
Query Slideshow Security & Risk Analysis
wordpress.org/plugins/query-slideshowQuery Slideshow is a plugin that adds 'Slideshow' as a Template Style for Query Wrangler.
Is Query Slideshow Safe to Use in 2026?
Generally Safe
Score 85/100Query Slideshow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "query-slideshow" v1.2 plugin exhibits a concerning security posture, primarily due to a lack of output escaping and a complete absence of capability checks and nonce verification. While the plugin boasts zero AJAX handlers, REST API routes, shortcodes, or cron events as direct entry points and all SQL queries utilize prepared statements, the lack of output escaping presents a significant risk. This means that any data displayed to users, if it originates from an untrusted source or is manipulated by an attacker, could be rendered without proper sanitization, potentially leading to cross-site scripting (XSS) vulnerabilities. The absence of capability and nonce checks on any potential, albeit undiscovered, entry points is also a red flag. The plugin's vulnerability history is clean, with no known CVEs, which is a positive sign. However, this might be more indicative of limited security research on this specific plugin rather than inherent robustness, especially given the identified code weaknesses. In conclusion, while the plugin has avoided publicly known vulnerabilities and uses secure SQL practices, the critical oversight in output escaping and the missing security controls on potential entry points create a substantial risk that requires immediate attention.
Key Concerns
- Output escaping: 0% properly escaped
- Nonce checks: 0
- Capability checks: 0
Query Slideshow Security Vulnerabilities
Query Slideshow Release Timeline
Query Slideshow Code Analysis
Output Escaping
Query Slideshow Attack Surface
WordPress Hooks 4
Maintenance & Trust
Query Slideshow Maintenance & Trust
Maintenance Signals
Community Trust
Query Slideshow Alternatives
WP-Cycle
wp-cycle
This plugin creates an image slideshow in your theme, using the jQuery Cycle plugin. You can upload/delete images via the administration panel, and di …
Slideshow
slideshow
A shortcode for displaying a slideshow of image attachments for a post.
All-In-One Slideshow
all-in-one-slideshow
All-In-One Slideshow plugin implements jCycle, Easing and Cufon scripts into the highly customizable slideshow gallery.
WP-Cycle Plus Captions
wp-cycle-plus-captions
The WP-Cycle Plus Captions plugin allows you to upload images from your computer, which will then be used to generate a jQuery Cycle Plugin slideshow.
Simple Content Slider / Slideshow
simple-content-slider
A simple and responsive content slider and slideshow plug-in for jQuery with features like touch and CSS3 transitions.
Query Slideshow Developer Profile
5 plugins · 11K total installs
How We Detect Query Slideshow
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/query-slideshow/js/jquery.cycle.all.js/wp-content/plugins/query-slideshow/js/jquery.cycle.all.jsHTML / DOM Fingerprints
qw-labelname="[display][speed]"name="[display][timeout]"name="[display][fx]"