Responsive WordPress Slider – HG Slider Security & Risk Analysis

wordpress.org/plugins/flexslider-hg

A responsive image rotator plugin that easily creates WordPress slideshows. Now 100% Organic!

7K active installs v2.1 PHP + WP + Updated Mar 30, 2021
attachmentsflexslidergalleryrotatorslider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Responsive WordPress Slider – HG Slider Safe to Use in 2026?

Generally Safe

Score 85/100

Responsive WordPress Slider – HG Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The flexslider-hg v2.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no direct SQL queries without prepared statements, and no file operations or external HTTP requests, which are all good indicators. The absence of known vulnerabilities in its history is also a significant strength, suggesting a history of responsible development or a lack of discoverable flaws.

However, there are notable areas of concern. The plugin has a relatively low percentage of properly escaped output (37%), which could leave it susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully within its shortcodes. Furthermore, the complete absence of nonce checks and capability checks is a significant security gap. While the current entry points (shortcodes) are not directly exposed via AJAX or REST API without checks, the lack of these fundamental security mechanisms means that if the plugin were to be extended or if new entry points were introduced in the future, it would be inherently less secure. The taint analysis showing zero flows is good, but this is often a reflection of limited test cases or very straightforward code, not necessarily a guarantee of absolute safety, especially when combined with the output escaping and auth check deficiencies.

In conclusion, while flexslider-hg v2.1 has a clean vulnerability history and avoids several common risky coding practices, the insufficient output escaping and the complete lack of nonce and capability checks present tangible risks. The strengths lie in its minimal external dependencies and direct database interaction safety, but the weaknesses in input validation and authorization mechanisms warrant attention.

Key Concerns

  • Insufficient output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Responsive WordPress Slider – HG Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Responsive WordPress Slider – HG Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

37% escaped30 total outputs
Attack Surface

Responsive WordPress Slider – HG Slider Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[flexslider] flexslider-hg.php:96
[hgslider] flexslider-hg.php:97
WordPress Hooks 14
actionplugins_loadedflexslider-hg.php:16
actioninitflexslider-hg.php:82
actionadmin_headflexslider-hg.php:83
actionwp_enqueue_scriptsflexslider-hg.php:84
actionadd_meta_boxesflexslider-hg.php:86
actionadd_meta_boxesflexslider-hg.php:87
actionsave_postflexslider-hg.php:88
filtermanage_edit-slides_columnsflexslider-hg.php:90
actionmanage_slides_posts_custom_columnflexslider-hg.php:91
filtermanage_edit-sliders_columnsflexslider-hg.php:93
actionmanage_sliders_posts_custom_columnflexslider-hg.php:94
actionadmin_menuflexslider-hg.php:99
filterenter_title_hereflexslider-hg.php:101
filterplugin_action_linksflexslider-hg.php:651
Maintenance & Trust

Responsive WordPress Slider – HG Slider Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 30, 2021
PHP min version
Downloads57K

Community Trust

Rating76/100
Number of ratings12
Active installs7K
Developer Profile

Responsive WordPress Slider – HG Slider Developer Profile

richardgabriel

2 plugins · 7K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Responsive WordPress Slider – HG Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flexslider-hg/js/jquery.flexslider-min.js/wp-content/plugins/flexslider-hg/css/flexslider.css
Script Paths
js/jquery.flexslider-min.js
Version Parameters
flexslider-hg/js/jquery.flexslider-min.js?ver=flexslider-hg/css/flexslider.css?ver=

HTML / DOM Fingerprints

CSS Classes
flexslider-hg-wrapperflexslider_hg_flexslider-hg-corners-flexslider-hg-style-flexslider-hg-text-align-slidesslide-contentslide-caption+2 more
Data Attributes
data-flexslider-hg-slugdata-flexslider-hg-speeddata-flexslider-hg-animation-speeddata-flexslider-hg-animationdata-flexslider-hg-directiondata-flexslider-hg-randomize+1 more
JS Globals
jQuery
Shortcode Output
[flexslider slug=""][hgslider slug=""]
FAQ

Frequently Asked Questions about Responsive WordPress Slider – HG Slider