Responsive Slick Slider WordPress Security & Risk Analysis

wordpress.org/plugins/responsive-slick-slider

Responsive Slick Slider is built on the top of slick js with support to unlimited banner images, text layers and videos(YouTube, Mp4, HTML5 and Vimeo) …

500 active installs v1.5 PHP + WP 3.5+ Updated Mar 6, 2025
banner-sliderslick-slidersliderslideshowvideo-slider
71
B · Generally Safe
CVEs total1
Unpatched1
Last CVEDec 7, 2023
Safety Verdict

Is Responsive Slick Slider WordPress Safe to Use in 2026?

Mostly Safe

Score 71/100

Responsive Slick Slider WordPress is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Dec 7, 2023Updated 1yr ago
Risk Assessment

The "responsive-slick-slider" v1.5 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, avoiding file operations and external HTTP requests, and implementing nonce and capability checks on most entry points. The substantial amount of output escaping (66% proper) is also a positive indicator. However, significant concerns arise from the presence of an unprotected AJAX handler, which represents a direct entry point for potential attacks without proper authentication or authorization. The plugin also has a history of known vulnerabilities, with one medium severity CVE remaining unpatched, indicating potential ongoing risks related to improper neutralization of special elements. This pattern suggests a recurring need for diligent security patching and review. While the absence of critical taint flows is reassuring, the combination of an unprotected entry point and an unpatched CVE warrants careful consideration for any WordPress site using this plugin.

Key Concerns

  • Unprotected AJAX handler
  • 1 unpatched medium CVE
  • Only 66% of outputs properly escaped
Vulnerabilities
1

Responsive Slick Slider WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2023 · unpatched
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-49852medium · 4.3Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Responsive Slick Slider WordPress <= 1.5 - Authenticated (Contributor+) Content Injection

Dec 7, 2023Unpatched
Code Analysis
Analyzed Mar 16, 2026

Responsive Slick Slider WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
182
346 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

66% escaped528 total outputs
Attack Surface
1 unprotected

Responsive Slick Slider WordPress Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_display_post_taxonomy_listincludes\class-responsive-slick-slider.php:177

Shortcodes 1

[vsz_slick_slider] public\class-responsive-slick-slider-public.php:110
WordPress Hooks 14
actionplugins_loadedincludes\class-responsive-slick-slider.php:142
actionadmin_enqueue_scriptsincludes\class-responsive-slick-slider.php:157
actionadmin_enqueue_scriptsincludes\class-responsive-slick-slider.php:158
actioninitincludes\class-responsive-slick-slider.php:161
actionadd_meta_boxes_vsz_responsive_slickincludes\class-responsive-slick-slider.php:165
actionsave_post_vsz_responsive_slickincludes\class-responsive-slick-slider.php:167
filtermanage_edit-vsz_responsive_slick_columnsincludes\class-responsive-slick-slider.php:170
actionmanage_vsz_responsive_slick_posts_custom_columnincludes\class-responsive-slick-slider.php:171
actionadmin_menuincludes\class-responsive-slick-slider.php:174
actionsave_post_vsz_responsive_slickincludes\class-responsive-slick-slider.php:178
actionwp_enqueue_scriptsincludes\class-responsive-slick-slider.php:194
actionwp_enqueue_scriptsincludes\class-responsive-slick-slider.php:195
actionafter_setup_themeincludes\class-responsive-slick-slider.php:197
actionwp_headincludes\class-responsive-slick-slider.php:200
Maintenance & Trust

Responsive Slick Slider WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 6, 2025
PHP min version
Downloads15K

Community Trust

Rating80/100
Number of ratings1
Active installs500
Developer Profile

Responsive Slick Slider WordPress Developer Profile

Vsourz Digital

8 plugins · 78K total installs

65
trust score
Avg Security Score
80/100
Avg Patch Time
845 days
View full developer profile
Detection Fingerprints

How We Detect Responsive Slick Slider WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-slick-slider/admin/css/responsive-slick-slider-admin.css/wp-content/plugins/responsive-slick-slider/admin/css/bootstrap.min.css/wp-content/plugins/responsive-slick-slider/admin/js/responsive-slick-slider-admin.js/wp-content/plugins/responsive-slick-slider/admin/js/jscolor.js
Version Parameters
responsive-slick-slider-admin.css?ver=bootstrap.min.css?ver=responsive-slick-slider-admin.js?ver=jscolor.js?ver=

HTML / DOM Fingerprints

CSS Classes
vsz_responsive_slick
HTML Comments
<!-- Add Slider --><!-- Slider Options -->
Data Attributes
data-cpt-name="vsz_responsive_slick"data-text-domain="vsz_responsive_slick"
JS Globals
responsive_slick_slider_admin
REST Endpoints
/wp-json/wp/v2/vsz_responsive_slick
FAQ

Frequently Asked Questions about Responsive Slick Slider WordPress