Post Sliders & Post Grids Security & Risk Analysis

wordpress.org/plugins/post-slider-carousel

Post Slider & Grid is beautiful responsive post thumbnail image slider and also support post grid display.It support post exclusion/inclusion, Cat …

1K active installs v1.0.22 PHP + WP 3.5+ Updated Dec 3, 2025
advance-post-slidercustom-post-gridlatest-post-sliderpost-gridpost-grid-display
100
A · Safe
CVEs total1
Unpatched0
Last CVENov 3, 2023
Safety Verdict

Is Post Sliders & Post Grids Safe to Use in 2026?

Generally Safe

Score 100/100

Post Sliders & Post Grids has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 3, 2023Updated 4mo ago
Risk Assessment

The 'post-slider-carousel' plugin v1.0.22 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and 100% proper output escaping are commendable practices. Furthermore, the plugin implements nonce and capability checks on its identified entry points, indicating an effort to protect against common web vulnerabilities. The analysis also shows no evidence of unsanitized paths in taint flows, further bolstering confidence in its code quality.

However, the plugin's vulnerability history is a significant concern. Despite having no currently unpatched CVEs, the presence of one known medium-severity vulnerability, specifically Cross-Site Scripting (XSS), indicates past weaknesses. The fact that this vulnerability was identified relatively recently (November 2023) suggests that even with good static analysis results, past issues may require ongoing vigilance. The absence of any reported vulnerabilities in the current version does not guarantee future safety, and the historical context should be considered when assessing overall risk.

In conclusion, while the current version of 'post-slider-carousel' appears to have addressed its past vulnerabilities and implements robust coding practices, its historical track record, particularly with XSS, warrants a cautious approach. Users should ensure they are always on the latest version and monitor for any new security advisories. The lack of any identified vulnerabilities in the current analysis is a positive sign, but the past incident cannot be entirely disregarded.

Key Concerns

  • One known medium severity CVE (XSS)
Vulnerabilities
1

Post Sliders & Post Grids Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-47226medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Post Sliders & Post Grids <= 1.0.20 - Authenticated (Administrator+) Stored Cross-Site Scripting

Nov 3, 2023 Patched in 1.0.21 (153d)
Code Analysis
Analyzed Mar 16, 2026

Post Sliders & Post Grids Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
545 escaped
Nonce Checks
2
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped546 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<post-slider-carousel> (post-slider-carousel.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Post Sliders & Post Grids Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[psc_print_post_slider_carousel] post-slider-carousel.php:20
[psc_print_post_grid] post-slider-carousel.php:21
WordPress Hooks 10
filterwidget_textpost-slider-carousel.php:15
actionadmin_menupost-slider-carousel.php:16
actionwp_enqueue_scriptspost-slider-carousel.php:19
actionadmin_noticespost-slider-carousel.php:22
filteruser_has_cappost-slider-carousel.php:23
actionplugins_loadedpost-slider-carousel.php:24
filtermap_meta_cappost-slider-carousel.php:66
filterwidget_text_contentpost-slider-carousel.php:3587
filterthe_contentpost-slider-carousel.php:3588
filterrender_blockpost-slider-carousel.php:3599
Maintenance & Trust

Post Sliders & Post Grids Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version
Downloads60K

Community Trust

Rating86/100
Number of ratings8
Active installs1K
Developer Profile

Post Sliders & Post Grids Developer Profile

Nks

19 plugins · 23K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
350 days
View full developer profile
Detection Fingerprints

How We Detect Post Sliders & Post Grids

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-slider-carousel/css/p_s_c_bx.css/wp-content/plugins/post-slider-carousel/css/psc_grid.css/wp-content/plugins/post-slider-carousel/css/font-awesome/css/font-awesome.min.css/wp-content/plugins/post-slider-carousel/js/p_s_c_bx.js/wp-content/plugins/post-slider-carousel/js/psc_grid_min.js
Script Paths
/wp-content/plugins/post-slider-carousel/js/p_s_c_bx.js/wp-content/plugins/post-slider-carousel/js/psc_grid_min.js
Version Parameters
post-slider-carousel/css/p_s_c_bx.css?ver=post-slider-carousel/css/psc_grid.css?ver=post-slider-carousel/css/font-awesome/css/font-awesome.min.css?ver=post-slider-carousel/js/p_s_c_bx.js?ver=post-slider-carousel/js/psc_grid_min.js?ver=

HTML / DOM Fingerprints

CSS Classes
psc_grid_container
Data Attributes
data-psc_grid_id
JS Globals
psc_post_slider_carousel
Shortcode Output
[psc_print_post_slider_carousel][psc_print_post_grid]
FAQ

Frequently Asked Questions about Post Sliders & Post Grids