Plugin Name: GMO Showtime Security & Risk Analysis

wordpress.org/plugins/gmo-showtime

GMO Showtime slider plugin gives cool effects to the slider in a snap. The control screen is simple, for anyone to easily use.

200 active installs v1.6 PHP + WP 3.8.1+ Updated Jan 29, 2016
effectssimpleslider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Plugin Name: GMO Showtime Safe to Use in 2026?

Generally Safe

Score 85/100

Plugin Name: GMO Showtime has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "gmo-showtime" plugin v1.6 demonstrates a generally good security posture based on the static analysis and vulnerability history provided. The absence of known CVEs and a clean taint analysis with no unsanitized paths are significant strengths. The plugin also avoids dangerous functions, external HTTP requests, and file operations, further reducing its attack surface. The use of prepared statements for SQL queries is excellent practice. However, a notable concern is the low percentage of properly escaped output (57%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, as untrusted data may be rendered directly in the browser without sufficient sanitization. While there are nonce checks present, the lack of capability checks on any entry points is a weakness, as it means operations might be accessible to users who shouldn't have permission to perform them. The single shortcode represents a potential entry point that, without explicit capability checks, could be a concern.

Key Concerns

  • Low percentage of properly escaped output
  • No capability checks on entry points
Vulnerabilities
None known

Plugin Name: GMO Showtime Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Plugin Name: GMO Showtime Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
35 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

57% escaped61 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
admin_init (gmo-showtime.php:260)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Plugin Name: GMO Showtime Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[showtime] gmo-showtime.php:126
WordPress Hooks 16
actionplugins_loadedgmo-showtime.php:107
actionwp_enqueue_scriptsgmo-showtime.php:120
actionadmin_enqueue_scriptsgmo-showtime.php:121
actionadmin_menugmo-showtime.php:122
actionadmin_initgmo-showtime.php:123
actionadmin_print_footer_scriptsgmo-showtime.php:124
actionwp_before_admin_bar_rendergmo-showtime.php:129
filtergmofontagent_default_tagsgmo-showtime.php:589
actioninitincludes\pan-pan-pan.php:3
actionadmin_menuincludes\pan-pan-pan.php:28
actionsave_postincludes\pan-pan-pan.php:44
actionmanage_posts_custom_columnincludes\pan-pan-pan.php:82
filtermanage_gmo-showtime_posts_columnsincludes\pan-pan-pan.php:133
actionadmin_print_styles-edit.phpincludes\pan-pan-pan.php:134
filtermanage_edit-gmo-showtime_sortable_columnsincludes\pan-pan-pan.php:135
actionadmin_headincludes\pan-pan-pan.php:152
Maintenance & Trust

Plugin Name: GMO Showtime Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJan 29, 2016
PHP min version
Downloads17K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Plugin Name: GMO Showtime Developer Profile

Z.com byGMO

6 plugins · 250 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Plugin Name: GMO Showtime

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gmo-showtime/css/nivo-slider.css/wp-content/plugins/gmo-showtime/js/jquery.nivo.slider.js/wp-content/plugins/gmo-showtime/js/gmo-showtime.js
Script Paths
wp-content/plugins/gmo-showtime/js/jquery.nivo.slider.jswp-content/plugins/gmo-showtime/js/gmo-showtime.js
Version Parameters
gmo-showtime/css/nivo-slider.css?ver=gmo-showtime/js/jquery.nivo.slider.js?ver=gmo-showtime/js/gmo-showtime.js?ver=

HTML / DOM Fingerprints

CSS Classes
gmo-show-timeslider-wrappertheme-defaultslider-boxshowtimenivoSlider
HTML Comments
<!-- Start GMO Showtime-->
Data Attributes
data-columnsdata-transitiondata-show_title
JS Globals
gmo_showtime_url
Shortcode Output
<div id="gmo-show-time" class="slider-wrapper theme-default"><div class="slider-box"><div class="showtime nivoSlider"
FAQ

Frequently Asked Questions about Plugin Name: GMO Showtime