HT Slider For Elementor Security & Risk Analysis

wordpress.org/plugins/ht-slider-for-elementor

The HT Slider is an Elementor slider plugin that enables you to add advanced sliders to your WordPress website.

20K active installs v1.7.6 PHP + WP 5.0+ Updated Jan 1, 2026
elementorelementor-addonspost-type-slidersliderwidgets
96
A · Safe
CVEs total3
Unpatched0
Last CVEDec 12, 2025
Safety Verdict

Is HT Slider For Elementor Safe to Use in 2026?

Generally Safe

Score 96/100

HT Slider For Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Dec 12, 2025Updated 3mo ago
Risk Assessment

The ht-slider-for-elementor v1.7.6 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a good adherence to several security best practices, including the absence of direct SQL queries without prepared statements and a high percentage of properly escaped output. It also demonstrates a commitment to using nonces and capability checks, and importantly, has no currently unpatched CVEs. However, the presence of three medium-severity vulnerabilities in its history, specifically Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF), is a notable concern. The last vulnerability being in late 2025 suggests a recent history of issues, even if they are now patched. The static analysis shows two unsanitized paths in taint analysis, which, although not classified as critical or high severity, warrants attention as these could potentially lead to security weaknesses if not handled with utmost care. The external HTTP requests, while not inherently a vulnerability, increase the plugin's attack surface and potential for supply chain risks.

Key Concerns

  • History of medium severity CVEs (XSS, CSRF)
  • Taint analysis shows unsanitized paths
  • External HTTP requests present
Vulnerabilities
3

HT Slider For Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-14278medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

HT Slider for Elementor <= 1.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 12, 2025 Patched in 1.7.5 (1d)
CVE-2025-53199medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

HT Slider For Elementor <= 1.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jun 27, 2025 Patched in 1.6.6 (6d)
CVE-2023-0495medium · 4.3Cross-Site Request Forgery (CSRF)

HT Slider For Elementor <= 1.3.9 - Cross-Site Request Forgery to Arbitrary Plugin Activation

Feb 28, 2023 Patched in 1.4.0 (329d)
Code Analysis
Analyzed Mar 16, 2026

HT Slider For Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
171 escaped
Nonce Checks
3
Capability Checks
7
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

86% escaped200 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
templates_ajax_request (include\admin\template-library.php:174)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

HT Slider For Elementor Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 4

authwp_ajax_htslider_noticesinclude\admin\class-notices.php:52
authwp_ajax_ht-slider_ajax_plugin_activationinclude\admin\Class_Recommended_Plugins.php:81
authwp_ajax_htslider_ajax_requestinclude\admin\template-library.php:24
noprivwp_ajax_htslider_ajax_requestinclude\admin\template-library.php:25

Shortcodes 1

[htslider] include\shortcode\htslider-shortcode.php:153
WordPress Hooks 29
actionadmin_noticesinclude\admin\class-notices.php:49
actionhtslider_admin_noticesinclude\admin\class-notices.php:50
actionadmin_footerinclude\admin\class-notices.php:51
actionadmin_menuinclude\admin\Class_Recommended_Plugins.php:77
actionadmin_enqueue_scriptsinclude\admin\Class_Recommended_Plugins.php:78
actionadmin_menuinclude\admin\template-library.php:23
actionadmin_enqueue_scriptsinclude\admin\template-library.php:27
actioninitinclude\class.htslider.php:17
actionplugins_loadedinclude\class.htslider.php:18
actionadmin_menuinclude\class.htslider.php:19
actionafter_setup_themeinclude\class.htslider.php:20
actionelementor/elements/categories_registeredinclude\class.htslider.php:21
filtersingle_templateinclude\class.htslider.php:22
actionwp_enqueue_scriptsinclude\class.htslider.php:23
actionelementor/editor/after_enqueue_stylesinclude\class.htslider.php:26
actionadmin_menuinclude\class.htslider.php:28
actionadmin_headinclude\class.htslider.php:29
actionadmin_headinclude\class.htslider.php:30
actionadmin_noticesinclude\class.htslider.php:33
actionadmin_noticesinclude\class.htslider.php:42
actionadmin_noticesinclude\class.htslider.php:47
actionadmin_noticesinclude\class.htslider.php:56
actionelementor/widgets/registerinclude\class.htslider.php:62
actionelementor/widgets/widgets_registeredinclude\class.htslider.php:64
actioninitinclude\class.htslider.php:253
actioninitinclude\custom-post-type.php:64
actioninitinclude\custom-post-type.php:111
filterviews_edit-htslider_sliderinclude\helpers_function.php:104
actionhtslider_slider_cat_pre_add_forminclude\helpers_function.php:105
Maintenance & Trust

HT Slider For Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 1, 2026
PHP min version
Downloads475K

Community Trust

Rating76/100
Number of ratings12
Active installs20K
Developer Profile

HT Slider For Elementor Developer Profile

HT Plugins

23 plugins · 64K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
124 days
View full developer profile
Detection Fingerprints

How We Detect HT Slider For Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ht-slider-for-elementor/assets/css/elementor-addon-main.css/wp-content/plugins/ht-slider-for-elementor/assets/css/swiper.min.css/wp-content/plugins/ht-slider-for-elementor/assets/css/font-awesome.min.css/wp-content/plugins/ht-slider-for-elementor/assets/js/elementor-addon-main.js/wp-content/plugins/ht-slider-for-elementor/assets/js/swiper.min.js/wp-content/plugins/ht-slider-for-elementor/assets/admin/css/ht-slider-admin.css/wp-content/plugins/ht-slider-for-elementor/assets/admin/js/ht-slider-admin.js/wp-content/plugins/ht-slider-for-elementor/assets/admin/js/plugins_install_manager.js
Script Paths
/wp-content/plugins/ht-slider-for-elementor/assets/js/elementor-addon-main.js/wp-content/plugins/ht-slider-for-elementor/assets/js/swiper.min.js/wp-content/plugins/ht-slider-for-elementor/assets/admin/js/ht-slider-admin.js/wp-content/plugins/ht-slider-for-elementor/assets/admin/js/plugins_install_manager.js
Version Parameters
ht-slider-for-elementor/assets/css/elementor-addon-main.css?ver=ht-slider-for-elementor/assets/css/swiper.min.css?ver=ht-slider-for-elementor/assets/css/font-awesome.min.css?ver=ht-slider-for-elementor/assets/js/elementor-addon-main.js?ver=ht-slider-for-elementor/assets/js/swiper.min.js?ver=ht-slider-for-elementor/assets/admin/css/ht-slider-admin.css?ver=ht-slider-for-elementor/assets/admin/js/ht-slider-admin.js?ver=ht-slider-for-elementor/assets/admin/js/plugins_install_manager.js?ver=

HTML / DOM Fingerprints

CSS Classes
htslider-section-wrapperhtslider-slider-areahtslider-slide-itemhtslider-slide-contenthtslider-slide-titlehtslider-slide-descriptionhtslider-slide-buttonhtrp-extension-admin-tab-area+3 more
HTML Comments
<!-- Recommended Plugins handlers class --><!-- Add Recommended Menu --><!-- Thickbox assest --><!-- localize data -->+1 more
Data Attributes
data-htslider-nav-prevdata-htslider-nav-nextdata-htslider-pagination
JS Globals
htrp_paramshtSliderElementorFrontend
REST Endpoints
/wp-json/ht-slider/v1/settings/wp-json/ht-slider/v1/slider
Shortcode Output
[ht_slider id=""]
FAQ

Frequently Asked Questions about HT Slider For Elementor