Video Slider – Slider Carousel Security & Risk Analysis

wordpress.org/plugins/slider-video

SLIDER plugin was created and specially designed for YouTube, Vimeo, Vevo and MP4 video to show in slider.

4K active installs v1.5.3 PHP + WP + Updated Sep 23, 2023
image-sliderphoto-slidersliderslider-pluginwordpress-slider
85
A · Safe
CVEs total1
Unpatched0
Last CVEMay 16, 2022
Safety Verdict

Is Video Slider – Slider Carousel Safe to Use in 2026?

Generally Safe

Score 85/100

Video Slider – Slider Carousel has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: May 16, 2022Updated 2yr ago
Risk Assessment

The "slider-video" plugin v1.5.3 exhibits a generally good security posture with strong adherence to best practices. The plugin demonstrates a high rate of proper output escaping and exclusively uses prepared statements for SQL queries, which significantly mitigates common web vulnerabilities. Furthermore, all identified entry points, including AJAX handlers and shortcodes, appear to have authentication and capability checks, and there are no unsanitized paths found in the taint analysis. This suggests a proactive approach to securing user inputs.

However, the presence of the `unserialize` function is a notable concern. While the static analysis did not reveal any direct unsanitized flows related to it, `unserialize` is inherently risky if not handled with extreme caution, as it can lead to object injection vulnerabilities. The plugin's vulnerability history, which includes one medium-severity Cross-Site Scripting (XSS) vulnerability patched in 2022, indicates that while vulnerabilities have been addressed, past issues with input sanitization for output should be monitored. The plugin's strengths lie in its robust handling of SQL and output, but the `unserialize` function and past XSS issues warrant careful consideration.

In conclusion, "slider-video" v1.5.3 has a solid foundation in security, particularly in preventing SQL injection and XSS through prepared statements and proper escaping. The absence of unpatched vulnerabilities and critical taint flows is commendable. The primary area for improvement and vigilance revolves around the `unserialize` function, ensuring it is never exposed to user-controlled input without rigorous validation and sanitization.

Key Concerns

  • Use of unserialize()
  • Past medium severity XSS vulnerability
Vulnerabilities
1 published

Video Slider – Slider Carousel Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-1541medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Video Slider WordPress <= 1.4.6 - Authenticated (Admin+) Cross-Site Scripting

May 16, 2022 Patched in 1.4.8 (617d)
Version History

Video Slider – Slider Carousel Release Timeline

v1.5.4
v1.5.3Current
v1.5.2
v1.5.1
v1.5.0
v1.4.9
v1.4.8
v1.4.71 CVE
v1.4.61 CVE
v1.4.51 CVE
v1.4.41 CVE
v1.4.31 CVE
v1.4.21 CVE
v1.4.11 CVE
v1.4.01 CVE
v1.3.91 CVE
v1.3.81 CVE
v1.3.71 CVE
v1.3.61 CVE
v1.3.51 CVE
Code Analysis
Analyzed Mar 16, 2026

Video Slider – Slider Carousel Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
497 prepared
Unescaped Output
82
12201 escaped
Nonce Checks
12
Capability Checks
4
File Operations
15
External Requests
1
Bundled Libraries
1

Dangerous Functions Found

unserialize$Rich_Web_VSlider_Image_Real=unserialize(wp_remote_get( "http://vimeo.com/api/v2/video/$Rich_Web_VSlRich-Web-Video-Slider-Ajax.php:101

Bundled Libraries

TinyMCE1.0

SQL Query Safety

100% prepared497 total queries

Output Escaping

99% escaped12283 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

11 flows
Rich_Web_VSlider_Del_Callback (Rich-Web-Video-Slider-Ajax.php:19)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Video Slider – Slider Carousel Attack Surface

Entry Points12
Unprotected0

AJAX Handlers 11

authwp_ajax_Rich_Web_VSlider_DelRich-Web-Video-Slider-Ajax.php:5
authwp_ajax_Rich_Web_VSlider_CopyRich-Web-Video-Slider-Ajax.php:6
authwp_ajax_Rich_Web_VSlider_Edit_MainRich-Web-Video-Slider-Ajax.php:7
authwp_ajax_Rich_Web_VSlider_Edit_VideosRich-Web-Video-Slider-Ajax.php:8
authwp_ajax_Rich_Web_VSlider_VimeoRich-Web-Video-Slider-Ajax.php:9
authwp_ajax_rich_web_VS_Del_OptionRich-Web-Video-Slider-Ajax.php:10
authwp_ajax_rich_web_VS_Edit_OptionRich-Web-Video-Slider-Ajax.php:11
authwp_ajax_rich_web_VS_Copy_OptionRich-Web-Video-Slider-Ajax.php:12
authwp_ajax_Rich_Web_VS_Insert_OptionRich-Web-Video-Slider-Ajax.php:13
authwp_ajax_Rich_Web_VS_Name_AvailableRich-Web-Video-Slider-Ajax.php:14
authwp_ajax_Rich_Web_VSlider_SaveRich-Web-Video-Slider-Ajax.php:15

Shortcodes 1

[Rich_Web_Video] Rich-Web-Video-Slider-Shortcode.php:11
WordPress Hooks 7
filterupload_size_limitRich-Web-Video-Slider-Admin.php:9
actionadmin_initRich-Web-Video-Slider-Ajax.php:2
actionwidgets_initSlider-Video.php:14
actionwp_enqueue_scriptsSlider-Video.php:22
actionadmin_menuSlider-Video.php:34
actionadmin_initSlider-Video.php:79
actionadmin_enqueue_scriptsSlider-Video.php:109
Maintenance & Trust

Video Slider – Slider Carousel Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedSep 23, 2023
PHP min version
Downloads211K

Community Trust

Rating94/100
Number of ratings71
Active installs4K
Developer Profile

Video Slider – Slider Carousel Developer Profile

richteam

7 plugins · 9K total installs

64
trust score
Avg Security Score
79/100
Avg Patch Time
549 days
View full developer profile
Detection Fingerprints

How We Detect Video Slider – Slider Carousel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Video Slider – Slider Carousel