Post Types Slider Security & Risk Analysis

wordpress.org/plugins/post-types-slider

Create fully customizable, responsive sliders and carousels for any WordPress post type or taxonomy. Powered by the Slick Slider library.

10 active installs v1.0.7 PHP 7.4+ WP 5.0+ Updated Jan 14, 2026
custom-post-typepost-type-sliderslick-carouselslick-sliderslider
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Types Slider Safe to Use in 2026?

Generally Safe

Score 100/100

Post Types Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "post-types-slider" v1.0.7 plugin demonstrates several good security practices, including a complete lack of dangerous functions, no direct SQL queries (all use prepared statements), and a low rate of unescaped output (86% properly escaped). The absence of known CVEs and historical vulnerabilities is also a positive indicator of the plugin's security maturity.

However, the analysis does reveal potential security concerns. A significant portion of the plugin's attack surface is exposed without proper authentication checks, specifically 3 out of 7 AJAX handlers lack authorization. While taint analysis found no critical or high severity issues, this, combined with the unprotected AJAX endpoints, could allow for unauthorized actions if malicious input is provided. The plugin also has a moderate number of nonces and capability checks, which is generally good, but the presence of unprotected AJAX handlers diminishes the overall security posture.

In conclusion, while "post-types-slider" v1.0.7 has a relatively clean bill of health regarding known vulnerabilities and core secure coding practices like prepared statements and output escaping, the unprotected AJAX endpoints present a tangible risk. This plugin is recommended for use, but with caution and a recommendation to review and secure these specific AJAX handlers to mitigate potential attack vectors.

Key Concerns

  • Unprotected AJAX handlers
  • Moderate rate of unescaped output
Vulnerabilities
None known

Post Types Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Post Types Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
115 escaped
Nonce Checks
4
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped133 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
posttysl_preview_slider (admin\class-post-type-slider-admin.php:747)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Post Types Slider Attack Surface

Entry Points8
Unprotected3

AJAX Handlers 7

authwp_ajax_post_slider_categoryadmin\class-post-type-slider-admin.php:66
authwp_ajax_post_slider_termsadmin\class-post-type-slider-admin.php:68
authwp_ajax_post_slider_add_to_cartadmin\class-post-type-slider-admin.php:71
noprivwp_ajax_post_slider_add_to_cartadmin\class-post-type-slider-admin.php:72
authwp_ajax_posttysl_preview_slideradmin\class-post-type-slider-admin.php:73
authwp_ajax_get_variation_idadmin\class-post-type-slider-admin.php:74
noprivwp_ajax_get_variation_idadmin\class-post-type-slider-admin.php:75

Shortcodes 1

[posttysl_slider] admin\class-post-type-slider-admin.php:65
WordPress Hooks 13
actioninitadmin\class-post-type-slider-admin.php:58
actionadd_meta_boxesadmin\class-post-type-slider-admin.php:61
actionsave_postadmin\class-post-type-slider-admin.php:62
filtermanage_posttysl_slide_posts_columnsadmin\class-post-type-slider-admin.php:63
actionmanage_posttysl_slide_posts_custom_columnadmin\class-post-type-slider-admin.php:64
actionadmin_menuadmin\class-post-type-slider-admin.php:69
actionadmin_initadmin\class-post-type-slider-admin.php:70
actionelementor/widgets/registeradmin\widget\elementor\elementor-post-type-slider-widget.php:126
actionplugins_loadedincludes\class-post-type-slider.php:143
actionadmin_enqueue_scriptsincludes\class-post-type-slider.php:158
actionadmin_enqueue_scriptsincludes\class-post-type-slider.php:159
actionwp_enqueue_scriptsincludes\class-post-type-slider.php:174
actionwp_enqueue_scriptsincludes\class-post-type-slider.php:175
Maintenance & Trust

Post Types Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 14, 2026
PHP min version7.4
Downloads769

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Post Types Slider Developer Profile

Waqas Ahmed

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post Types Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-types-slider/css/post-type-slider-admin.css/wp-content/plugins/post-types-slider/js/post-type-slider-admin.js
Script Paths
/wp-content/plugins/post-types-slider/js/post-type-slider-admin.js
Version Parameters
post-types-slider/css/post-type-slider-admin.css?ver=post-types-slider/js/post-type-slider-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
posttysl-slider-settingsposttysl-post-settingsposttysl-slider-previewposttysl-admin-wrapposttysl_edit_slide
Data Attributes
data-posttysl-slider-id
JS Globals
post_slider_handler
Shortcode Output
[posttysl_slider
FAQ

Frequently Asked Questions about Post Types Slider