Scrollsequence – Cinematic Scroll Image Animation Plugin Security & Risk Analysis

wordpress.org/plugins/scrollsequence

Image sequence animation on scroll. Take any video, and transform it into immersive dynamic landing page that animate as you scroll.

4K active installs v1.6.2 PHP 7.0+ WP 5.0+ Updated Jul 31, 2025
image-animationimage-sequencescrollscroll-animationvideo-scroll
100
A · Safe
CVEs total1
Unpatched0
Last CVEMar 16, 2024
Safety Verdict

Is Scrollsequence – Cinematic Scroll Image Animation Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

Scrollsequence – Cinematic Scroll Image Animation Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 16, 2024Updated 8mo ago
Risk Assessment

The Scrollsequence plugin v1.6.2 presents a mixed security posture. While it demonstrates some good practices, such as a relatively low number of total SQL queries and a reasonable percentage of those using prepared statements, and a good rate of output escaping, there are significant concerns. A notable weakness is the presence of four unprotected AJAX handlers, forming a substantial portion of its attack surface. Furthermore, the taint analysis revealed a flow with unsanitized paths of high severity, indicating a potential for vulnerabilities if user input is not handled carefully. The plugin's vulnerability history, while currently showing no unpatched CVEs, includes a past medium severity vulnerability for Cross-Site Scripting, suggesting a prior area of weakness that warrants ongoing vigilance. The bundled Freemius library, though at version 1.0, is a potential concern if it has known vulnerabilities that are not addressed by the plugin itself. Overall, the plugin has strengths in its SQL query practices and output escaping, but the high number of unprotected entry points and the critical taint flow are significant risk factors.

Key Concerns

  • Unprotected AJAX handlers
  • High severity taint flow
  • Bundled Freemius v1.0 library
  • Past medium CVE for XSS
Vulnerabilities
1

Scrollsequence – Cinematic Scroll Image Animation Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-29118medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Scrollsequence <= 1.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 16, 2024 Patched in 1.5.5 (5d)
Code Analysis
Analyzed Mar 16, 2026

Scrollsequence – Cinematic Scroll Image Animation Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
8
6 prepared
Unescaped Output
56
121 escaped
Nonce Checks
3
Capability Checks
5
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

43% prepared14 total queries

Output Escaping

68% escaped177 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
<scrollsequence-admin-display-media-tools-preview> (admin\partials\scrollsequence-admin-display-media-tools-preview.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Scrollsequence – Cinematic Scroll Image Animation Plugin Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 4

authwp_ajax_carbon_fields_add_sidebarincludes\carbonfields\htmlburger\carbon-fields\core\Libraries\Sidebar_Manager\Sidebar_Manager.php:26
authwp_ajax_carbon_fields_remove_sidebarincludes\carbonfields\htmlburger\carbon-fields\core\Libraries\Sidebar_Manager\Sidebar_Manager.php:27
authwp_ajax_carbon_fields_fetch_association_optionsincludes\carbonfields\htmlburger\carbon-fields\core\Loader\Loader.php:51
authwp_ajax_add_scrollsequence_postincludes\class-scrollsequence.php:201

