Parallax Image Security & Risk Analysis

wordpress.org/plugins/parallax-image

Insert a full width parallax image into your page with this simple shortcode. Parameters allow for setting several key functions like height

2K active installs v1.9.1 PHP 7.0+ WP 4.5+ Updated Nov 15, 2024
full-screen-parallaxparallaxparallax-imageparallax-window
90
A · Safe
CVEs total3
Unpatched0
Last CVENov 18, 2024
Safety Verdict

Is Parallax Image Safe to Use in 2026?

Generally Safe

Score 90/100

Parallax Image has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Nov 18, 2024Updated 1yr ago
Risk Assessment

The static analysis of the "parallax-image" plugin v1.9.1 reveals a generally strong security posture in terms of its codebase. The absence of dangerous functions, SQL injection vulnerabilities, unescaped output, file operations, external HTTP requests, and a complete lack of taint flows with unsanitized paths are all positive indicators. The plugin also demonstrates good practice by not relying on bundled libraries, which can often be a source of vulnerabilities when not kept up-to-date.

However, a significant concern arises from the plugin's vulnerability history. With a total of three known medium-severity CVEs, all of which are now patched, it indicates a past susceptibility to certain types of vulnerabilities, specifically Cross-Site Scripting (XSS). While these vulnerabilities are listed as patched, the frequency and nature of past issues warrant caution. The lack of any attack surface (AJAX, REST API, shortcodes, cron) in the current version is excellent, but the historical context suggests that previous versions likely had such entry points that were exploited.

In conclusion, the current version of the "parallax-image" plugin appears to be well-coded with no immediately apparent exploitable flaws in its static analysis. The complete absence of an attack surface is a significant strength. Nevertheless, the documented history of XSS vulnerabilities, even if patched, means users should remain vigilant and ensure they are always running the latest available version of the plugin to benefit from past security fixes.

Key Concerns

  • Past medium severity CVEs (3 total)
Vulnerabilities
3

Parallax Image Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2024-11224medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parallax Image <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via position Parameter

Nov 18, 2024 Patched in 1.9.1 (1d)
CVE-2024-9898medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parallax Image <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via dd-parallax Shortcode

Oct 16, 2024 Patched in 1.9 (1d)
CVE-2023-47854medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parallax Image <= 1.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 20, 2023 Patched in 1.8 (92d)
Code Analysis
Analyzed Mar 16, 2026

Parallax Image Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Parallax Image Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Parallax Image Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 15, 2024
PHP min version7.0
Downloads56K

Community Trust

Rating100/100
Number of ratings10
Active installs2K
Developer Profile

Parallax Image Developer Profile

thehowarde

6 plugins · 4K total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
33 days
View full developer profile
Detection Fingerprints

How We Detect Parallax Image

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/parallax-image/assets/css/parallax.css/wp-content/plugins/parallax-image/assets/js/parallax.min.js
Script Paths
/wp-content/plugins/parallax-image/assets/js/parallax.min.js
Version Parameters
parallax-image/assets/css/parallax.css?ver=parallax-image/assets/js/parallax.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
parallax-window
Data Attributes
data-parallaxdata-image-src
JS Globals
jQuery
Shortcode Output
[dd-parallax
FAQ

Frequently Asked Questions about Parallax Image