Post Type Slider for Customizr Security & Risk Analysis

wordpress.org/plugins/post-type-slider-for-customizr

Replace the Customizr theme's default frontpage slider with any post type that you wish. E.g. product, event, post, project, etc.

10 active installs v0.1 PHP + WP 4.4+ Updated Jan 12, 2016
customizrpost-typeslider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Type Slider for Customizr Safe to Use in 2026?

Generally Safe

Score 85/100

Post Type Slider for Customizr has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin "post-type-slider-for-customizr" v0.1 exhibits a generally positive security posture based on the static analysis provided. There are no identified critical or high severity code signals such as dangerous functions, raw SQL queries, or unsanitized taint flows. The absence of external HTTP requests and file operations further reduces the potential attack surface. Furthermore, the plugin has no recorded vulnerability history, which is a strong indicator of diligent development practices or a lack of past issues being publicly disclosed.

However, there are a few areas that could be improved. The output escaping is only properly handled in 61% of cases, which presents a moderate risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed. While the plugin has only two capability checks, the complete absence of nonce checks and a lack of unprotected entry points means that existing checks might be sufficient for the current functionality, but this could become a weakness if new features are added without proper security considerations. The fact that there are no AJAX handlers, REST API routes, or shortcodes with unprotected entry points is a significant strength, but the low percentage of properly escaped output is a concern that warrants attention.

In conclusion, "post-type-slider-for-customizr" v0.1 appears to be a relatively secure plugin, especially given its lack of known vulnerabilities and no critical code issues identified. The primary weakness lies in the incomplete output escaping. Developers should prioritize addressing the remaining 39% of unescaped outputs to mitigate potential XSS risks. The limited number of capability checks and the absence of nonce checks, while not problematic currently, should be monitored as the plugin evolves.

Key Concerns

  • Unescaped output identified
Vulnerabilities
None known

Post Type Slider for Customizr Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Post Type Slider for Customizr Release Timeline

v0.1Current
Code Analysis
Analyzed Apr 16, 2026

Post Type Slider for Customizr Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
41 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

61% escaped67 total outputs
Attack Surface

Post Type Slider for Customizr Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_initclass-admin.php:39
actionadmin_menuclass-admin.php:40
actionadmin_enqueue_scriptsclass-admin.php:41
filterinitclass-admin.php:42
action__post_slider_infosclass-metabox.php:39
actionsave_postclass-metabox.php:40
actionplugins_loadedrisbl-post-type-slider-for-customizr.php:47
filtertc_show_slider_edit_linkrisbl-post-type-slider-for-customizr.php:91
filtertc_the_slidesrisbl-post-type-slider-for-customizr.php:106
Maintenance & Trust

Post Type Slider for Customizr Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJan 12, 2016
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Post Type Slider for Customizr Developer Profile

Kharis Sulistiyono

7 plugins · 290 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post Type Slider for Customizr

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-type-slider-for-customizr/css/risbl-admin.css/wp-content/plugins/post-type-slider-for-customizr/js/risbl-admin.js
Script Paths
/wp-content/plugins/post-type-slider-for-customizr/js/risbl-admin.js
Version Parameters
post-type-slider-for-customizr/css/risbl-admin.css?ver=post-type-slider-for-customizr/js/risbl-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
risbl-slider-customizr
Data Attributes
data-risbl-id
JS Globals
risbl_customizr_slider_settings
FAQ

Frequently Asked Questions about Post Type Slider for Customizr