
Envoke Supersized Security & Risk Analysis
wordpress.org/plugins/envoke-supersizedThis plugin creates an easy to use interface for managing the Supersized jQuery Plugin on your site.
Is Envoke Supersized Safe to Use in 2026?
Generally Safe
Score 85/100Envoke Supersized has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The envoke-supersized plugin version 2.2.1 exhibits a strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with direct attack surfaces is a significant positive indicator. Furthermore, the code signals show no dangerous functions, no raw SQL queries (all prepared statements), no file operations, and no external HTTP requests. The presence of nonce and capability checks, even if limited, suggests an awareness of WordPress security best practices. Taint analysis also yielded no concerning results, indicating no identified pathways for malicious data injection.
However, a notable concern arises from the output escaping analysis, where only 47% of outputs are properly escaped. This leaves a portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is not handled correctly before being rendered. While the vulnerability history shows no known CVEs, which is excellent, the lack of a robust output sanitization strategy presents a weakness that could be exploited. The plugin's strengths lie in its limited attack surface and secure data handling for SQL and external requests, but the unescaped output represents a tangible risk that should be addressed.
Key Concerns
- Significant portion of output not properly escaped
Envoke Supersized Security Vulnerabilities
Envoke Supersized Code Analysis
Output Escaping
Envoke Supersized Attack Surface
WordPress Hooks 17
Maintenance & Trust
Envoke Supersized Maintenance & Trust
Maintenance Signals
Community Trust
Envoke Supersized Alternatives
Easy Fullscreen Slider
easy-fullscreen-slider
An easy-to-use WordPress fullscreen slider plugin for Supersized.
Jellyfish backdrop
jellyfish-backdrop
Fullscreen background images and background slideshows on any WordPress post or page. Easily upload and select images using the media library.
cbVegas
cb-vegas
Requires at least: 3.9 Tested up to: 4.7.2 Stable tag: 0.3.6 Version: 0.3.6 License: GPLv2 or later License URI: https://www.gnu.org/licenses/gpl-2.0.
RokGallery Background Slideshow
rokgallery-background-slideshow
Display your RokGallery galleries as an slideshow in the background of your site.
Smart Slider 3
smart-slider-3
Responsive slider plugin to create sliders in visual editor easily. Build beautiful image slider, layer slider, video slider, post slider, and more.
Envoke Supersized Developer Profile
2 plugins · 70 total installs
How We Detect Envoke Supersized
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/envoke-supersized/assets/css/envoke_supersized.min.css/wp-content/plugins/envoke-supersized/assets/js/enss-front-end.min.js/wp-content/plugins/envoke-supersized/assets/js/enss-front-end.min.jsenvoke-supersized/assets/css/envoke_supersized.min.css?ver=envoke-supersized/assets/js/enss-front-end.min.js?ver=HTML / DOM Fingerprints
enss-overlayenss-containerenss-overlay-load-itemthumbnail navigation currently not used at allThumbnail NavigationArrow NavigationTime Bar+5 moreid="supersized_overlay"id="prevthumb"id="nextthumb"id="prevslide"id="nextslide"id="thumb-tray"+16 moreENSS