Weaver Show Sliders Security & Risk Analysis

wordpress.org/plugins/show-sliders

This isn't the typical plugin to create Sliders: Slide Shows, Carousels, Sliders with Posts. This is a Slider with options!

1K active installs v1.7 PHP + WP 5.4+ Updated Apr 1, 2023
recent-postsresponsiveresponsive-sliderslide-showslider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Weaver Show Sliders Safe to Use in 2026?

Generally Safe

Score 85/100

Weaver Show Sliders has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "show-sliders" v1.7 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and implementing a reasonable number of nonce and capability checks. The absence of known CVEs and a clean vulnerability history also suggest a generally stable plugin. However, the presence of the `unserialize` function is a significant concern. This function is notoriously dangerous when used with user-controlled input, as it can lead to remote code execution vulnerabilities if not handled with extreme care. The taint analysis further highlights this risk, revealing two high-severity flows with unsanitized paths, likely stemming from the use of `unserialize` on potentially untrusted data. While the attack surface is small and appears to be protected by authentication, these high-severity taint flows represent a concrete risk that could be exploited if an attacker can influence the data being unserialized.

Key Concerns

  • High severity taint flow with unsanitized path
  • High severity taint flow with unsanitized path
  • Use of dangerous unserialize function
  • Output escaping is not consistently applied
Vulnerabilities
None known

Weaver Show Sliders Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Weaver Show Sliders Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
65
116 escaped
Nonce Checks
4
Capability Checks
12
File Operations
1
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$restore = unserialize($contents);includes\atw-slider-slider-admin.php:722

Output Escaping

64% escaped181 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
atw_sliders_restore_filter (includes\atw-slider-slider-admin.php:667)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Weaver Show Sliders Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[show_slider] atw-show-sliders.php:340
WordPress Hooks 35
actionplugins_loadedatw-show-sliders.php:39
actionatw_show_sliders_post_pageratw-show-sliders.php:40
actioninitatw-show-sliders.php:65
actioninitatw-show-sliders.php:66
actionadd_meta_boxesatw-show-sliders.php:67
actionwp_enqueue_scriptsatw-show-sliders.php:68
actionwp_footeratw-show-sliders.php:69
actionadmin_enqueue_scriptsatw-show-sliders.php:70
filterpost_galleryatw-show-sliders.php:336
filterbody_classatw-show-sliders.php:837
actionadmin_menuatw-show-sliders.php:857
filteratw_slider_no_httpatw-show-sliders.php:909
actiontgmpa_registerincludes\atw-activate-show-posts.php:66
actioninitincludes\class-tgm-plugin-activation.php:277
actionadmin_menuincludes\class-tgm-plugin-activation.php:424
actionadmin_headincludes\class-tgm-plugin-activation.php:425
filterinstall_plugin_complete_actionsincludes\class-tgm-plugin-activation.php:428
filterupdate_plugin_complete_actionsincludes\class-tgm-plugin-activation.php:429
actionadmin_noticesincludes\class-tgm-plugin-activation.php:432
actionadmin_initincludes\class-tgm-plugin-activation.php:433
actionadmin_enqueue_scriptsincludes\class-tgm-plugin-activation.php:434
actionload-plugins.phpincludes\class-tgm-plugin-activation.php:439
actionswitch_themeincludes\class-tgm-plugin-activation.php:442
actionswitch_themeincludes\class-tgm-plugin-activation.php:445
actionadmin_initincludes\class-tgm-plugin-activation.php:450
actionswitch_themeincludes\class-tgm-plugin-activation.php:455
filterupgrader_source_selectionincludes\class-tgm-plugin-activation.php:804
actionplugins_loadedincludes\class-tgm-plugin-activation.php:1920
filtertgmpa_table_data_itemsincludes\class-tgm-plugin-activation.php:2044
filterupgrader_source_selectionincludes\class-tgm-plugin-activation.php:2771
actionadmin_initincludes\class-tgm-plugin-activation.php:2931
actionupgrader_process_completeincludes\class-tgm-plugin-activation.php:3026
filterupgrader_post_installincludes\class-tgm-plugin-activation.php:3083
filterupgrader_post_installincludes\class-tgm-plugin-activation.php:3225
actionwidgets_initincludes\slider-widgets.php:93
Maintenance & Trust

Weaver Show Sliders Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedApr 1, 2023
PHP min version
Downloads66K

Community Trust

Rating90/100
Number of ratings6
Active installs1K
Developer Profile

Weaver Show Sliders Developer Profile

wpweaver

6 plugins · 20K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
158 days
View full developer profile
Detection Fingerprints

How We Detect Weaver Show Sliders

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/show-sliders/includes/css/show-sliders.css/wp-content/plugins/show-sliders/includes/css/font-awesome.min.css/wp-content/plugins/show-sliders/includes/css/theme.css/wp-content/plugins/show-sliders/includes/css/slick.css/wp-content/plugins/show-sliders/includes/css/slick-theme.css/wp-content/plugins/show-sliders/includes/js/jquery.ddslick.js/wp-content/plugins/show-sliders/includes/js/jquery.easing.1.3.js/wp-content/plugins/show-sliders/includes/js/slick.min.js+1 more
Script Paths
/wp-content/plugins/show-sliders/includes/js/jquery.ddslick.js/wp-content/plugins/show-sliders/includes/js/jquery.easing.1.3.js/wp-content/plugins/show-sliders/includes/js/slick.min.js/wp-content/plugins/show-sliders/includes/js/show-sliders.js
Version Parameters
show-sliders/includes/css/show-sliders.css?ver=show-sliders/includes/css/font-awesome.min.css?ver=show-sliders/includes/css/theme.css?ver=show-sliders/includes/css/slick.css?ver=show-sliders/includes/css/slick-theme.css?ver=show-sliders/includes/js/jquery.ddslick.js?ver=show-sliders/includes/js/jquery.easing.1.3.js?ver=show-sliders/includes/js/slick.min.js?ver=show-sliders/includes/js/show-sliders.js?ver=

HTML / DOM Fingerprints

CSS Classes
slick-slideslick-trackslick-listslick-arrowslick-prevslick-nextdd-selectdd-option+2 more
HTML Comments
<!-- begin atw_show_sliders --><!-- end atw_show_sliders --><!-- weaver : end slider --><!-- weaver : end slide -->+5 more
Data Attributes
data-slick-indexdata-slick-slidedata-lazydata-thumb
JS Globals
show_sliders_options
Shortcode Output
<div class="atw-slider<div class="atw-slider-image<div class="atw-slider-content<div class="atw-slider-caption
FAQ

Frequently Asked Questions about Weaver Show Sliders