Parallax Slider Block Security & Risk Analysis

wordpress.org/plugins/parallax-slider-block

Create A Captivating Visual Experience & Impress Your Audience

1K active installs v1.2.7 PHP + WP 5.6+ Updated Jul 29, 2024
blockblockseditorgutenbergprogress
92
A · Safe
CVEs total1
Unpatched0
Last CVENov 29, 2023
Download
Safety Verdict

Is Parallax Slider Block Safe to Use in 2026?

Generally Safe

Score 92/100

Parallax Slider Block has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 29, 2023Updated 1yr ago
Risk Assessment

The static analysis of the 'parallax-slider-block' v1.2.7 plugin reveals a generally strong security posture. The plugin has no identified attack surface points like AJAX handlers, REST API routes, or shortcodes, which significantly limits potential entry vectors for attackers. Furthermore, all SQL queries use prepared statements, and all identified outputs are properly escaped, indicating good practices in preventing common web vulnerabilities. The absence of dangerous functions, file operations, external HTTP requests, and the presence of at least one capability check further reinforce this positive assessment.

However, the plugin's vulnerability history presents a notable concern. While there are no currently unpatched CVEs, the plugin has a history of one medium severity vulnerability, specifically Cross-Site Scripting (XSS), with the last recorded incident in late 2023. This indicates that while the developers may have addressed past issues, the potential for such vulnerabilities exists within the codebase. The static analysis also reports zero taint flows and zero flows with unsanitized paths, which is excellent. However, the absence of nonce checks on potential entry points (though none are identified) and the limited capability checks could be areas for minor improvement if any entry points were to be introduced in the future.

In conclusion, the 'parallax-slider-block' v1.2.7 plugin demonstrates good security development practices, particularly in its handling of SQL and output escaping, and its minimal attack surface. The primary weakness lies in its past vulnerability history, specifically XSS, suggesting a need for continued vigilance and robust input validation, even with the current clean static analysis. The lack of identified entry points is a significant strength, but the historical context warrants a slightly cautious approach.

Key Concerns

  • Past medium severity vulnerability (XSS)
  • 0 Nonce checks detected
Vulnerabilities
1

Parallax Slider Block Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-49184medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parallax Slider Block <= 1.2.5 - Authenticated (Author+) Stored Cross-Site Scripting

Nov 29, 2023 Patched in 1.2.6 (142d)
Code Analysis
Analyzed Mar 17, 2026

Parallax Slider Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Parallax Slider Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterrender_blockincludes\font-loader.php:31
actionwp_footerincludes\font-loader.php:33
actionadmin_enqueue_scriptsincludes\helpers.php:33
filterinitincludes\post-meta.php:12
actioninitparallax-slider-block.php:113
Maintenance & Trust

Parallax Slider Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 29, 2024
PHP min version
Downloads22K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

Parallax Slider Block Developer Profile

WPDeveloper

46 plugins · 4.0M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
163 days
View full developer profile
Detection Fingerprints

How We Detect Parallax Slider Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/parallax-slider-block/dist/index.js/wp-content/plugins/parallax-slider-block/lib/css/animate.min.css/wp-content/plugins/parallax-slider-block/dist/style.css/wp-content/plugins/parallax-slider-block/lib/js/eb-animation-load.js/wp-content/plugins/parallax-slider-block/dist/frontend/index.js
Script Paths
/wp-content/plugins/parallax-slider-block/dist/index.asset.php/wp-content/plugins/parallax-slider-block/dist/frontend/index.asset.php
Version Parameters
parallax-slider-block/dist/index.js?ver=parallax-slider-block/lib/css/animate.min.css?ver=parallax-slider-block/dist/style.css?ver=parallax-slider-block/lib/js/eb-animation-load.js?ver=parallax-slider-block/dist/frontend/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-essential-blocks-parallax-slider
Data Attributes
data-block="essential-blocks/parallax-slider"data-type="parallax-slider-block"data-layout="parallax-slider-block"
JS Globals
Parallax_Slider_Font_Loader
FAQ

Frequently Asked Questions about Parallax Slider Block