-details-slides/js/slick.custom.js
Version Parameters
employees-details-slides/css/slick-custom.css?ver=employees-details-slides/css/slick.css?ver=employees-details-slides/js/slick.custom.js?ver=employees-details-slides/js/slick.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
slick-slide
Shortcode Output
[employee_info]
FAQ

Frequently Asked Questions about Membros Details Slide