Slider Factory Security & Risk Analysis

wordpress.org/plugins/slider-factory

Build image sliders, photo carousels, and video slideshows with 12 layouts. Drag-and-drop interface with responsive design.

3K active installs v1.3.13 PHP 5.0+ WP 5.0+ Updated Feb 19, 2026
carouselimage-sliderphoto-sliderresponsive-sliderslider
99
A · Safe
CVEs total2
Unpatched0
Last CVEOct 20, 2021
Safety Verdict

Is Slider Factory Safe to Use in 2026?

Generally Safe

Score 99/100

Slider Factory has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Oct 20, 2021Updated 1mo ago
Risk Assessment

The static analysis of slider-factory v1.3.13 reveals a generally strong security posture. The plugin demonstrates excellent adherence to secure coding practices, with 100% of SQL queries using prepared statements, 99% of output being properly escaped, and robust use of nonce and capability checks on its entry points. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. Taint analysis shows no critical or high severity issues related to unsanitized data flows.

However, the plugin's vulnerability history presents a significant concern. It has a history of two known CVEs, including one high and one medium severity vulnerability, primarily related to Missing Authorization and Cross-Site Request Forgery (CSRF). While there are currently no unpatched vulnerabilities, the existence of past critical security flaws, especially those involving authorization bypass and CSRF, indicates a recurring weakness in how user actions and data are handled, even if current code analysis doesn't highlight immediate risks. The last vulnerability was recorded in 2021, suggesting a long period without publicly disclosed issues, but past patterns are important to consider.

In conclusion, while slider-factory v1.3.13 exhibits strong technical security measures in its current codebase, its historical vulnerability record necessitates caution. The past high and medium severity issues, particularly around authorization and CSRF, suggest that thorough auditing and vigilant monitoring of future updates are crucial. Users should be aware that despite good current static analysis results, a history of significant vulnerabilities implies potential for similar issues to re-emerge.

Key Concerns

  • High severity historical vulnerability
  • Medium severity historical vulnerability
  • Past missing authorization vulnerabilities
  • Past CSRF vulnerabilities
Vulnerabilities
2

Slider Factory Security Vulnerabilities

CVEs by Year

2 CVEs in 2021
2021
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

Responsive Image Slider, Photo Gallery And Carousel < 1.3.6 - Missing Authorization

Oct 20, 2021 Patched in 1.3.6 (825d)
WF-6f00dfd7-3194-4459-b895-f16d3aa8d66f-slider-factoryhigh · 8.8Cross-Site Request Forgery (CSRF)

Responsive Image Slider, Photo Gallery And Carousel < 1.3.2 - Cross-Site Request Forgery

Oct 18, 2021 Patched in 1.3.2 (827d)
Code Analysis
Analyzed Mar 16, 2026

Slider Factory Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
7
959 escaped
Nonce Checks
6
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

99% escaped966 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
<manage-slider> (admin\manage-slider.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Slider Factory Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 4

authwp_ajax_sf_image_idslider-factory.php:188
authwp_ajax_sf_save_sliderslider-factory.php:434
authwp_ajax_sf_clone_sliderslider-factory.php:490
authwp_ajax_sf_remove_sliderslider-factory.php:524

Shortcodes 1

[sf] shortcode.php:6
WordPress Hooks 5
actionplugins_loadedslider-factory.php:70
actionadmin_menuslider-factory.php:79
actionadmin_enqueue_scriptsslider-factory.php:111
actionwp_enqueue_scriptsslider-factory.php:583
filterwidget_textslider-factory.php:587
Maintenance & Trust

Slider Factory Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version5.0
Downloads55K

Community Trust

Rating90/100
Number of ratings13
Active installs3K
Developer Profile

Slider Factory Developer Profile

FARAZFRANK

28 plugins · 47K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
578 days
View full developer profile
Detection Fingerprints

How We Detect Slider Factory

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/slider-factory/admin/assets/css/style.css/wp-content/plugins/slider-factory/admin/assets/bootstrap-5.0.0/css/bootstrap-admin.css/wp-content/plugins/slider-factory/admin/assets/fontawesome-free-5.15.1-web/css/all.css/wp-content/plugins/slider-factory/admin/assets/bootstrap-5.0.0/js/bootstrap.js/wp-content/plugins/slider-factory/admin/assets/bootstrap-5.0.0/js/bootstrap.bundle.js
Script Paths
admin/assets/css/style.cssadmin/assets/bootstrap-5.0.0/css/bootstrap-admin.cssadmin/assets/fontawesome-free-5.15.1-web/css/all.cssadmin/assets/bootstrap-5.0.0/js/bootstrap.jsadmin/assets/bootstrap-5.0.0/js/bootstrap.bundle.js
Version Parameters
slider-factory/admin/assets/css/style.css?ver=slider-factory/admin/assets/bootstrap-5.0.0/css/bootstrap-admin.css?ver=slider-factory/admin/assets/fontawesome-free-5.15.1-web/css/all.css?ver=slider-factory/admin/assets/bootstrap-5.0.0/js/bootstrap.js?ver=slider-factory/admin/assets/bootstrap-5.0.0/js/bootstrap.bundle.js?ver=

HTML / DOM Fingerprints

CSS Classes
sf-slide-columnsf-slide-boxsf_slide_idsf_slide_titlesf_slide_descsf_slide_thumbnailsf_slide_linksf_slide_alt+12 more
Data Attributes
data-position
JS Globals
sf_upload_nonce
FAQ

Frequently Asked Questions about Slider Factory