Post Category Image With Grid and Slider Security & Risk Analysis

wordpress.org/plugins/post-category-image-with-grid-and-slider

Post Category Image With Grid and Slider allow users to upload category image and display in grid and slider via shortcode or Gutenberg block.

2K active installs v1.5.3 PHP + WP 4.0+ Updated Feb 20, 2026
categorycategory-imagepost-category-imagepost-category-image-gridpost-category-image-slider
100
A · Safe
CVEs total1
Unpatched0
Last CVEJan 4, 2023
Safety Verdict

Is Post Category Image With Grid and Slider Safe to Use in 2026?

Generally Safe

Score 100/100

Post Category Image With Grid and Slider has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 4, 2023Updated 1mo ago
Risk Assessment

The "post-category-image-with-grid-and-slider" plugin v1.5.3 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, secure handling of SQL queries through prepared statements, and a high percentage of properly escaped output are positive indicators. The plugin also shows a commendable effort in output escaping and a capability check, suggesting an awareness of security best practices. However, the lack of nonce checks on its entry points is a notable concern, as it could potentially expose the plugin to certain types of attacks if other vulnerabilities exist or are introduced.

The vulnerability history indicates a past Cross-Site Scripting (XSS) vulnerability, though it has since been patched. The fact that there are no currently unpatched vulnerabilities is a positive sign, suggesting timely updates. The single medium-severity vulnerability in the past, which was XSS, aligns with the potential risk of unescaped output if the escaping wasn't as robust as reported.

In conclusion, the plugin demonstrates strengths in secure coding practices, particularly with SQL handling and output escaping. The primary weakness identified is the absence of nonce checks on its entry points, which, while not directly exploitable in this static analysis, represents a potential avenue for attack if not addressed. The past XSS vulnerability, although resolved, warrants continued vigilance regarding output sanitization.

Key Concerns

  • Missing nonce checks on entry points
  • Past XSS vulnerability history
Vulnerabilities
1

Post Category Image With Grid and Slider Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-4747medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Post Category Image With Grid and Slider <= 1.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Jan 4, 2023 Patched in 1.4.8 (384d)
Code Analysis
Analyzed Mar 16, 2026

Post Category Image With Grid and Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
180 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped183 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<solutions-features> (includes\admin\settings\solution-features\solutions-features.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Post Category Image With Grid and Slider Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[pci-cat-grid] includes\shortcode\pciwgas-grid.php:129
[pci-cat-slider] includes\shortcode\pciwgas-slider.php:157
WordPress Hooks 12
actionadmin_menuincludes\admin\class-pciwgas-admin.php:20
actionadmin_initincludes\admin\class-pciwgas-admin.php:23
actionadmin_initincludes\admin\class-pciwgas-admin.php:26
actioninitincludes\admin\supports\gutenberg-block.php:182
actionenqueue_block_assetsincludes\admin\supports\gutenberg-block.php:191
actionenqueue_block_editor_assetsincludes\admin\supports\gutenberg-block.php:215
filterblock_categories_allincludes\admin\supports\gutenberg-block.php:236
actionadmin_enqueue_scriptsincludes\class-pciwgas-script.php:20
actionwp_enqueue_scriptsincludes\class-pciwgas-script.php:23
actionplugins_loadedpost-category-image-with-grid-and-slider.php:84
actionupdate_option_active_pluginspost-category-image-with-grid-and-slider.php:120
actionadmin_noticespost-category-image-with-grid-and-slider.php:193
Maintenance & Trust

Post Category Image With Grid and Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version
Downloads62K

Community Trust

Rating100/100
Number of ratings5
Active installs2K
Developer Profile

Post Category Image With Grid and Slider Developer Profile

Essential Plugin

33 plugins · 205K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
219 days
View full developer profile
Detection Fingerprints

How We Detect Post Category Image With Grid and Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-category-image-with-grid-and-slider/assets/js/blocks.build.js/wp-content/plugins/post-category-image-with-grid-and-slider/assets/css/frontend.css/wp-content/plugins/post-category-image-with-grid-and-slider/assets/js/owl.carousel.min.js/wp-content/plugins/post-category-image-with-grid-and-slider/assets/js/frontend.js
Script Paths
assets/js/blocks.build.jsassets/js/owl.carousel.min.jsassets/js/frontend.js
Version Parameters
post-category-image-with-grid-and-slider/assets/js/blocks.build.js?ver=post-category-image-with-grid-and-slider/assets/css/frontend.css?ver=post-category-image-with-grid-and-slider/assets/js/owl.carousel.min.js?ver=post-category-image-with-grid-and-slider/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
pciwgas-slider-wrappciwgas-slider-itempciwgas-grid-wrappciwgas-grid-itempciwgas-category-image
HTML Comments
<!-- Shortcode Start By Post Category Image With Grid and Slider --><!-- Shortcode End By Post Category Image With Grid and Slider -->
Data Attributes
data-pciwgas-slider-options
JS Globals
Pciwgas_Block
Shortcode Output
[pciwgas_categories_grid[pciwgas_categories_slider
FAQ

Frequently Asked Questions about Post Category Image With Grid and Slider