Shortcodes 1

[scrollsequence] admin\class-scrollsequence-admin.php:56
WordPress Hooks 95
actionadmin_enqueue_scriptsadmin\class-scrollsequence-admin.php:177
actioninitincludes\carbonfields\htmlburger\carbon-fields\core\Container\Block_Container.php:73
filterblock_categories_allincludes\carbonfields\htmlburger\carbon-fields\core\Container\Block_Container.php:125
actionadmin_initincludes\carbonfields\htmlburger\carbon-fields\core\Container\Comment_Meta_Container.php:35
actionedit_commentincludes\carbonfields\htmlburger\carbon-fields\core\Container\Comment_Meta_Container.php:36
filterwp_edit_nav_menu_walkerincludes\carbonfields\htmlburger\carbon-fields\core\Container\Nav_Menu_Item_Container.php:42
actionwp_update_nav_menu_itemincludes\carbonfields\htmlburger\carbon-fields\core\Container\Nav_Menu_Item_Container.php:58
actioncarbon_fields_print_nav_menu_item_container_fieldsincludes\carbonfields\htmlburger\carbon-fields\core\Container\Nav_Menu_Item_Container.php:59
actionnetwork_admin_menuincludes\carbonfields\htmlburger\carbon-fields\core\Container\Network_Container.php:41
actionadmin_initincludes\carbonfields\htmlburger\carbon-fields\core\Container\Post_Meta_Container.php:69
actionsave_postincludes\carbonfields\htmlburger\carbon-fields\core\Container\Post_Meta_Container.php:70
actionadd_attachmentincludes\carbonfields\htmlburger\carbon-fields\core\Container\Post_Meta_Container.php:73
actionedit_attachmentincludes\carbonfields\htmlburger\carbon-fields\core\Container\Post_Meta_Container.php:74
actionadmin_initincludes\carbonfields\htmlburger\carbon-fields\core\Container\Term_Meta_Container.php:32
actioninitincludes\carbonfields\htmlburger\carbon-fields\core\Container\Term_Meta_Container.php:33
actionadmin_menuincludes\carbonfields\htmlburger\carbon-fields\core\Container\Theme_Options_Container.php:77
actionadmin_initincludes\carbonfields\htmlburger\carbon-fields\core\Container\User_Meta_Container.php:33
actionprofile_updateincludes\carbonfields\htmlburger\carbon-fields\core\Container\User_Meta_Container.php:34
actionuser_registerincludes\carbonfields\htmlburger\carbon-fields\core\Container\User_Meta_Container.php:35
actionshow_user_profileincludes\carbonfields\htmlburger\carbon-fields\core\Container\User_Meta_Container.php:151
actionedit_user_profileincludes\carbonfields\htmlburger\carbon-fields\core\Container\User_Meta_Container.php:152
actionuser_new_formincludes\carbonfields\htmlburger\carbon-fields\core\Container\User_Meta_Container.php:153
actiondelete_termincludes\carbonfields\htmlburger\carbon-fields\core\Datastore\Term_Meta_Datastore.php:28
actionadmin_noticesincludes\carbonfields\htmlburger\carbon-fields\core\Exception\Incorrect_Syntax_Exception.php:18
actionnetwork_admin_noticesincludes\carbonfields\htmlburger\carbon-fields\core\Exception\Incorrect_Syntax_Exception.php:19
filterposts_fields_requestincludes\carbonfields\htmlburger\carbon-fields\core\Field\Association_Field.php:446
filterposts_groupby_requestincludes\carbonfields\htmlburger\carbon-fields\core\Field\Association_Field.php:448
filterposts_orderby_requestincludes\carbonfields\htmlburger\carbon-fields\core\Field\Association_Field.php:449
filterpost_limits_requestincludes\carbonfields\htmlburger\carbon-fields\core\Field\Association_Field.php:450
filterget_terms_fieldsincludes\carbonfields\htmlburger\carbon-fields\core\Field\Association_Field.php:511
filterterms_clausesincludes\carbonfields\htmlburger\carbon-fields\core\Field\Association_Field.php:512
filtercomments_clausesincludes\carbonfields\htmlburger\carbon-fields\core\Field\Association_Field.php:616
actionadmin_print_footer_scriptsincludes\carbonfields\htmlburger\carbon-fields\core\Field\Field.php:296
actionadmin_print_footer_scriptsincludes\carbonfields\htmlburger\carbon-fields\core\Field\Field.php:297
actionadmin_print_footer_scriptsincludes\carbonfields\htmlburger\carbon-fields\core\Field\Field.php:313
actionadmin_footerincludes\carbonfields\htmlburger\carbon-fields\core\Field\Rich_Text_Field.php:85
filteruser_can_richeditincludes\carbonfields\htmlburger\carbon-fields\core\Field\Rich_Text_Field.php:103
actionmedia_buttonsincludes\carbonfields\htmlburger\carbon-fields\core\Field\Rich_Text_Field.php:140
actionwpincludes\carbonfields\htmlburger\carbon-fields\core\Field\Scripts_Field.php:31
actionwidgets_initincludes\carbonfields\htmlburger\carbon-fields\core\Libraries\Sidebar_Manager\Sidebar_Manager.php:15
actionadmin_enqueue_scriptsincludes\carbonfields\htmlburger\carbon-fields\core\Libraries\Sidebar_Manager\Sidebar_Manager.php:18
filtercarbon_fields_sidebar_default_optionsincludes\carbonfields\htmlburger\carbon-fields\core\Libraries\Sidebar_Manager\Sidebar_Manager.php:22
actionafter_setup_themeincludes\carbonfields\htmlburger\carbon-fields\core\Loader\Loader.php:43
actioninitincludes\carbonfields\htmlburger\carbon-fields\core\Loader\Loader.php:44
actionrest_api_initincludes\carbonfields\htmlburger\carbon-fields\core\Loader\Loader.php:45
actioncarbon_fields_fields_registeredincludes\carbonfields\htmlburger\carbon-fields\core\Loader\Loader.php:46
actionadmin_enqueue_scriptsincludes\carbonfields\htmlburger\carbon-fields\core\Loader\Loader.php:47
actionadmin_print_footer_scriptsincludes\carbonfields\htmlburger\carbon-fields\core\Loader\Loader.php:48
actionadmin_print_footer_scriptsincludes\carbonfields\htmlburger\carbon-fields\core\Loader\Loader.php:49
actionedit_form_after_titleincludes\carbonfields\htmlburger\carbon-fields\core\Loader\Loader.php:50
