
Slider Blocks Security & Risk Analysis
wordpress.org/plugins/slider-blocksSlider Blocks is a WordPress Slider Block Plugin that allows you to create a slider or carousel with both static and dyanmic content.
Is Slider Blocks Safe to Use in 2026?
Generally Safe
Score 99/100Slider Blocks has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The slider-blocks plugin v2.11.4 exhibits a mixed security posture. On the positive side, the code demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output. The plugin also includes some nonce and capability checks, indicating an awareness of security. However, a significant concern arises from the presence of an unprotected REST API route, which presents a direct attack vector. The static analysis identified a total of 2 entry points, with 1 being unprotected, highlighting a potential vulnerability.
The vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, last patched on 2024-07-10. While there are no currently unpatched vulnerabilities, this history suggests that the plugin has had exploitable flaws in the past. The absence of critical or high severity taint flows is a positive sign, but the single unprotected REST API route remains a critical oversight that could be exploited without proper authentication.
In conclusion, while the plugin utilizes secure coding practices for database interactions and output handling, the unprotected REST API route introduces a substantial risk. The past XSS vulnerability also warrants attention, suggesting a need for continuous security diligence. The plugin's strengths lie in its output escaping and SQL practices, but its weakness is the exposed REST API endpoint.
Key Concerns
- Unprotected REST API route
- Past medium severity CVE
Slider Blocks Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
GutSlider – All in One Block Slider <= 2.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Slider Blocks Release Timeline
Slider Blocks Code Analysis
Output Escaping
Data Flow Analysis
Slider Blocks Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 18
Maintenance & Trust
Slider Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Slider Blocks Alternatives
Simple Slider Block – Create Sliders From Core Blocks
gutenberg-block-for-slick-slider
Create sliders from core blocks.
BubiBlock Slider
bubiblock-slider
Slider Block for Gutenberg. Create a image slider, color slider, video slider, fullscreen slider with this powerful and simple slider block.
Awesome Logo Carousel Block
awesome-logo-carousel-block
Awesome Logo Carousel Block allows you to create interactive client logos carousel with Gutenberg Block Editor.
WP Swiper
wp-swiper
Gutenberg Block The Most Modern Mobile Touch Slider. Swiper is the most modern free mobile touch slider with hardware accelerated transitions and amaz …
Slider and Carousel Block – Responsive, Accessible
blablablocks-slider-block
Build responsive, accessible sliders or carousel in the Block Editor fast templates, no code needed.
Slider Blocks Developer Profile
5 plugins · 27K total installs
How We Detect Slider Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/slider-blocks/admin/css/admin.css/wp-content/plugins/slider-blocks/admin/js/admin.js/wp-content/plugins/slider-blocks/build/index.js/wp-content/plugins/slider-blocks/build/index.asset.php/wp-content/plugins/slider-blocks/admin/js/admin.js/wp-content/plugins/slider-blocks/build/index.jsslider-blocks/admin/css/admin.css?ver=slider-blocks/admin/js/admin.js?ver=slider-blocks/build/index.js?ver=HTML / DOM Fingerprints
gutslider-blocks-editor-wrapperblock-editor-block-list__blockdata-gutsilder-block-idwindow.gutSliderBlocksData/wp-json/gutslider/v1/blocks/settings