
Slickstream: Engagement and Conversions Security & Risk Analysis
wordpress.org/plugins/slick-engagementUse Slickstream to upgrade your site search. Get beautiful as-you-type search, relevant content recommendations, user favorites and more!
Is Slickstream: Engagement and Conversions Safe to Use in 2026?
Generally Safe
Score 98/100Slickstream: Engagement and Conversions has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'slick-engagement' v3.0.1 plugin presents a mixed security posture. On the positive side, the static analysis reveals a clean attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks. The code also demonstrates good practices regarding SQL queries, with 100% using prepared statements, and a strong emphasis on capability checks and nonce verification. However, there are notable areas of concern that temper the overall assessment. The taint analysis indicates that all analyzed flows involve unsanitized paths, even though no critical or high severity issues were flagged in this analysis. This suggests a potential for vulnerabilities if input is not consistently validated and sanitized, despite the absence of immediate critical findings. Furthermore, the plugin has a history of medium severity vulnerabilities, specifically Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS). While currently unpatched CVEs are zero, the existence of past vulnerabilities in these common types warrants vigilance and reinforces the need for robust input sanitization and output escaping.
Key Concerns
- Taint flows with unsanitized paths detected
- Past medium severity vulnerabilities (CSRF, XSS)
- Only 85% of outputs properly escaped
- File operations performed
- External HTTP requests made
Slickstream: Engagement and Conversions Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Slickstream <= 2.0.3 - Cross-Site Request Forgery
Slickstream: Engagement and Conversions <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via slick-grid Shortcode
Slickstream: Engagement and Conversions Release Timeline
Slickstream: Engagement and Conversions Code Analysis
Output Escaping
Data Flow Analysis
Slickstream: Engagement and Conversions Attack Surface
WordPress Hooks 6
Maintenance & Trust
Slickstream: Engagement and Conversions Maintenance & Trust
Maintenance Signals
Community Trust
Slickstream: Engagement and Conversions Alternatives
Clerk
clerkio
Clerk.io is a software that helps your customers buy more from your webshop, through 4 amazing feature:
Salesfire
salesfire
Boost the conversion rate of your WordPress or WooCommerce store with Salesfire's suite of intelligent CRO tools.
DBWD Bookmark Page
dbwd-bookmark-page
Adds a "Bookmark this Page" button to your header WITHOUT editing your theme - Firefox and IE tested.
Engaging Buttons
engaging-buttons
Easily add research-based, engaging buttons (such as "Respect" or "Important") to your site.
Visidea
visidea
Visidea is the Visual Search, Search Bar and Product Recommendations plugin for WooCommerce.
Slickstream: Engagement and Conversions Developer Profile
1 plugin · 2K total installs
How We Detect Slickstream: Engagement and Conversions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/slick-engagement/slick-engagement.css/wp-content/plugins/slick-engagement/slick-engagement.js/wp-content/plugins/slick-engagement/slick-engagement.jsslick-engagement/slick-engagement.css?ver=slick-engagement/slick-engagement.js?ver=HTML / DOM Fingerprints
slick-film-strip-wrapperslick-film-strip-itemslick-search-panel-wrapperslick-search-panel-inputslick-story-wrapperslick-story-content<!-- Slickstream Engagement plugin --><!-- Slickstream Filmstrip Markup --><!-- Slickstream Inline Search Panel Markup -->data-slick-site-codedata-slick-server-urlwindow.slickstreamConfigvar slickstreamSettings/wp-json/slickstream/v1/search/wp-json/slickstream/v1/content[slick-film-strip][slick-grid][slick-story][slick-story-carousel]