
LM Easy Slider Security & Risk Analysis
wordpress.org/plugins/lm-easy-sliderLM Easy Slider is a plugin designed to make easy to insert sliders into a post, page or widget.
Is LM Easy Slider Safe to Use in 2026?
Generally Safe
Score 85/100LM Easy Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lm-easy-slider" v1.0 plugin exhibits a mixed security posture. On the positive side, it has a very small attack surface with only one shortcode as an entry point, and importantly, there are no identified AJAX handlers or REST API routes lacking proper authentication or permission checks. Furthermore, its vulnerability history is clean, with no known CVEs or past security issues, which is a strong indicator of potentially good development practices in that regard. The presence of nonce and capability checks is also a positive sign for basic security implementations.
However, the static analysis reveals significant concerns. The use of the `create_function` function is a critical red flag, as it can lead to arbitrary code execution if not handled with extreme care, and its mere presence suggests potential for future vulnerabilities. The fact that 100% of its SQL queries are not using prepared statements is a major risk for SQL injection vulnerabilities. Coupled with only 30% of output being properly escaped, this plugin is highly susceptible to cross-site scripting (XSS) attacks. Taint analysis showing zero flows analyzed is not necessarily a positive; it might indicate the analysis tool had limitations or the code structure didn't lend itself to this type of automated flow tracing.
In conclusion, while the plugin's limited attack surface and clean vulnerability history are commendable, the critical code signals related to SQL, output escaping, and the use of `create_function` present substantial security risks. The absence of taint analysis results is inconclusive but doesn't negate the clear risks identified in other areas. Users should be highly cautious until these significant code-level vulnerabilities are addressed.
Key Concerns
- Raw SQL queries without prepared statements
- Low percentage of properly escaped output
- Dangerous function used (create_function)
LM Easy Slider Security Vulnerabilities
LM Easy Slider Release Timeline
LM Easy Slider Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
LM Easy Slider Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
LM Easy Slider Maintenance & Trust
Maintenance Signals
Community Trust
LM Easy Slider Alternatives
Ultimate Responsive Image Slider
ultimate-responsive-image-slider
Create stunning responsive sliders in minutes. Drag-and-drop builder, unlimited sliders, mobile-friendly & SEO optimized!
Image Gallery Block – Create and display photo gallery/photo album.
3d-image-gallery
Image Gallery Block helps you create responsive photo galleries, masonry layouts, and 3D sliders. Offers professional layouts and lightbox effects.
Gallery – Photo Albums Plugin
easy-media-gallery
Image Gallery – Photo Albums Plugin is the easiest tool to create image gallery, photo albums, portfolio and also photo slider.
Responsive Slider Gallery
responsive-slider-gallery
Build image slideshows with drag-and-drop. A simple responsive slider for posts, pages, and widgets with custom navigation styles.
Gallery Images Ape
gallery-images-ape
Image gallery, responsive photo gallery grid, customizable image slider, simple interface, links, video links and lightbox, custom themes, thumbnails
LM Easy Slider Developer Profile
2 plugins · 20 total installs
How We Detect LM Easy Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lm-easy-slider/front-end/slider.js/wp-content/plugins/lm-easy-slider/dist/js/bootstrap.min.js/wp-content/plugins/lm-easy-slider/dist/css/bootstrap.min.css/wp-content/plugins/lm-easy-slider/front-end/slider.cssdist/js/bootstrap.min.jsfront-end/slider.jslm-easy-slider/style.css?ver=lm-easy-slider/script.js?ver=HTML / DOM Fingerprints
imageFramecheckImageimmaginebutton-preview-wrapper<!-- THE KEY BUSINESS --><!-- Per disabilitare il submit quando il titolo è vuoto -->id="upload_image_button"id="newid="img-id="myplugin-image-inputnewname="myplugin_attachment_id_array[]"id="result"+6 moremyplugin_media_uploadlmEasySlider_checkDeletestringaIdChecknImages<div class="carousel slide"><div class="carousel-inner"><div class="carousel-item"><a href="