
Simple SEO Slideshow Security & Risk Analysis
wordpress.org/plugins/simple-seo-slideshowA plugin to display slideshow in a widget with title, description and custom link from page or post gallery.
Is Simple SEO Slideshow Safe to Use in 2026?
Generally Safe
Score 85/100Simple SEO Slideshow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'simple-seo-slideshow' v1.2.8 exhibits a generally positive security posture due to its lack of known vulnerabilities and a significant portion of its SQL queries using prepared statements. The absence of external HTTP requests and file operations further contributes to a reduced attack surface. However, there are notable areas of concern. The presence of the dangerous `create_function` function, even if it's only one instance, can be a significant security risk if not handled with extreme care, as it allows for arbitrary code execution. Furthermore, the low percentage (22%) of properly escaped output is a substantial weakness, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks on the identified entry point (shortcode) also means that actions triggered by this shortcode are susceptible to Cross-Site Request Forgery (CSRF) attacks. While the vulnerability history is clean, the identified code-level weaknesses suggest that this plugin could be vulnerable if exploited through its limited entry points.
Key Concerns
- Dangerous function create_function used
- Low percentage of properly escaped output
- Missing nonce check on entry point (shortcode)
Simple SEO Slideshow Security Vulnerabilities
Simple SEO Slideshow Release Timeline
Simple SEO Slideshow Code Analysis
Dangerous Functions Found
Output Escaping
Simple SEO Slideshow Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Simple SEO Slideshow Maintenance & Trust
Maintenance Signals
Community Trust
Simple SEO Slideshow Alternatives
No alternatives data available yet.
Simple SEO Slideshow Developer Profile
3 plugins · 5K total installs
How We Detect Simple SEO Slideshow
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-seo-slideshow/slideshow.css/wp-content/plugins/simple-seo-slideshow/slideshow.js/wp-content/plugins/simple-seo-slideshow/widget.css/wp-content/plugins/simple-seo-slideshow/slideshow.jssimple-seo-slideshow/slideshow.css?ver=simple-seo-slideshow/slideshow.js?ver=simple-seo-slideshow/widget.css?ver=HTML / DOM Fingerprints
simpleSlideshowWidgetsss-containersss-imgsss-captionsss-prevsss-nextsss-bulletssss-bullet<!-- Simple SEO Slideshow Widget --><!-- /Simple SEO Slideshow Widget --><!-- Slideshow Start --><!-- Slideshow End -->data-sss-delaydata-sss-heightdata-sss-display-bulletsdata-sss-display-arrowsdata-sss-display-captiondata-sss-bullets-position+4 moresimpleSEOSlideshow[simple_slideshow]