
Image Slider Security & Risk Analysis
wordpress.org/plugins/image-slider-widgetImage Slider - The best and very easy slider plugin for your post, page or sidebar. 100% Responsive.
Is Image Slider Safe to Use in 2026?
Generally Safe
Score 96/100Image Slider has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The image-slider-widget plugin exhibits a mixed security posture. While it demonstrates good practices in using prepared statements for SQL queries and a high percentage of properly escaped outputs, several concerning areas are highlighted by the static analysis. The presence of a dangerous function like `create_function` is a significant red flag, as it can lead to arbitrary code execution if misused. Furthermore, one of the five AJAX handlers lacks authentication checks, creating a potential entry point for unauthorized actions.
The vulnerability history reveals a pattern of past exploitable issues, including critical and high-severity vulnerabilities such as Cross-site Scripting, SQL Injection, Cross-Site Request Forgery, and External Control of File Name or Path. The recurrence of these vulnerability types suggests potential underlying weaknesses in input validation and secure coding practices within the plugin's development. Despite the absence of currently unpatched CVEs, the history indicates a need for ongoing vigilance and thorough code reviews.
In conclusion, while the plugin has strengths in areas like SQL handling and output escaping, the identified dangerous function, unprotected AJAX endpoint, and a history of severe vulnerabilities necessitate caution. These factors collectively present a moderate to high risk that should be addressed through developer review and potential updates.
Key Concerns
- Unprotected AJAX Handler
- Dangerous function (create_function)
- Total known CVEs (5)
- 1 Critical vulnerability in history
- 2 High vulnerabilities in history
- 2 Medium vulnerabilities in history
- Common vulnerability types: XSS, SQLi, CSRF, External File Control
Image Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Image Slider <= 1.1.125 - Authenticated (Editor+) Stored Cross-Site Scripting
Image Slider <= 1.1.119 - Subscriber+ SQL Injection
Image Slider <= 1.1.121 - Cross-Site Request Forgery to Post Duplication
Image Slider <= 1.1.95 - SQL Injection
Image Slider < 1.1.90 - Arbitrary File Deletion
Image Slider Release Timeline
Image Slider Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Image Slider Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 44
Scheduled Events 1
Maintenance & Trust
Image Slider Maintenance & Trust
Maintenance Signals
Community Trust
Image Slider Alternatives
Smart Slider 3
smart-slider-3
Responsive slider plugin to create sliders in visual editor easily. Build beautiful image slider, layer slider, video slider, post slider, and more.
Slider Factory
slider-factory
Build image sliders, photo carousels, and video slideshows with 12 layouts. Drag-and-drop interface with responsive design.
Responsive Slider Gallery
responsive-slider-gallery
Build image slideshows with drag-and-drop. A simple responsive slider for posts, pages, and widgets with custom navigation styles.
Slick Slider
slick-slider
Turn your native WordPress galleries into beautiful fully responsive sliders. Adjust the slider to your needs on a per gallery base.
Responsive Slideshow
slider-responsive-slideshow
Create responsive image sliders with carousel effects, touch navigation, and custom animations for your website.
Image Slider Developer Profile
11 plugins · 21K total installs
How We Detect Image Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-slider-widget/inc/images/ewic-cp-icon.png