Feslider – Featured Slider Security & Risk Analysis

wordpress.org/plugins/feslider

Image slider that act like featured image, its featured slider!

80 active installs v1.3 PHP + WP 4.0+ Updated Feb 15, 2023
featured-imagefeatured-sliderfeatured-slideshowresponsive-slidersingle-slider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Feslider – Featured Slider Safe to Use in 2026?

Generally Safe

Score 85/100

Feslider – Featured Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The feslider plugin v1.3 exhibits a generally good security posture based on the static analysis. The absence of known CVEs and the presence of nonce and capability checks are positive indicators. The plugin also demonstrates good practice by exclusively using prepared statements for SQL queries and not performing file operations or external HTTP requests, further limiting potential attack vectors.

However, a significant concern arises from the output escaping. With 40 total outputs and only 5% properly escaped, there is a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied data or dynamically generated content, if not handled carefully, could be injected and executed in the browser of other users. The lack of any taint analysis flows being reported might be due to the nature of the static analysis tool used or the specific code structure, but it doesn't negate the observed output escaping deficiency.

Despite the limited entry points and absence of critical security signals like dangerous functions or unsanitized taint flows, the poor output escaping represents a tangible and common security risk. The plugin's history of zero vulnerabilities might suggest diligent development or a lack of prior scrutiny, but the current code analysis reveals a weakness that needs immediate attention. A balanced conclusion is that while the plugin avoids many common pitfalls, the prevalent lack of output escaping creates a significant security concern that could be exploited.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Feslider – Featured Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Feslider – Featured Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
2 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

5% escaped40 total outputs
Attack Surface

Feslider – Featured Slider Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[feslider] feslider.php:25
WordPress Hooks 8
actionadd_meta_boxesfeslider.php:22
actionadmin_enqueue_scriptsfeslider.php:23
actionsave_postfeslider.php:24
actionadmin_menufeslider.php:26
actionadmin_initfeslider.php:27
filterthe_contentfeslider.php:28
filterget_post_metadatafeslider.php:29
filterpost_thumbnail_htmlfeslider.php:30
Maintenance & Trust

Feslider – Featured Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 15, 2023
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings5
Active installs80
Developer Profile

Feslider – Featured Slider Developer Profile

Haris

4 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Feslider – Featured Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/feslider/lib/style-admin.css/wp-content/plugins/feslider/lib/slider-pro/css/slider-pro.min.css/wp-content/plugins/feslider/lib/style-frontend.css/wp-content/plugins/feslider/lib/slider-pro/js/jquery.sliderPro.min.js/wp-content/plugins/feslider/lib/select2/select2.min.css/wp-content/plugins/feslider/lib/select2/select2.min.js
Script Paths
/wp-content/plugins/feslider/lib/slider-pro/js/jquery.sliderPro.min.js
Version Parameters
feslider/lib/slider-pro/js/jquery.sliderPro.min.js?ver=1.6.0

HTML / DOM Fingerprints

CSS Classes
feslider-sliderfeslider-image-wrap
HTML Comments
<!-- Feslider - Featured Slider --><!-- Use nonce for verification -->
Data Attributes
data-id="feslider_image_id"data-url="feslider_image_url"data-thumb="feslider_image_thumb"
JS Globals
feslider
Shortcode Output
[feslider]
FAQ

Frequently Asked Questions about Feslider – Featured Slider