Jeba Social Slide Security & Risk Analysis

wordpress.org/plugins/jebe-cute-social-slide

Jeba Social Slide is an awesome Filter, super lightweight plugin for your wordpress website social slide.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Nov 13, 2014
awesome-social-sliderawosome-slidejeba-social-slidesocial-slider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Jeba Social Slide Safe to Use in 2026?

Generally Safe

Score 85/100

Jeba Social Slide has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The static analysis of jebe-cute-social-slide v1.0 reveals a plugin with a seemingly minimal attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that could serve as direct entry points for attackers. Furthermore, the absence of dangerous function calls and the exclusive use of prepared statements for SQL queries are positive indicators of secure coding practices in these areas.

However, a significant concern arises from the output escaping. With 100% of its output not being properly escaped, the plugin is highly vulnerable to Cross-Site Scripting (XSS) attacks. Any data rendered by the plugin without proper sanitization could be exploited by attackers to inject malicious scripts into the user's browser. The lack of any nonce or capability checks, while not directly exploitable due to the absence of entry points, indicates a general oversight in security best practices that could become a liability if new entry points were added in future versions.

The vulnerability history is notably clean, with no recorded CVEs. This suggests that the plugin has historically been free of publicly disclosed vulnerabilities or has not been a target for such disclosures. Coupled with the small number of code signals indicating potential issues, this might imply a less complex plugin or one that has been carefully developed and maintained concerning known security flaws. Despite the current lack of exploitable entry points and historical vulnerabilities, the critical failure in output escaping presents a substantial and immediate risk.

Key Concerns

  • 100% of output unescaped
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Jeba Social Slide Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Jeba Social Slide Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Jeba Social Slide Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery

Output Escaping

0% escaped12 total outputs
Attack Surface

Jeba Social Slide Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitjeba-social-index.php:13
actioninitjeba-social-index.php:19
actionwp_footerjeba-social-index.php:26
actionwp_footerjeba-social-index.php:37
actionadmin_menujeba-social-index.php:46
actionadmin_initjeba-social-index.php:68
actionwp_footerjeba-social-index.php:231
Maintenance & Trust

Jeba Social Slide Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedNov 13, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Jeba Social Slide Alternatives

No alternatives data available yet.

Developer Profile

Jeba Social Slide Developer Profile

Md Jahed

12 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Jeba Social Slide

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jebe-cute-social-slide/jeba/social.slider.jquery.min.css/wp-content/plugins/jebe-cute-social-slide/jeba/social.slider.jquery.min.js
Version Parameters
jeba-formss-cssjebacuteformss-js

HTML / DOM Fingerprints

CSS Classes
j_donate
HTML Comments
5.1. Add settings API hook under form action.5.2. If the form has just been submitted, this shows the notification6.1 Add settings API hook under form action.6.2 This function outputs some hidden fields required by the form, including a nonce, a unique number used to ensure the form has been submitted from the admin page and not somewhere else, very important for security
Data Attributes
jeba_facebook_idjeba_twitter_idjeba_twitter_widget_idjeba_linkedin_idjeba_google_idjeba_youtube_id
JS Globals
jQuery$
Shortcode Output
<div id="social-slider"></div>
FAQ

Frequently Asked Questions about Jeba Social Slide