Left right image slideshow gallery Security & Risk Analysis

wordpress.org/plugins/left-right-image-slideshow-gallery

Left right image slideshow gallery lets showcase images in a horizontal move style. Single image at a time and pull one by one continually.

60 active installs v12.1 PHP + WP 3.4+ Updated Oct 28, 2023
galleryimageslideshow
84
B · Generally Safe
CVEs total1
Unpatched0
Last CVEOct 30, 2023
Safety Verdict

Is Left right image slideshow gallery Safe to Use in 2026?

Mostly Safe

Score 84/100

Left right image slideshow gallery is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVELast CVE: Oct 30, 2023Updated 2yr ago
Risk Assessment

The 'left-right-image-slideshow-gallery' plugin version 12.1 presents a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries, with 96% utilizing prepared statements, and it has no identified critical or high severity taint flows. The absence of file operations and external HTTP requests further reduces potential attack vectors.

However, concerns arise from the output escaping, where only 54% of outputs are properly escaped, leaving a significant portion potentially vulnerable to Cross-Site Scripting (XSS) attacks. The presence of one high-severity SQL injection vulnerability in its history, though currently unpatched, indicates a past weakness that users should be aware of. While the plugin has no unpatched vulnerabilities currently, the historical pattern suggests potential for such issues.

In conclusion, the plugin has made significant strides in secure coding with its SQL handling and taint analysis. Nevertheless, the insufficient output escaping and the historical high-severity SQL injection vulnerability warrant caution. Users should ensure the plugin is updated to the latest version to mitigate any historical risks and remain vigilant about potential XSS vulnerabilities stemming from improper output sanitization.

Key Concerns

  • High percentage of outputs not properly escaped
  • Past high severity SQL injection vulnerability
Vulnerabilities
1

Left right image slideshow gallery Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2023-5431high · 8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Left right image slideshow gallery <= 12.0 - Authenticated (Subscriber+) SQL Injection via Shortcode

Oct 30, 2023 Patched in 12.1 (85d)
Code Analysis
Analyzed Mar 17, 2026

Left right image slideshow gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
23 prepared
Unescaped Output
30
35 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

96% prepared24 total queries

Output Escaping

54% escaped65 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<image-management-show> (pages\image-management-show.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Left right image slideshow gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[lr-slideshow] left-right-image-slideshow-gallery.php:176
WordPress Hooks 5
actionplugins_loadedleft-right-image-slideshow-gallery.php:311
actionwp_enqueue_scriptsleft-right-image-slideshow-gallery.php:312
actionplugins_loadedleft-right-image-slideshow-gallery.php:313
actionadmin_menuleft-right-image-slideshow-gallery.php:316
actionadmin_enqueue_scriptsleft-right-image-slideshow-gallery.php:317
Maintenance & Trust

Left right image slideshow gallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedOct 28, 2023
PHP min version
Downloads26K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Left right image slideshow gallery Developer Profile

gopiplus

52 plugins · 19K total installs

76
trust score
Avg Security Score
83/100
Avg Patch Time
70 days
View full developer profile
Detection Fingerprints

How We Detect Left right image slideshow gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/left-right-image-slideshow-gallery/images/250x167_1.jpg/wp-content/plugins/left-right-image-slideshow-gallery/images/250x167_2.jpg/wp-content/plugins/left-right-image-slideshow-gallery/images/250x167_3.jpg/wp-content/plugins/left-right-image-slideshow-gallery/images/250x167_4.jpg

HTML / DOM Fingerprints

Data Attributes
id="Lrisg_widgetss"Lrisg_WrapperidLrisg_WidthHeightLrisg_ImageArrayLrisg_DisplaymodeLrisg_Orientation+9 more
JS Globals
Lrisg_SlideShowLrisg_Show
Shortcode Output
[lr-slideshow]
FAQ

Frequently Asked Questions about Left right image slideshow gallery