MaxSlider Security & Risk Analysis

wordpress.org/plugins/maxslider

MaxSlider is a free WordPress slider plugin that lets you create responsive sliders for your website. Shortcode and Visual Composer support included.

7K active installs v1.2.4 PHP + WP 5.0+ Updated Apr 25, 2025
image-sliderphoto-sliderresponsive-slidersliderwordpress-slider
90
A · Safe
CVEs total1
Unpatched0
Last CVESep 30, 2024
Safety Verdict

Is MaxSlider Safe to Use in 2026?

Generally Safe

Score 90/100

MaxSlider has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Sep 30, 2024Updated 1yr ago
Risk Assessment

The maxslider plugin version 1.2.4 exhibits a generally positive security posture based on the provided static analysis. It demonstrates good practices by having no dangerous functions, using prepared statements exclusively for SQL queries, and a high percentage of properly escaped output. The presence of nonce and capability checks, along with the absence of external HTTP requests or file operations, further contribute to its security. The attack surface is minimal, with only one shortcode identified, and crucially, no unprotected entry points were found in the static analysis.

However, the plugin's vulnerability history presents a significant concern. A known high-severity CVE exists for this plugin, specifically related to Improper Control of Filename for Include/Require Statement, indicating a potential for PHP Remote File Inclusion vulnerabilities. While this specific CVE is reported as currently unpatched, its historical occurrence suggests a pattern of potential weaknesses in how file paths are handled, which attackers could exploit to execute arbitrary code. The absence of taint analysis results for this version makes it difficult to assess if this specific historical vulnerability has been addressed in the code itself, or if it's a lingering risk.

In conclusion, while the current code analysis shows no immediate exploitable vulnerabilities and good security practices are evident, the historical high-severity RFI vulnerability cannot be ignored. This indicates a past weakness that may not be fully mitigated in this version. Users should be aware of this historical risk and ensure they are monitoring for any updates or advisories related to maxslider.

Key Concerns

  • Unpatched high severity CVE historically
  • High percentage of output unescaped (12%)
Vulnerabilities
1 published

MaxSlider Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-47351high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

MaxSlider <= 1.2.3 - Authenticated (Contributor+) Local File Inclusion

Sep 30, 2024 Patched in 1.2.4 (11d)
Version History

MaxSlider Release Timeline

v1.2.4Current
v1.2.31 CVE
v1.2.21 CVE
v1.2.11 CVE
v1.2.01 CVE
v1.1.81 CVE
v1.1.71 CVE
v1.1.61 CVE
v1.1.51 CVE
v1.1.41 CVE
v1.1.31 CVE
v1.1.21 CVE
v1.1.11 CVE
v1.1.01 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

MaxSlider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
33
248 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped281 total outputs
Attack Surface

MaxSlider Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[maxslider] maxslider.php:1522
WordPress Hooks 20
actioninitblock\block.php:2
filtermaxslider_get_slider_parameters_arrayclass-maxslider-back-compat.php:15
filtermaxslider_slider_classesclass-maxslider-template-hooks.php:8
actioninitmaxslider.php:172
actioninitmaxslider.php:173
actioninitmaxslider.php:174
actioninitmaxslider.php:175
actionvc_before_initmaxslider.php:176
actioninitmaxslider.php:178
actionadmin_enqueue_scriptsmaxslider.php:192
actionadd_meta_boxesmaxslider.php:193
actionsave_postmaxslider.php:194
filtermaxslider_metabox_slides_container_classesmaxslider.php:197
actionmaxslider_metabox_slides_repeatable_slide_field_before_titlemaxslider.php:198
actionmaxslider_metabox_slides_field_controlsmaxslider.php:201
filterblock_categoriesmaxslider.php:208
filterblock_categories_allmaxslider.php:210
actionenqueue_block_assetsmaxslider.php:212
actionwp_enqueue_scriptsmaxslider.php:223
actionplugins_loadedmaxslider.php:2002
Maintenance & Trust

MaxSlider Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 25, 2025
PHP min version
Downloads93K

Community Trust

Rating94/100
Number of ratings12
Active installs7K
Developer Profile

MaxSlider Developer Profile

The CSSIgniter Team

8 plugins · 30K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
36 days
View full developer profile
Detection Fingerprints

How We Detect MaxSlider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/maxslider/assets/vendor/alpha-color-picker/alpha-color-picker.css/wp-content/plugins/maxslider/assets/vendor/slick/slick.css/wp-content/plugins/maxslider/assets/css/maxslider.css/wp-content/plugins/maxslider/assets/css/admin-styles.css/wp-content/plugins/maxslider/assets/vendor/alpha-color-picker/alpha-color-picker.js/wp-content/plugins/maxslider/assets/vendor/slick/slick.js/wp-content/plugins/maxslider/assets/js/maxslider.js/wp-content/plugins/maxslider/assets/js/maxslider-admin.js+1 more
Script Paths
/wp-content/plugins/maxslider/assets/vendor/alpha-color-picker/alpha-color-picker.js/wp-content/plugins/maxslider/assets/vendor/slick/slick.js/wp-content/plugins/maxslider/assets/js/maxslider.js/wp-content/plugins/maxslider/assets/js/maxslider-admin.js/wp-content/plugins/maxslider/block/build/block.js
Version Parameters
maxslider/assets/css/maxslider.css?ver=maxslider/assets/css/admin-styles.css?ver=maxslider/assets/js/maxslider.js?ver=maxslider/assets/js/maxslider-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
maxslider-containermaxslider-slidemaxslider-navigationmaxslider-prevmaxslider-next
HTML Comments
MaxSlider Slider WrapperMaxSlider Slide
Data Attributes
data-slider-optionsdata-maxslider-id
JS Globals
maxslider_scripts
Shortcode Output
[maxslider id=\"\d+\"]
FAQ

Frequently Asked Questions about MaxSlider