[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0JAX-O_C2f-uG6fSTGv34WMMx3VDEqld_NiHhAGv6fc":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":18,"download_link":23,"security_score":24,"vuln_count":25,"unpatched_count":25,"last_vuln_date":26,"fetched_at":27,"vulnerabilities":28,"developer":29,"crawl_stats":26,"alternatives":36,"analysis":56,"fingerprints":176},"smooth-slideshow","Smooth Slideshow","1.5.2","faaiq","https:\u002F\u002Fprofiles.wordpress.org\u002Ffaaiq\u002F","\u003Cp>This is a fade slideshow with movable text. after installing this plugin a new content type named slides will be created. you can see on left menu. Add title,content and upload image of your slideshow. This plugin does resize image so please upload image of exact size of your slide show. this slideshow provide face effect on image and text move from right to left;\u003C\u002Fp>\n","Fade Slideshow Show with movable text",10,6885,100,1,"2013-03-11T12:38:00.000Z","3.5.2","3.5","",[20,21,22,4],"fade-slideshow","jquery-slideshow","slideshow-javascript-slideshow","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsmooth-slideshow.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":30,"total_installs":31,"avg_security_score":32,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},6,630,89,498,71,"2026-04-04T18:25:38.964Z",[37],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":11,"downloaded":45,"rating":13,"num_ratings":14,"last_updated":46,"tested_up_to":47,"requires_at_least":48,"requires_php":18,"tags":49,"homepage":54,"download_link":55,"security_score":24,"vuln_count":25,"unpatched_count":25,"last_vuln_date":26,"fetched_at":27},"versatile-jquery-slider","Versitile jQuery Slider","1.1.3","elevaunt","https:\u002F\u002Fprofiles.wordpress.org\u002Felevaunt\u002F","\u003Cp>The Versatile jQuery Slider helps you set up an easy, versatile, responsive slider with images or any HTML content.  Powered by \u003Ca href=\"http:\u002F\u002Fjquery.malsup.com\u002Fcycle2\" rel=\"nofollow ugc\">jQuery Cycle2\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>I’ve often looked for a good plugin that would allow me to quickly and easily add the jQuery Cycle2 plugin to a site, but I couldn’t find any good ones… so I built this.  Basically, the Versatile jQuery Slider (VJS Slider) is a wrapper that pulls in most of the available options into a shortcode for easy use. So you’ll want to check out the \u003Ca href=\"http:\u002F\u002Fjquery.malsup.com\u002Fcycle2\u002Fapi\" rel=\"nofollow ugc\">jQuery Cycle2 options\u003C\u002Fa> to know what is available.\u003C\u002Fp>\n\u003Cp>The nice part is, the jQuery Cycle2 scripts are only loaded on the pages that they are used on, and only the necessary scripts are loaded.  So if you need the carousel plugin, it will automatically be added in if the \u003Ccode>fx\u003C\u002Fcode> attribute is set \u003Ccode>carousel\u003C\u002Fcode>.  You need to center vertically?  Set the \u003Ccode>center-vert\u003C\u002Fcode> attribute to \u003Ccode>true\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>Easy as that!\u003C\u002Fp>\n\u003Ch4>Demos\u003C\u002Fh4>\n\u003Cp>Check out the \u003Ca href=\"http:\u002F\u002Felevaunt.com\u002Fplugins\u002Fversatile-jquery-slider\u002Fdemos\" rel=\"nofollow ugc\">demos page\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Parameters\u003C\u002Fh4>\n\u003Cp>VJS Slider has some unique paramaters that jQuery Cycle2 doesn’t have.  Also there are a some changes to a few of the jQuery Cycle2 parameters.  \u003Ca href=\"http:\u002F\u002Felevaunt.com\u002Fplugins\u002Fversatile-jquery-slider\" rel=\"nofollow ugc\">Check them out\u003C\u002Fa>.\u003C\u002Fp>\n","Set up an easy, versatile, responsive slider with images or any HTML content.  Powered by jQuery Cycle2.",1548,"2017-02-10T06:01:00.000Z","4.5.33","3.0.1",[50,21,51,52,53],"jquery-slider","responsive-slider","slider","slideshow","http:\u002F\u002Fwww.elevaunt.com\u002Fplugins\u002Fversatile-jquery-slider","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fversatile-jquery-slider.1.1.3.zip",{"attackSurface":57,"codeSignals":89,"taintFlows":120,"riskAssessment":159,"analyzedAt":175},{"hooks":58,"ajaxHandlers":85,"restRoutes":86,"shortcodes":87,"cronEvents":88,"entryPointCount":25,"unprotectedCount":25},[59,64,67,71,74,78,82],{"type":60,"name":61,"callback":61,"file":62,"line":63},"action","init","wp-slideshow.php",17,{"type":60,"name":65,"callback":65,"file":62,"line":66},"post_edit_form_tag",18,{"type":60,"name":68,"callback":69,"file":62,"line":70},"add_meta_boxes","meta_box",19,{"type":60,"name":72,"callback":72,"priority":14,"file":62,"line":73},"save_post",20,{"type":60,"name":75,"callback":76,"file":62,"line":77},"admin_menu","adminmenu",21,{"type":60,"name":79,"callback":80,"file":62,"line":81},"wp_head","head",22,{"type":60,"name":83,"callback":83,"file":62,"line":84},"admin_head",23,[],[],[],[],{"dangerousFunctions":90,"sqlUsage":91,"outputEscaping":96,"fileOperations":25,"externalRequests":25,"nonceChecks":25,"capabilityChecks":25,"bundledLibraries":119},[],{"prepared":25,"raw":14,"locations":92},[93],{"file":62,"line":94,"context":95},39,"$wpdb->get_results() with