Pixelating image slideshow gallery Security & Risk Analysis

wordpress.org/plugins/pixelating-image-slideshow-gallery

This is your normal hyperlinked image slideshow, but in IE the added images are "pixelated" into view. And its good cross browser script.

10 active installs v8.0 PHP + WP 3.4+ Updated Dec 1, 2022
galleryimagepixelatingslideshow
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJul 4, 2025
Safety Verdict

Is Pixelating image slideshow gallery Safe to Use in 2026?

Use With Caution

Score 63/100

Pixelating image slideshow gallery has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jul 4, 2025Updated 3yr ago
Risk Assessment

The pixelating-image-slideshow-gallery plugin version 8.0 exhibits a mixed security posture. While the static analysis shows a limited attack surface and a high percentage of SQL queries utilizing prepared statements, there are significant areas of concern. The output escaping is alarmingly low at 46%, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the plugin has a history of known vulnerabilities, including a recently patched medium-severity SQL injection flaw from July 2025, suggesting a pattern of insecure coding practices that may not be fully rectified.

The static analysis did not reveal any critical or high severity taint flows, which is a positive sign. However, the lack of capability checks on the identified entry points, even though the number of entry points is low, presents a potential weakness if any future vulnerabilities are discovered. The presence of a historical medium-severity SQL injection vulnerability, even if currently patched, underscores the need for vigilant monitoring and robust security practices in plugin development.

In conclusion, while the plugin has some strengths in its limited attack surface and SQL query practices, the poor output escaping and a history of SQL injection vulnerabilities present notable risks. Developers should prioritize addressing the output escaping issues to mitigate XSS risks and maintain a strong security track record. The presence of an unpatched vulnerability, even if historical, warrants careful consideration and prompt patching in any active deployment.

Key Concerns

  • Unescaped output is a significant risk
  • Unpatched CVE: medium severity SQL Injection
  • Lack of capability checks on entry points
Vulnerabilities
1

Pixelating image slideshow gallery Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-30979medium · 6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Pixelating image slideshow gallery <= 8.0 - Authenticated (Contributor+) SQL Injection

Jul 4, 2025Unpatched
Code Analysis
Analyzed Mar 17, 2026

Pixelating image slideshow gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
24 prepared
Unescaped Output
32
27 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

96% prepared25 total queries

Output Escaping

46% escaped59 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<image-management-show> (pages\image-management-show.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Pixelating image slideshow gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[pixelating-image-slideshow-gallery] pixelating-image-slideshow-gallery.php:117
WordPress Hooks 5
actionplugins_loadedpixelating-image-slideshow-gallery.php:347
actionadmin_menupixelating-image-slideshow-gallery.php:348
actionplugins_loadedpixelating-image-slideshow-gallery.php:349
actioninitpixelating-image-slideshow-gallery.php:352
actionadmin_enqueue_scriptspixelating-image-slideshow-gallery.php:353
Maintenance & Trust

Pixelating image slideshow gallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 1, 2022
PHP min version
Downloads12K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Pixelating image slideshow gallery Developer Profile

gopiplus

52 plugins · 19K total installs

76
trust score
Avg Security Score
83/100
Avg Patch Time
70 days
View full developer profile
Detection Fingerprints

How We Detect Pixelating image slideshow gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- var slidespeed=--><!-- var slideimages=--><!-- var slidelinks=--><!-- var imageholder=-->+50 more
Data Attributes
filter:progid:DXImageTransform.Microsoft.Pixelate(MaxSquare=filter:progid:DXImageTransform.Microsoft.Pixelate(MaxSquare=filter:progid:DXImageTransform.Microsoft.Pixelate(MaxSquare=filter:progid:DXImageTransform.Microsoft.Pixelate(MaxSquare=
JS Globals
slidespeedslideimagesslidelinksimageholderie55whichlink+2 more
Shortcode Output
<script language="JavaScript1.1">var slidespeed=var slideimages=new Array(var slidelinks=new Array(
FAQ

Frequently Asked Questions about Pixelating image slideshow gallery