Max Slider for Elementor Security & Risk Analysis

wordpress.org/plugins/max-slider

Build Elementor sliders using the Max Slider and Elementor Builder with many variations like animations, arrows, and paginations.

0 active installs v1.3.0 PHP + WP 5.0+ Updated Sep 4, 2024
elementorelementor-addonspost-type-slidersliderwidgets
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Max Slider for Elementor Safe to Use in 2026?

Generally Safe

Score 92/100

Max Slider for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The max-slider plugin v1.3.0 exhibits a generally good security posture with some notable exceptions. The plugin demonstrates strong practices by exclusively using prepared statements for all SQL queries and ensuring a high percentage (91%) of output is properly escaped. The absence of recorded vulnerabilities in its history and the lack of critical or high severity taint flows are positive indicators. However, a significant concern arises from the presence of an unprotected AJAX handler, which represents a direct entry point that could be exploited without authentication. The lack of nonce checks on any AJAX handlers is also a critical oversight, leaving these endpoints vulnerable to Cross-Site Request Forgery (CSRF) attacks. While the plugin has a clean history, the current analysis reveals potential weaknesses that require immediate attention. The plugin's overall security is strong in many areas, but the unprotected AJAX handler and absence of nonce checks on AJAX endpoints introduce substantial risks that need to be mitigated.

Key Concerns

  • Unprotected AJAX handler
  • AJAX handlers without nonce checks
Vulnerabilities
None known

Max Slider for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Max Slider for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
4
41 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared8 total queries

Output Escaping

91% escaped45 total outputs
Attack Surface
1 unprotected

Max Slider for Elementor Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

authwp_ajax_max_slider_select2_search_postinc\max-slider-select2.php:17
authwp_ajax_max_slider_select2_get_titleinc\max-slider-select2.php:18
WordPress Hooks 15
actionadmin_enqueue_scriptsinc\demo-importer\init.php:88
actionadmin_menuinc\demo-importer\init.php:151
actionelementor/controls/registerinc\max-slider-select2.php:16
actioninitinc\slides.php:31
actionadmin_initinc\slides.php:74
actionplugins_loadedmax-slider.php:67
actionadmin_noticesmax-slider.php:87
actionadmin_noticesmax-slider.php:93
actionadmin_noticesmax-slider.php:99
actionelementor/initmax-slider.php:113
actionelementor/frontend/after_register_scriptsplugin.php:58
actionelementor/frontend/after_enqueue_stylesplugin.php:69
actionelementor/editor/after_enqueue_scriptsplugin.php:80
actionelementor/editor/after_enqueue_stylesplugin.php:90
actionelementor/widgets/registerplugin.php:127
Maintenance & Trust

Max Slider for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 4, 2024
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Max Slider for Elementor Developer Profile

maxech

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Max Slider for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/max-slider/assets/js/max-slider-select2.js/wp-content/plugins/max-slider/assets/js/max-slider-importer.js/wp-content/plugins/max-slider/assets/js/max-slider-slides.js/wp-content/plugins/max-slider/assets/css/max-slider-style.css
Script Paths
/wp-content/plugins/max-slider/assets/js/max-slider-select2.js/wp-content/plugins/max-slider/assets/js/max-slider-importer.js/wp-content/plugins/max-slider/assets/js/max-slider-slides.js
Version Parameters
max-slider/assets/js/max-slider-select2.js?ver=max-slider/assets/js/max-slider-importer.js?ver=max-slider/assets/js/max-slider-slides.js?ver=max-slider/assets/css/max-slider-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
max-slider-wrapmax-slider-itemmax-slider-controls-wrapmax-slider-content-wrapmax-slider-elementor-editormax-slider-controlsmax-slider-paginationmax-slider-arrow+3 more
Data Attributes
data-max-slider-iddata-max-slider-options
JS Globals
MaxSlidermax_slider_select2_localize
Shortcode Output
[max_slider[max_slider_item
FAQ

Frequently Asked Questions about Max Slider for Elementor