Slickstream: Engagement and Conversions Security & Risk Analysis

wordpress.org/plugins/slick-engagement

Use Slickstream to upgrade your site search. Get beautiful as-you-type search, relevant content recommendations, user favorites and more!

2K active installs v3.0.1 PHP 7.4.0+ WP 5.2.0+ Updated Sep 25, 2025
bookmarksengagementfavoritesrecommendationssearch
98
A · Safe
CVEs total2
Unpatched0
Last CVEJun 27, 2025
Safety Verdict

Is Slickstream: Engagement and Conversions Safe to Use in 2026?

Generally Safe

Score 98/100

Slickstream: Engagement and Conversions has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Jun 27, 2025Updated 7mo ago
Risk Assessment

The 'slick-engagement' v3.0.1 plugin presents a mixed security posture. On the positive side, the static analysis reveals a clean attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks. The code also demonstrates good practices regarding SQL queries, with 100% using prepared statements, and a strong emphasis on capability checks and nonce verification. However, there are notable areas of concern that temper the overall assessment. The taint analysis indicates that all analyzed flows involve unsanitized paths, even though no critical or high severity issues were flagged in this analysis. This suggests a potential for vulnerabilities if input is not consistently validated and sanitized, despite the absence of immediate critical findings. Furthermore, the plugin has a history of medium severity vulnerabilities, specifically Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS). While currently unpatched CVEs are zero, the existence of past vulnerabilities in these common types warrants vigilance and reinforces the need for robust input sanitization and output escaping.

Key Concerns

  • Taint flows with unsanitized paths detected
  • Past medium severity vulnerabilities (CSRF, XSS)
  • Only 85% of outputs properly escaped
  • File operations performed
  • External HTTP requests made
Vulnerabilities
2 published

Slickstream: Engagement and Conversions Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-53273medium · 4.3Cross-Site Request Forgery (CSRF)

Slickstream <= 2.0.3 - Cross-Site Request Forgery

Jun 27, 2025 Patched in 3.0.0 (85d)
CVE-2024-10179medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Slickstream: Engagement and Conversions <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via slick-grid Shortcode

Nov 11, 2024 Patched in 2.0.0 (1d)
Version History

Slickstream: Engagement and Conversions Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Slickstream: Engagement and Conversions Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
86 escaped
Nonce Checks
1
Capability Checks
2
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

85% escaped101 total outputs
Data Flows · Security
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
fetchPageBootData (PageBootData.php:126)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Slickstream: Engagement and Conversions Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuActionsFilters.php:139
actionwp_headActionsFilters.php:142
actioninitActionsFilters.php:143
filterrocket_delay_js_exclusionsActionsFilters.php:159
actionadmin_noticesslick-engagement.php:30
actionplugins_loadedslick-engagement.php:47
Maintenance & Trust

Slickstream: Engagement and Conversions Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 25, 2025
PHP min version7.4.0
Downloads59K

Community Trust

Rating100/100
Number of ratings11
Active installs2K
Developer Profile

Slickstream: Engagement and Conversions Developer Profile

Slickstream

1 plugin · 2K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
43 days
View full developer profile
Detection Fingerprints

How We Detect Slickstream: Engagement and Conversions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/slick-engagement/slick-engagement.css/wp-content/plugins/slick-engagement/slick-engagement.js
Script Paths
/wp-content/plugins/slick-engagement/slick-engagement.js
Version Parameters
slick-engagement/slick-engagement.css?ver=slick-engagement/slick-engagement.js?ver=

HTML / DOM Fingerprints

CSS Classes
slick-film-strip-wrapperslick-film-strip-itemslick-search-panel-wrapperslick-search-panel-inputslick-story-wrapperslick-story-content
HTML Comments
<!-- Slickstream Engagement plugin --><!-- Slickstream Filmstrip Markup --><!-- Slickstream Inline Search Panel Markup -->
Data Attributes
data-slick-site-codedata-slick-server-url
JS Globals
window.slickstreamConfigvar slickstreamSettings
REST Endpoints
/wp-json/slickstream/v1/search/wp-json/slickstream/v1/content
Shortcode Output
[slick-film-strip][slick-grid][slick-story][slick-story-carousel]
FAQ

Frequently Asked Questions about Slickstream: Engagement and Conversions