NextGEN 3D and 2D Animated Flux Slider Template Security & Risk Analysis

wordpress.org/plugins/nextgen-3d-flux-slider-template

CSS3 animated 3D and 2D transitions. Use [nggallery id=x template="3dfluxsliderview"] for a cool animated slider

100 active installs v1.1.1 PHP + WP 3.0.1+ Updated Mar 20, 2013
featured-sliderimage-slidernextgennextgen-sliderslider-animation
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NextGEN 3D and 2D Animated Flux Slider Template Safe to Use in 2026?

Generally Safe

Score 85/100

NextGEN 3D and 2D Animated Flux Slider Template has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The plugin "nextgen-3d-flux-slider-template" v1.1.1 exhibits a mixed security posture. On one hand, the absence of known CVEs and a lack of recorded past vulnerabilities suggest a relatively stable and well-maintained codebase. The plugin also demonstrates good practices regarding SQL query handling, with 100% of queries using prepared statements and no file operations or external HTTP requests identified, which significantly reduces common attack vectors. The limited attack surface, with zero identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events, is a strong positive indicator. However, significant concerns arise from the static code analysis. The presence of two instances of `create_function` is a critical security risk, as this function is deprecated and can be a vector for code injection if not handled with extreme caution and rigorous sanitization, which appears to be lacking. Furthermore, the analysis indicates that 0% of the 20 identified output operations are properly escaped. This widespread lack of output escaping is a serious vulnerability, potentially leading to Cross-Site Scripting (XSS) attacks across various contexts where the plugin's output is rendered. The lack of nonce and capability checks, while seemingly mitigated by the minimal attack surface, would become a critical issue if any entry points were to be discovered or introduced in future updates. In conclusion, while the plugin benefits from a clean vulnerability history and sound SQL practices, the prevalent unescaped output and the use of deprecated, insecure functions like `create_function` represent substantial security weaknesses that require immediate attention.

Key Concerns

  • Unescaped output found in 100% of outputs
  • Use of deprecated and insecure create_function
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

NextGEN 3D and 2D Animated Flux Slider Template Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

NextGEN 3D and 2D Animated Flux Slider Template Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
20
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action( 'plugins_loaded', create_function( '', 'global $ngg3DFluxSliderSettings; $ngg3DFluxSlideadmin-settings.php:9
create_functionadd_action('plugins_loaded', create_function('', 'global $ngg3DFluxSliderview; $ngg3DFluxSliderview nextgen-3D-flux-slider-template.php:47

Output Escaping

0% escaped20 total outputs
Attack Surface

NextGEN 3D and 2D Animated Flux Slider Template Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedadmin-settings.php:9
actionadmin_menuadmin-settings.php:14
actionadmin_initadmin-settings.php:15
actionwp_enqueue_scriptsnextgen-3D-flux-slider-template.php:22
actionwp_enqueue_scriptsnextgen-3D-flux-slider-template.php:23
filterngg_render_templatenextgen-3D-flux-slider-template.php:24
actionplugins_loadednextgen-3D-flux-slider-template.php:47
Maintenance & Trust

NextGEN 3D and 2D Animated Flux Slider Template Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedMar 20, 2013
PHP min version
Downloads30K

Community Trust

Rating100/100
Number of ratings4
Active installs100
Developer Profile

NextGEN 3D and 2D Animated Flux Slider Template Developer Profile

Mohsin Rasool

2 plugins · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NextGEN 3D and 2D Animated Flux Slider Template

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nextgen-3d-flux-slider-template/css/style.css/wp-content/plugins/nextgen-3d-flux-slider-template/js/flux.min.js
Script Paths
/wp-content/plugins/nextgen-3d-flux-slider-template/js/flux.min.js
Version Parameters
nextgen-3d-flux-slider-template/css/style.css?ver=1.0.1nextgen-3d-flux-slider-template/js/flux.min.js?ver=1.0

HTML / DOM Fingerprints

Data Attributes
ng_3dfluxslider_transitionsng_3dfluxslider_captionng_3dfluxslider_controlsng_3dfluxslider_paginationng_3dfluxslider_delay
FAQ

Frequently Asked Questions about NextGEN 3D and 2D Animated Flux Slider Template