
GPP Slideshow Security & Risk Analysis
wordpress.org/plugins/gpp-slideshowA minimalist slideshow plugin that creates a new gallery post type. Add slideshows to widgets, posts, pages and gallery posts.
Is GPP Slideshow Safe to Use in 2026?
Use With Caution
Score 63/100GPP Slideshow has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The gpp-slideshow plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and includes some capability checks and a nonce check. There are no detected dangerous functions or external HTTP requests, and it doesn't bundle external libraries. However, a significant concern arises from the presence of an unprotected AJAX handler, which represents a direct entry point for potential attacks without proper authentication or authorization.
The static analysis did not reveal any taint flows, which is a positive indicator. Nevertheless, the limited output escaping (only 6% properly escaped) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities in the plugin's output, even if not explicitly flagged by the taint analysis in this run. The plugin has a history of a medium severity vulnerability related to missing authorization, and the fact that this vulnerability is currently unpatched is a critical red flag.
In conclusion, while the plugin shows some security strengths in areas like SQL handling, the unprotected AJAX endpoint and the unpatched medium-severity vulnerability significantly detract from its overall security. The poor output escaping further compounds these risks, making the plugin a notable security concern that requires immediate attention and patching.
Key Concerns
- Unpatched CVE
- Unprotected AJAX handler
- Low output escaping percentage
GPP Slideshow Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
GPP Slideshow <= 1.3.5 - Missing Authorization
GPP Slideshow Code Analysis
SQL Query Safety
Output Escaping
GPP Slideshow Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 28
Maintenance & Trust
GPP Slideshow Maintenance & Trust
Maintenance Signals
Community Trust
GPP Slideshow Alternatives
WPJaipho Mobile Gallery
wpjaipho
WPJaipho extends native Wordpress image gallery, NextGEN 1.x and NextCellent Gallery with optimized support for mobile users
NextGEN Gallery Date
nextgen-gallery-date
This plugin will let you sort the galleries by date and get info about gallery creation (and modification) date.
SSP Director Tools
ssp-director-tools
SSP Director Tools give you means for integrating SlideShowPro Director content into a WordPress blog.
Lightbox with PhotoSwipe
lightbox-photoswipe
Integration of PhotoSwipe (http://photoswipe.com) for WordPress.
Embed Google Photos album
embed-google-photos-album-easily
Embed Google Photos album using Player widget.
GPP Slideshow Developer Profile
7 plugins · 1K total installs
How We Detect GPP Slideshow
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gpp-slideshow/css/style.cssgpp-slideshow/css/style.css?ver=HTML / DOM Fingerprints
gpp_slideshow_wrappereachthumbsgpp_gallery_hiddenidsgpp_gallery_meta_box[gallery ids=