HAQ Slider Security & Risk Analysis

wordpress.org/plugins/haq-slider

Allows you to add fully customizable, responsive. This plugin creates an image slide in your theme. You can upload/delete images via the admin panel,

0 active installs v2.0.1 PHP + WP 4.0+ Updated Jul 30, 2024
images-sliderjquery-sliderslide-effectsliderslideshow
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HAQ Slider Safe to Use in 2026?

Generally Safe

Score 92/100

HAQ Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'haq-slider' plugin version 2.0.1 exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are positive indicators. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding external HTTP requests. The attack surface is minimal, with only one shortcode and no unprotected entry points identified.

However, there are notable areas for improvement. The most significant concern is the low percentage of properly escaped output, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. The lack of nonce checks and capability checks, while not immediately leading to exploitable issues given the limited attack surface and zero unprotected entry points, represents a missed opportunity to strengthen security against potential future vulnerabilities or more sophisticated attack vectors. The plugin also performs file operations, which, without specific context or demonstrated vulnerabilities, warrants a cautious approach, especially when combined with the low output escaping.

In conclusion, 'haq-slider' v2.0.1 is not demonstrably vulnerable in its current state according to the provided data, due to its small attack surface and reliance on prepared statements. However, the insufficient output escaping remains a significant weakness that could be exploited. The absence of robust authentication checks on its single entry point is a risk that should be addressed to improve its overall security posture.

Key Concerns

  • Low output escaping percentage
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

HAQ Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

HAQ Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
36
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
5
External Requests
0
Bundled Libraries
0

Output Escaping

10% escaped40 total outputs
Attack Surface

HAQ Slider Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[haq_slider] haq-slider.php:100
WordPress Hooks 5
actionadmin_initfunction.php:17
actionadmin_menuhaq-slider.php:20
actionwp_print_scriptshaq-slider.php:109
actionwp_footerhaq-slider.php:115
actionwp_headhaq-slider.php:135
Maintenance & Trust

HAQ Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 30, 2024
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

HAQ Slider Developer Profile

Husain Ahmed

4 plugins · 4K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HAQ Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/haq-slider/media/js/haqslider.all.min.js
Script Paths
/wp-content/plugins/haq-slider/media/js/haqslider.all.min.js

HTML / DOM Fingerprints

CSS Classes
haq_slider
Data Attributes
data-haq-slider
JS Globals
haq_settingshaqSliderImage
Shortcode Output
<div id="haq-slider-wrapper">
FAQ

Frequently Asked Questions about HAQ Slider