
NextGen NivoSlider Security & Risk Analysis
wordpress.org/plugins/nextgen-nivosliderThe NextGen Nivoslider plugin allows you to create a NivoSlider, using images from your NextGen gallery, with a simple shortcode or widget.
Is NextGen NivoSlider Safe to Use in 2026?
Generally Safe
Score 85/100NextGen NivoSlider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The nextgen-nivoslider v3.2.7 plugin presents a mixed security posture. While it boasts no known CVEs and a relatively small attack surface consisting of a single shortcode, the static analysis reveals significant areas of concern. The use of the `create_function` dangerous function is a red flag, and the complete absence of nonce and capability checks across all entry points is highly problematic. Furthermore, all SQL queries are executed without prepared statements, increasing the risk of SQL injection vulnerabilities. The taint analysis, though limited in scope (3 flows), indicated unsanitized paths, but thankfully no critical or high severity issues were identified in this specific analysis. The lack of past vulnerabilities might suggest a history of good security practices, or simply that past code was not thoroughly analyzed or exploited. However, the current code's deficiencies require immediate attention.
Key Concerns
- Dangerous function create_function used
- No nonce checks on entry points
- No capability checks on entry points
- All SQL queries unescaped
- Tainted flows with unsanitized paths
- Low output escaping percentage
NextGen NivoSlider Security Vulnerabilities
NextGen NivoSlider Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
NextGen NivoSlider Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
NextGen NivoSlider Maintenance & Trust
Maintenance Signals
Community Trust
NextGen NivoSlider Alternatives
JJ NextGen JQuery Slider
jj-nextgen-jquery-slider
Allows you to pick a gallery from the 'NextGen Gallery' plugin to use as a 'JQuery Nivo slider'.
NextGEN Gallery Sidebar Widget
nextgen-gallery-sidebar-widget
A widget to show NextGEN galleries in your sidebar.
JJ NextGen JQuery Carousel
jj-nextgen-jquery-carousel
Allows you to pick a gallery from the 'NextGen Gallery' plugin to use as a 'JQuery JCarousel'.
JJ NextGen JQuery Cycle
jj-nextgen-jquery-cycle
Allows you to pick a gallery from the 'NextGen Gallery' plugin to use with 'JQuery Cycle Lite'.
JJ NextGen Image List
jj-nextgen-image-list
Allows you to pick a gallery from the 'NextGen Gallery' plugin to list images from. You can list images vertically or horizontally.
NextGen NivoSlider Developer Profile
1 plugin · 300 total installs
How We Detect NextGen NivoSlider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nextgen-nivoslider/script/jquery.nivo.slider.js/wp-content/plugins/nextgen-nivoslider/script/jquery.jj_ngg_shuffle.js/wp-content/plugins/nextgen-nivoslider/stylesheets/nivo-slider.css/wp-content/plugins/nextgen-nivoslider/script/jquery.nivo.slider.js/wp-content/plugins/nextgen-nivoslider/script/jquery.jj_ngg_shuffle.jsjquery.nivo.slider.js?ver=2.4nivo-slider.css?ver=HTML / DOM Fingerprints
ngg-nivosliderdata-effectdata-slicesdata-boxColsdata-boxRowsdata-animSpeeddata-pauseTime+33 morejQuery.jj_ngg_shuffle[ngg-nivosliderid='slider'order='random'center='1'