Frontpage Slider Security & Risk Analysis

wordpress.org/plugins/frontpage-slider

Frontpage slider with predesigned templates. Different templates for different themes.

20 active installs v1.0.6 PHP 7.3+ WP 5.3+ Updated Unknown
carouselfrontpage-sliderheader-sliderimage-sliderslider
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Frontpage Slider Safe to Use in 2026?

Generally Safe

Score 100/100

Frontpage Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'frontpage-slider' plugin v1.0.6 exhibits a generally good security posture, with no known CVEs in its history and a commendable approach to SQL query sanitization using prepared statements. The static analysis also shows no critical or high severity taint flows, and a lack of dangerous functions or file operations. However, the plugin's security is not without concerns. A significant portion of its output (41%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is incorporated into these outputs. Additionally, the absence of nonce checks across all entry points, combined with the presence of capability checks on only a limited basis, presents a potential weakness. While the attack surface of direct entry points like AJAX and REST API is zero, the six shortcodes represent a surface that could be exploited if they handle user input without proper validation and sanitization, especially in conjunction with the unescaped output.

Key Concerns

  • Significant amount of unescaped output
  • No nonce checks on entry points
  • Limited capability checks
Vulnerabilities
None known

Frontpage Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Frontpage Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
163
234 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

59% escaped397 total outputs
Data Flows
All sanitized

Data Flow Analysis

12 flows
fpsl_instructions (templates\aaTopSlider\AAtopSlider_metaB.php:30)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Frontpage Slider Attack Surface

Entry Points6
Unprotected0

Shortcodes 6

[AAtopSlider] templates\aaTopSlider\slider-section.php:86
[bannerSlider] templates\bannerSlider\slider-section.php:58
[FavoriteProducts] templates\favoriteProducts\slider-section.php:26
[headerSlider] templates\headerSlider\slider-section.php:80
[productSlider] templates\productSlider\slider-section.php:40
[topCategories] templates\topCategories\slider-section.php:62
WordPress Hooks 21
actioninitfrontpage-slider.php:47
actionwp_enqueue_scriptsfrontpage-slider.php:52
actionwp_headfrontpage-slider.php:53
actionafter_setup_themefrontpage-slider.php:54
actionadmin_menufrontpage-slider.php:55
actionadd_meta_boxesinc\metaboxes\product_meta_boxes.php:8
actionsave_postinc\metaboxes\product_meta_boxes.php:9
actionadd_meta_boxesinc\metaboxes\slider_meta_box.php:12
actionsave_postinc\metaboxes\slider_meta_box.php:13
actionadd_meta_boxestemplates\aaTopSlider\AAtopSlider_metaB.php:11
actionsave_posttemplates\aaTopSlider\AAtopSlider_metaB.php:12
actionadd_meta_boxestemplates\bannerSlider\bannerSlider_metaB.php:11
actionsave_posttemplates\bannerSlider\bannerSlider_metaB.php:12
actionadd_meta_boxestemplates\favoriteProducts\favoriteProducts_metaB.php:11
actionsave_posttemplates\favoriteProducts\favoriteProducts_metaB.php:12
actionadd_meta_boxestemplates\headerSlider\headerSlider_metaB.php:14
actionsave_posttemplates\headerSlider\headerSlider_metaB.php:15
actionadd_meta_boxestemplates\productSlider\productSlider_metaB.php:11
actionsave_posttemplates\productSlider\productSlider_metaB.php:12
actionadd_meta_boxestemplates\topCategories\topCategories_metaB.php:11
actionsave_posttemplates\topCategories\topCategories_metaB.php:12
Maintenance & Trust

Frontpage Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.3
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

Frontpage Slider Developer Profile

Milkan Trninic

2 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Frontpage Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/frontpage-slider/public/css/swiper.min.css/wp-content/plugins/frontpage-slider/public/css/custom_swiper.css/wp-content/plugins/frontpage-slider/templates/aaTopSlider/css/aa-top-slider.css
Script Paths
/wp-content/plugins/frontpage-slider/public/js/swiper-bundle.min.js/wp-content/plugins/frontpage-slider/templates/aaTopSlider/js/aatopslider.js
Version Parameters
frontpage-slider/public/css/swiper.min.css?ver=frontpage-slider/public/css/custom_swiper.css?ver=frontpage-slider/public/js/swiper-bundle.min.js?ver=frontpage-slider/templates/aaTopSlider/js/aatopslider.js?ver=

HTML / DOM Fingerprints

CSS Classes
aatopslider
Data Attributes
data-swiper-slide-index
Shortcode Output
<div class="aatopslider swiper-container" style="height:100%;"><div class="swiper-wrapper">
FAQ

Frequently Asked Questions about Frontpage Slider