Slider for Photos Images Videos Security & Risk Analysis

wordpress.org/plugins/media-slider

Create responsive image and video sliders with thumbnails, navigation, autoplay, and carousel layouts for your site.

3K active installs v1.5.1 PHP 7.0+ WP 5.0+ Updated Feb 18, 2026
image-sliderresponsive-slidersliderslideshowvideo-slider
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 6, 2024
Safety Verdict

Is Slider for Photos Images Videos Safe to Use in 2026?

Generally Safe

Score 99/100

Slider for Photos Images Videos has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 6, 2024Updated 1mo ago
Risk Assessment

The media-slider plugin v1.5.1 exhibits a generally good security posture, with a strong emphasis on proper coding practices. The high percentage of properly escaped output and the exclusive use of prepared statements for SQL queries are commendable. The plugin also implements a good number of nonce and capability checks, which are crucial for preventing unauthorized actions. However, the presence of the 'unserialize' function in the code signals a potential risk. While taint analysis did not reveal critical or high-severity issues, two flows with unsanitized paths were identified, which warrants attention. The vulnerability history shows one medium-severity CVE with a recent patch, indicating a past issue that has been addressed. Overall, the plugin is well-maintained with robust security features, but the 'unserialize' function and identified unsanitized paths are areas that could be further scrutinized to ensure absolute security.

Key Concerns

  • Dangerous function used (unserialize)
  • Flows with unsanitized paths
  • Medium severity CVE in history
Vulnerabilities
1

Slider for Photos Images Videos Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-35717medium · 4.3Missing Authorization

Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow <= 1.3.9 - Missing Authorization

Jun 6, 2024 Patched in 1.4.0 (7d)
Code Analysis
Analyzed Mar 16, 2026

Slider for Photos Images Videos Code Analysis

Dangerous Functions
5
Raw SQL Queries
0
0 prepared
Unescaped Output
21
278 escaped
Nonce Checks
7
Capability Checks
17
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserializereturn ($str == serialize(false) || @unserialize($str) !== false);media-slider-code.php:17
unserialize$slider_settings = unserialize($decodedData);media-slider-code.php:43
unserialize$slider_settings = unserialize($decodedData);media-slider-settings.php:13
unserializereturn($str == serialize(false) || @unserialize($str) !== false);media-slider.php:330
unserialize$slider_settings = unserialize($decodedData);media-slider.php:343

Output Escaping

93% escaped299 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ajax_media_slider (media-slider.php:473)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Slider for Photos Images Videos Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_media_slider_jsmedia-slider.php:90

Shortcodes 1

[MDSL] shortcode.php:9
WordPress Hooks 35
actioninitclass-tgm-plugin-activation.php:268
filterload_textdomain_mofileclass-tgm-plugin-activation.php:269
actioninitclass-tgm-plugin-activation.php:272
actionadmin_menuclass-tgm-plugin-activation.php:421
actionadmin_headclass-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionsclass-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionsclass-tgm-plugin-activation.php:426
actionadmin_noticesclass-tgm-plugin-activation.php:429
actionadmin_initclass-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptsclass-tgm-plugin-activation.php:431
actionload-plugins.phpclass-tgm-plugin-activation.php:436
actionswitch_themeclass-tgm-plugin-activation.php:439
actionswitch_themeclass-tgm-plugin-activation.php:442
actionadmin_initclass-tgm-plugin-activation.php:447
actionswitch_themeclass-tgm-plugin-activation.php:452
actionload_textdomain_mofileclass-tgm-plugin-activation.php:475
filterupgrader_source_selectionclass-tgm-plugin-activation.php:889
actionplugins_loadedclass-tgm-plugin-activation.php:2132
filtertgmpa_table_data_itemsclass-tgm-plugin-activation.php:2256
filterupgrader_source_selectionclass-tgm-plugin-activation.php:2997
actionadmin_initclass-tgm-plugin-activation.php:3167
actionupgrader_process_completeclass-tgm-plugin-activation.php:3262
filterupgrader_post_installclass-tgm-plugin-activation.php:3321
filterupgrader_post_installclass-tgm-plugin-activation.php:3470
actioninitmedia-slider.php:79
actionadmin_menumedia-slider.php:82
actioninitmedia-slider.php:85
actionadd_meta_boxesmedia-slider.php:88
actionsave_postmedia-slider.php:92
filterwidget_textmedia-slider.php:95
filtermanage_media_slider_posts_columnsmedia-slider.php:98
actionmanage_media_slider_posts_custom_columnmedia-slider.php:101
actionwp_enqueue_scriptsmedia-slider.php:103
actionwp_enqueue_scriptsmedia-slider.php:621
actiontgmpa_registermedia-slider.php:624
Maintenance & Trust

Slider for Photos Images Videos Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version7.0
Downloads157K

Community Trust

Rating100/100
Number of ratings15
Active installs3K
Developer Profile

Slider for Photos Images Videos Developer Profile

A WP Life

61 plugins · 64K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
267 days
View full developer profile
Detection Fingerprints

How We Detect Slider for Photos Images Videos

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/media-slider/js/admin.js/wp-content/plugins/media-slider/js/copy-shortcode.js/wp-content/plugins/media-slider/css/admin.css/wp-content/plugins/media-slider/css/ms-style.css
Script Paths
/wp-content/plugins/media-slider/js/admin.js/wp-content/plugins/media-slider/js/copy-shortcode.js
Version Parameters
/wp-content/plugins/media-slider/js/admin.js?ver=/wp-content/plugins/media-slider/js/copy-shortcode.js?ver=/wp-content/plugins/media-slider/css/admin.css?ver=/wp-content/plugins/media-slider/css/ms-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
media-slider-shortcodems-frontend-sliderawl-sliders
Data Attributes
id="media-slider-shortcode-id='media-slider-shortcode-id='copy-msg-onclick='return MEDIACopyShortcodevalue='[MDSL id=
JS Globals
MEDIACopyShortcode
Shortcode Output
[MDSL id=
FAQ

Frequently Asked Questions about Slider for Photos Images Videos