
Simple SEO Slideshow Security & Risk Analysis
wordpress.org/plugins/simple-seo-slideshowA plugin to display slideshow in a widget with title, description and custom link from page or post gallery.
Is Simple SEO Slideshow Safe to Use in 2026?
Generally Safe
Score 85/100Simple SEO Slideshow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'simple-seo-slideshow' v1.2.8 exhibits a generally positive security posture due to its lack of known vulnerabilities and a significant portion of its SQL queries using prepared statements. The absence of external HTTP requests and file operations further contributes to a reduced attack surface. However, there are notable areas of concern. The presence of the dangerous `create_function` function, even if it's only one instance, can be a significant security risk if not handled with extreme care, as it allows for arbitrary code execution. Furthermore, the low percentage (22%) of properly escaped output is a substantial weakness, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks on the identified entry point (shortcode) also means that actions triggered by this shortcode are susceptible to Cross-Site Request Forgery (CSRF) attacks. While the vulnerability history is clean, the identified code-level weaknesses suggest that this plugin could be vulnerable if exploited through its limited entry points.
Key Concerns
- Dangerous function create_function used
- Low percentage of properly escaped output
- Missing nonce check on entry point (shortcode)
Simple SEO Slideshow Security Vulnerabilities
Simple SEO Slideshow Code Analysis
Dangerous Functions Found
Output Escaping
Simple SEO Slideshow Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Simple SEO Slideshow Maintenance & Trust
Maintenance Signals
Community Trust
Simple SEO Slideshow Alternatives
No alternatives data available yet.
Simple SEO Slideshow Developer Profile
3 plugins · 5K total installs
How We Detect Simple SEO Slideshow
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-seo-slideshow/slideshow.css/wp-content/plugins/simple-seo-slideshow/slideshow.js/wp-content/plugins/simple-seo-slideshow/widget.css/wp-content/plugins/simple-seo-slideshow/slideshow.jssimple-seo-slideshow/slideshow.css?ver=simple-seo-slideshow/slideshow.js?ver=simple-seo-slideshow/widget.css?ver=HTML / DOM Fingerprints
simpleSlideshowWidgetsss-containersss-imgsss-captionsss-prevsss-nextsss-bulletssss-bullet<!-- Simple SEO Slideshow Widget --><!-- /Simple SEO Slideshow Widget --><!-- Slideshow Start --><!-- Slideshow End -->data-sss-delaydata-sss-heightdata-sss-display-bulletsdata-sss-display-arrowsdata-sss-display-captiondata-sss-bullets-position+4 moresimpleSEOSlideshow[simple_slideshow]