filtercarbon_fields_container_static_condition_typesincludes\carbonfields\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:254
filtercarbon_fields_post_meta_container_static_condition_typesincludes\carbonfields\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:262
filtercarbon_fields_post_meta_container_dynamic_condition_typesincludes\carbonfields\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:263
filtercarbon_fields_term_meta_container_static_condition_typesincludes\carbonfields\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:265
filtercarbon_fields_term_meta_container_dynamic_condition_typesincludes\carbonfields\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:266
filtercarbon_fields_user_meta_container_static_condition_typesincludes\carbonfields\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:268
filtercarbon_fields_user_meta_container_dynamic_condition_typesincludes\carbonfields\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:269
filtercarbon_fields_theme_options_container_static_condition_typesincludes\carbonfields\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:271
actionrest_api_initincludes\carbonfields\htmlburger\carbon-fields\core\REST_API\Decorator.php:31
actionrest_api_initincludes\carbonfields\htmlburger\carbon-fields\core\REST_API\Router.php:113
filtercarbon_fields_datastore_storage_arrayincludes\carbonfields\htmlburger\carbon-fields\core\Service\Legacy_Storage_Service_v_1_5.php:60
filterget_meta_sqlincludes\carbonfields\htmlburger\carbon-fields\core\Service\Meta_Query_Service.php:42
actionpre_get_postsincludes\carbonfields\htmlburger\carbon-fields\core\Service\Meta_Query_Service.php:44
actionpre_get_termsincludes\carbonfields\htmlburger\carbon-fields\core\Service\Meta_Query_Service.php:45
actionpre_get_usersincludes\carbonfields\htmlburger\carbon-fields\core\Service\Meta_Query_Service.php:46
actioncarbon_fields_fields_registeredincludes\carbonfields\htmlburger\carbon-fields\core\Service\REST_API_Service.php:40
filtercarbon_get_post_meta_post_idincludes\carbonfields\htmlburger\carbon-fields\core\Service\Revisions_Service.php:11
actioncarbon_fields_post_meta_container_savedincludes\carbonfields\htmlburger\carbon-fields\core\Service\Revisions_Service.php:12
filter_wp_post_revision_fieldsincludes\carbonfields\htmlburger\carbon-fields\core\Service\Revisions_Service.php:13
filter_wp_post_revision_fieldsincludes\carbonfields\htmlburger\carbon-fields\core\Service\Revisions_Service.php:14
actionwp_restore_post_revisionincludes\carbonfields\htmlburger\carbon-fields\core\Service\Revisions_Service.php:15
filterwp_save_post_revision_check_for_changesincludes\carbonfields\htmlburger\carbon-fields\core\Service\Revisions_Service.php:16
actionplugins_loadedincludes\class-scrollsequence.php:142
actionadmin_enqueue_scriptsincludes\class-scrollsequence.php:157
actionadmin_enqueue_scriptsincludes\class-scrollsequence.php:158
actioninitincludes\class-scrollsequence.php:160
actioninitincludes\class-scrollsequence.php:162
actioninitincludes\class-scrollsequence.php:164
actionadmin_headincludes\class-scrollsequence.php:165
actiontemplate_includeincludes\class-scrollsequence.php:169
actionafter_setup_themeincludes\class-scrollsequence.php:171
actioncarbon_fields_register_fieldsincludes\class-scrollsequence.php:173
actionadmin_noticesincludes\class-scrollsequence.php:176
actionedit_form_after_titleincludes\class-scrollsequence.php:179
actionmanage_scrollsequence_posts_columnsincludes\class-scrollsequence.php:182
actionmanage_scrollsequence_posts_custom_columnincludes\class-scrollsequence.php:183
actionmanage_scrollsequence_posts_columnsincludes\class-scrollsequence.php:186
actionmanage_scrollsequence_posts_custom_columnincludes\class-scrollsequence.php:187
actionadmin_initincludes\class-scrollsequence.php:190
actionpost_row_actionsincludes\class-scrollsequence.php:193
actionadmin_action_duplicate_scrollsequence_as_draftincludes\class-scrollsequence.php:194
actionadmin_noticesincludes\class-scrollsequence.php:195
actionadmin_enqueue_scriptsincludes\class-scrollsequence.php:198
actionwp_enqueue_scriptsincludes\class-scrollsequence.php:222
actionwp_enqueue_scriptsincludes\class-scrollsequence.php:223
Maintenance & Trust

Scrollsequence – Cinematic Scroll Image Animation Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 31, 2025
PHP min version7.0
Downloads126K

Community Trust

Rating92/100
Number of ratings19
Active installs4K
Developer Profile

Scrollsequence – Cinematic Scroll Image Animation Plugin Developer Profile

Scrollsequence

1 plugin · 4K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Scrollsequence – Cinematic Scroll Image Animation Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scrollsequence/css/scrollsequence-admin.css/wp-content/plugins/scrollsequence/js/scrollsequence-admin.js/wp-content/plugins/scrollsequence/js/scrollsequence-public.js
Version Parameters
scrollsequence-admin.css?ver=scrollsequence-admin.js?ver=scrollsequence-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
scrollsequence-containerscrollsequence-animation
HTML Comments
<!-- Shortcode scrollsequence -->
Data Attributes
data-scrollsequence-loopdata-scrollsequence-playdata-scrollsequence-rewinddata-scrollsequence-images
JS Globals
scrollsequence
Shortcode Output
[scrollsequence]
FAQ

Frequently Asked Questions about Scrollsequence – Cinematic Scroll Image Animation Plugin