MaxSlider Security & Risk Analysis

wordpress.org/plugins/maxslider

MaxSlider is a free WordPress slider plugin that lets you create responsive sliders for your website. Shortcode and Visual Composer support included.

8K active installs v1.2.4 PHP + WP 5.0+ Updated Apr 25, 2025
image-sliderphoto-sliderresponsive-slidersliderwordpress-slider
98
A · Safe
CVEs total1
Unpatched0
Last CVESep 30, 2024
Safety Verdict

Is MaxSlider Safe to Use in 2026?

Generally Safe

Score 98/100

MaxSlider has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 30, 2024Updated 11mo ago
Risk Assessment

The maxslider plugin version 1.2.4 exhibits a generally positive security posture based on the provided static analysis. It demonstrates good practices by having no dangerous functions, using prepared statements exclusively for SQL queries, and a high percentage of properly escaped output. The presence of nonce and capability checks, along with the absence of external HTTP requests or file operations, further contribute to its security. The attack surface is minimal, with only one shortcode identified, and crucially, no unprotected entry points were found in the static analysis.

However, the plugin's vulnerability history presents a significant concern. A known high-severity CVE exists for this plugin, specifically related to Improper Control of Filename for Include/Require Statement, indicating a potential for PHP Remote File Inclusion vulnerabilities. While this specific CVE is reported as currently unpatched, its historical occurrence suggests a pattern of potential weaknesses in how file paths are handled, which attackers could exploit to execute arbitrary code. The absence of taint analysis results for this version makes it difficult to assess if this specific historical vulnerability has been addressed in the code itself, or if it's a lingering risk.

In conclusion, while the current code analysis shows no immediate exploitable vulnerabilities and good security practices are evident, the historical high-severity RFI vulnerability cannot be ignored. This indicates a past weakness that may not be fully mitigated in this version. Users should be aware of this historical risk and ensure they are monitoring for any updates or advisories related to maxslider.

Key Concerns

  • Unpatched high severity CVE historically
  • High percentage of output unescaped (12%)
Vulnerabilities
1

MaxSlider Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-47351high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

MaxSlider <= 1.2.3 - Authenticated (Contributor+) Local File Inclusion

Sep 30, 2024 Patched in 1.2.4 (11d)
Code Analysis
Analyzed Mar 16, 2026

MaxSlider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
33
248 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped281 total outputs
Attack Surface

MaxSlider Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[maxslider] maxslider.php:1522
WordPress Hooks 20
actioninitblock\block.php:2
filtermaxslider_get_slider_parameters_arrayclass-maxslider-back-compat.php:15
filtermaxslider_slider_classesclass-maxslider-template-hooks.php:8
actioninitmaxslider.php:172
actioninitmaxslider.php:173
actioninitmaxslider.php:174
actioninitmaxslider.php:175
actionvc_before_initmaxslider.php:176
actioninitmaxslider.php:178
actionadmin_enqueue_scriptsmaxslider.php:192
actionadd_meta_boxesmaxslider.php:193
actionsave_postmaxslider.php:194
filtermaxslider_metabox_slides_container_classesmaxslider.php:197
actionmaxslider_metabox_slides_repeatable_slide_field_before_titlemaxslider.php:198
actionmaxslider_metabox_slides_field_controlsmaxslider.php:201
filterblock_categoriesmaxslider.php:208
filterblock_categories_allmaxslider.php:210
actionenqueue_block_assetsmaxslider.php:212
actionwp_enqueue_scriptsmaxslider.php:223
actionplugins_loadedmaxslider.php:2002
Maintenance & Trust

MaxSlider Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 25, 2025
PHP min version
Downloads92K

Community Trust

Rating94/100
Number of ratings12
Active installs8K
Developer Profile

MaxSlider Developer Profile

The CSSIgniter Team

8 plugins · 31K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
36 days
View full developer profile
Detection Fingerprints

How We Detect MaxSlider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/maxslider/assets/vendor/alpha-color-picker/alpha-color-picker.css/wp-content/plugins/maxslider/assets/vendor/slick/slick.css/wp-content/plugins/maxslider/assets/css/maxslider.css/wp-content/plugins/maxslider/assets/css/admin-styles.css/wp-content/plugins/maxslider/assets/vendor/alpha-color-picker/alpha-color-picker.js/wp-content/plugins/maxslider/assets/vendor/slick/slick.js/wp-content/plugins/maxslider/assets/js/maxslider.js/wp-content/plugins/maxslider/assets/js/maxslider-admin.js+1 more
Script Paths
/wp-content/plugins/maxslider/assets/vendor/alpha-color-picker/alpha-color-picker.js/wp-content/plugins/maxslider/assets/vendor/slick/slick.js/wp-content/plugins/maxslider/assets/js/maxslider.js/wp-content/plugins/maxslider/assets/js/maxslider-admin.js/wp-content/plugins/maxslider/block/build/block.js
Version Parameters
maxslider/assets/css/maxslider.css?ver=maxslider/assets/css/admin-styles.css?ver=maxslider/assets/js/maxslider.js?ver=maxslider/assets/js/maxslider-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
maxslider-containermaxslider-slidemaxslider-navigationmaxslider-prevmaxslider-next
HTML Comments
MaxSlider Slider WrapperMaxSlider Slide
Data Attributes
data-slider-optionsdata-maxslider-id
JS Globals
maxslider_scripts
Shortcode Output
[maxslider id=\"\d+\"]
FAQ

Frequently Asked Questions about MaxSlider