flshow Manager Security & Risk Analysis

wordpress.org/plugins/flshow-manager

This plugin adds a management interface for the flShow photo carousel as well as template tags to insert the carousel into your WordPress template.

10 active installs v1.1.1 PHP + WP 2.5+ Updated Unknown
carouselflashgalleryphotosslideshow
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is flshow Manager Safe to Use in 2026?

Generally Safe

Score 100/100

flshow Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The flshow-manager v1.1.1 plugin exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in avoiding dangerous functions and using prepared statements for SQL queries, the complete lack of capability checks on its six AJAX entry points is a major vulnerability. This means any user, regardless of their WordPress role, can trigger these actions, potentially leading to unauthorized operations or information disclosure.

The taint analysis reveals that a high percentage of data flows involve unsanitized paths, although no critical or high severity issues were flagged. This suggests a potential for input manipulation, but the lack of documented vulnerabilities in its history is a positive sign. However, the absence of vulnerabilities can sometimes indicate a lack of rigorous security auditing or that past issues were not publicly disclosed.

In conclusion, the plugin has strengths in its SQL handling and lack of known serious code flaws. Nevertheless, the unprotected AJAX handlers and the taint analysis findings present a notable risk. It is crucial to implement proper authentication and authorization checks for all AJAX actions to mitigate these risks. Until these are addressed, the plugin should be considered with caution.

Key Concerns

  • 6 AJAX handlers without auth checks
  • 75 outputs, 0% properly escaped
  • Flows with unsanitized paths
  • Nonce checks: 1 (out of 6 entry points)
  • Capability checks: 0
Vulnerabilities
None known

flshow Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

flshow Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
75
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped75 total outputs
Data Flows
7 unsanitized

Data Flow Analysis

8 flows7 with unsanitized paths
process_finalize (flshow.php:225)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

flshow Manager Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_flshow_sortflshow.php:36
authwp_ajax_flshow_uploadflshow.php:37
authwp_ajax_flshow_findflshow.php:38
authwp_ajax_flshow_enqueueflshow.php:39
authwp_ajax_flshow_dequeueflshow.php:40
authwp_ajax_flshow_manage_rowsflshow.php:41
WordPress Hooks 5
actionadmin_menuflshow.php:35
actionmedia_upload_flShow-newflshow.php:44
actionmedia_upload_flShow-imagesflshow.php:45
actionmedia_upload_flShow-finalizeflshow.php:46
filtermedia_upload_tabsflshow.php:97
Maintenance & Trust

flshow Manager Maintenance & Trust

Maintenance Signals

WordPress version tested2.7
Last updatedUnknown
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

flshow Manager Developer Profile

Amie

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect flshow Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flshow-manager/resources/jquery.tablednd.js/wp-content/plugins/flshow-manager/resources/flShow.js/wp-content/plugins/flshow-manager/resources/swfobject.js/wp-content/plugins/flshow-manager/resources/flshow.css
Script Paths
resources/jquery.tablednd.jsresources/flShow.jsresources/swfobject.js
Version Parameters
flshow-manager/resources/flshow.css?ver=

HTML / DOM Fingerprints

CSS Classes
flshow-management-nav
Data Attributes
data-flshow-settings
JS Globals
flshow
REST Endpoints
/wp-json/flshow-manager/v1/settings
Shortcode Output
[flshow-manager id=
FAQ

Frequently Asked Questions about flshow Manager