variable interpolation",{"escaped":25,"rawEcho":11,"locations":97},[98,101,103,105,107,109,111,113,115,117],{"file":62,"line":99,"context":100},40,"raw output",{"file":62,"line":102,"context":100},50,{"file":62,"line":104,"context":100},53,{"file":62,"line":106,"context":100},55,{"file":62,"line":108,"context":100},61,{"file":62,"line":110,"context":100},64,{"file":62,"line":112,"context":100},133,{"file":62,"line":114,"context":100},168,{"file":62,"line":116,"context":100},172,{"file":62,"line":118,"context":100},176,[],[121,147],{"entryPoint":122,"graph":123,"unsanitizedCount":30,"severity":146},"settings (wp-slideshow.php:141)",{"nodes":124,"edges":142},[125,130,136,138],{"id":126,"type":127,"label":128,"file":62,"line":129},"n0","source","$_POST (x3)",144,{"id":131,"type":132,"label":133,"file":62,"line":134,"wp_function":135},"n1","sink","update_option() [Settings Manipulation]",145,"update_option",{"id":137,"type":127,"label":128,"file":62,"line":129},"n2",{"id":139,"type":132,"label":140,"file":62,"line":114,"wp_function":141},"n3","echo() [XSS]","echo",[143,145],{"from":126,"to":131,"sanitized":144},false,{"from":137,"to":139,"sanitized":144},"medium",{"entryPoint":148,"graph":149,"unsanitizedCount":30,"severity":158},"\u003Cwp-slideshow> (wp-slideshow.php:0)",{"nodes":150,"edges":155},[151,152,153,154],{"id":126,"type":127,"label":128,"file":62,"line":129},{"id":131,"type":132,"label":133,"file":62,"line":134,"wp_function":135},{"id":137,"type":127,"label":128,"file":62,"line":129},{"id":139,"type":132,"label":140,"file":62,"line":114,"wp_function":141},[156,157],{"from":126,"to":131,"sanitized":144},{"from":137,"to":139,"sanitized":144},"low",{"summary":160,"deductions":161},"The \"smooth-slideshow\" plugin v1.5.2 exhibits a concerning security posture despite the absence of known vulnerabilities and a seemingly small attack surface. The static analysis reveals significant weaknesses in secure coding practices, particularly regarding SQL queries and output escaping.  All detected SQL queries are not using prepared statements, posing a direct risk of SQL injection if user-supplied data is incorporated. Furthermore, a substantial portion of output is not properly escaped, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, especially if user input influences displayed content. The taint analysis shows flows with unsanitized paths, reinforcing the concern for data manipulation vulnerabilities.  While the plugin has no reported CVEs, this absence is not a guarantee of security, especially given the fundamental coding flaws identified.  The lack of capability checks and nonce checks on entry points (though there are none currently) suggests a potential for future vulnerabilities if new entry points are added without proper security considerations.  Overall, the plugin's strengths lie in its limited attack surface and lack of known exploits, but its weaknesses in secure data handling and output sanitization present a significant risk that requires immediate attention.",[162,164,167,170,173],{"reason":163,"points":11},"SQL queries not using prepared statements",{"reason":165,"points":166},"No output properly escaped",8,{"reason":168,"points":169},"Flows with unsanitized paths",15,{"reason":171,"points":172},"No nonce checks found",5,{"reason":174,"points":172},"No capability checks found","2026-03-17T01:16:04.623Z",{"wat":177,"direct":184},{"assetPaths":178,"generatorPatterns":181,"scriptPaths":182,"versionParams":183},[179,180],"\u002Fwp-content\u002Fplugins\u002Fsmooth-slideshow\u002Fslide.js","\u002Fwp-content\u002Fplugins\u002Fsmooth-slideshow\u002Fstyle.css",[],[179],[],{"cssClasses":185,"htmlComments":189,"htmlAttributes":190,"restEndpoints":194,"jsGlobals":195,"shortcodeOutput":197},[186,187,188],"slideshowcontainer","slideshow_data","text_data",[],[191,192,193],"id=\"slideshowcontainer\"","id=\"text_","id=\"slide_",[],[196],"var total_slide",[]]