
Slider Templates Security & Risk Analysis
wordpress.org/plugins/slider-templatesAutomatically import Slider Templates from slider-templates.com to your website with just one-click!
Is Slider Templates Safe to Use in 2026?
High Risk
Score 41/100Slider Templates carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The "slider-templates" plugin v1.0.3 presents a concerning security posture, despite some positive indicators like the use of prepared statements for all SQL queries and a high percentage of properly escaped output. The primary weakness lies in its attack surface, with two AJAX handlers that lack any authentication checks. This directly exposes functionalities that could be manipulated by unauthenticated users.
The taint analysis reveals two flows with unsanitized paths, indicating a potential for path traversal vulnerabilities. While no critical or high severity taint flows were found, the presence of unsanitized paths in conjunction with unprotected AJAX endpoints significantly elevates the risk. The vulnerability history is also a major red flag, with two known medium severity CVEs, both of which remain unpatched. These past vulnerabilities, specifically mentioning Missing Authorization and Server-Side Request Forgery (SSRF), align directly with the identified lack of authorization on AJAX endpoints and the presence of unsanitized paths, suggesting a recurring pattern of insecure development practices.
In conclusion, while the plugin demonstrates good practices in database interaction and output sanitization, the critical deficiencies in authentication for its AJAX endpoints, coupled with unsanitized path flows and a history of unpatched authorization and SSRF vulnerabilities, make this plugin a significant security risk. The unpatched CVEs alone warrant immediate attention, and the code analysis highlights the underlying reasons for these historical issues, which persist in the current version.
Key Concerns
- Unpatched CVEs (2)
- Unprotected AJAX handlers (2)
- Taint flows with unsanitized paths (2)
- Vulnerability history: Missing Authorization
- Vulnerability history: SSRF
Slider Templates Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Slider Templates <= 1.0.3 - Missing Authorization
Slider Templates <= 1.0.3 - Authenticated (Subscriber+) Server-Side Request Forgery
Slider Templates Release Timeline
Slider Templates Code Analysis
Output Escaping
Data Flow Analysis
Slider Templates Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
Slider Templates Maintenance & Trust
Maintenance Signals
Community Trust
Slider Templates Alternatives
Ditty – Responsive News Tickers, Sliders, and Lists
ditty-news-ticker
Ditty offers a range of content display options, including its signature news ticker and customizable layouts.
Ultimate Responsive Image Slider
ultimate-responsive-image-slider
Create stunning responsive sliders in minutes. Drag-and-drop builder, unlimited sliders, mobile-friendly & SEO optimized!
WP Logo Showcase Responsive Slider and Carousel
wp-logo-showcase-responsive-slider-slider
WP Logo Showcase Responsive Slider and Carousel allows you to display logos of clients, sponsors, brands, or partners in a professional and responsive …
Serious Slider
cryout-serious-slider
Serious Slider is a free highly efficient SEO friendly fully translatable accessibility ready image slider for WordPress. Seriously!
Slider by 10Web – Responsive Image Slider
slider-wd
Slider by 10Web plugin is the perfect slider solution for Wordpress.
Slider Templates Developer Profile
8 plugins · 2K total installs
How We Detect Slider Templates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/slider-templates/admin/css/slider-templates-admin.css/wp-content/plugins/slider-templates/admin/js/slider-templates-admin.js/wp-content/plugins/slider-templates/admin/js/slider-templates-admin.jsslider-templates/admin/css/slider-templates-admin.css?ver=slider-templates/admin/js/slider-templates-admin.js?ver=HTML / DOM Fingerprints
data-st-modulest/wp-json/st/v1/