
Slidy Security & Risk Analysis
wordpress.org/plugins/slidySlidy is a responsive jQuery slider that uses slick carousel. Insert it directly into a template or with its shortcode into pages, posts & widgets …
Is Slidy Safe to Use in 2026?
Generally Safe
Score 100/100Slidy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'slidy' plugin version 0.0.3 exhibits a generally positive security posture based on the static analysis. It demonstrates good practices by exclusively using prepared statements for SQL queries, performing capability checks, and including nonce checks. The attack surface is minimal with only one entry point (a shortcode) and no unprotected AJAX handlers or REST API routes. There are no identified dangerous functions, file operations, or external HTTP requests, further reducing potential risks.
However, a significant concern lies in the output escaping. Only 11% of the nine total outputs are properly escaped, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. This is a critical oversight that could allow attackers to inject malicious scripts into the site. The absence of any identified taint flows or historical vulnerabilities is a strength, suggesting the plugin has not been a target or has been developed with a focus on avoiding common exploit vectors. Despite the good foundational security practices, the poor output escaping creates a substantial risk that needs immediate attention.
In conclusion, while 'slidy' v0.0.3 benefits from a small attack surface and strong data sanitization for SQL, the critical lack of proper output escaping poses a significant XSS risk. The plugin's vulnerability history is clean, which is positive, but it does not mitigate the immediate dangers presented by the unescaped output. Addressing the output escaping issues should be the top priority to improve the plugin's security.
Key Concerns
- Poor output escaping (XSS risk)
Slidy Security Vulnerabilities
Slidy Code Analysis
Output Escaping
Slidy Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Slidy Maintenance & Trust
Maintenance Signals
Community Trust
Slidy Alternatives
Tishfy Slider
tishfy-slider
Configure a Responsive Slick jQuery Carousel Slider and Insert it in any Page or Post as a Shortcode.
WP Slick Slider and Image Carousel
wp-slick-slider-and-image-carousel
A quick, easy way to add and display multiple WP Slick Slider and carousel using a shortcode. Also added Gutenberg block support.
MaxGalleria
maxgalleria
Responsive WordPress Gallery plugin with built in Slider and Lightbox
Free WooCommerce Products Slider/Carousel Pro
woo-products-slider-pro
Display WooCommerce Products in a Carousel / Slider. Show Top Rated, Best Selling, ON Sale, Featured, Recently Viewed Products With Category Filter.
Carousel 3D Slider
carousel-3d-slider
Configure a Responsive 3D jQuery Carousel Slider and Insert it in any Page or Post as a Shortcode.
Slidy Developer Profile
1 plugin · 10 total installs
How We Detect Slidy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/slidy/slick/slick.css/wp-content/plugins/slidy/css/main.css/wp-content/plugins/slidy/js/main.js/wp-content/plugins/slidy/slick/slick.min.js/wp-content/plugins/slidy/js/main.js/wp-content/plugins/slidy/slick/slick.min.jsHTML / DOM Fingerprints
slidy_slide_url