
Sneakers Security & Risk Analysis
wordpress.org/plugins/sneakersEasily add visually appealing Collapsible Panels facing any direction on the screen, without jQuery. Supports Shortcode, Custom Colors and 12 differen …
Is Sneakers Safe to Use in 2026?
Generally Safe
Score 85/100Sneakers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sneakers" v1.1 plugin presents a mixed security posture. On the positive side, it demonstrates good practices in SQL query handling, exclusively using prepared statements, and has no recorded vulnerability history, suggesting a generally secure development approach. The absence of file operations, external HTTP requests, and critical taint flows further bolsters its security.
However, significant concerns arise from the plugin's attack surface. It exposes two AJAX handlers, both of which lack authentication checks. This is a critical oversight, as it allows any unauthenticated user to trigger these actions. Additionally, the presence of a dangerous `unserialize` function, while not immediately exploitable without a specific entry point, introduces a potential risk if an attacker can control the serialized data passed to it. The low percentage of properly escaped output (7%) is another notable weakness, increasing the likelihood of cross-site scripting (XSS) vulnerabilities.
While the plugin has no known CVEs, the identified code-level risks, particularly the unprotected AJAX endpoints and the `unserialize` function, warrant careful attention. The lack of authentication on entry points is a fundamental security flaw that overshadows the otherwise positive aspects. A balanced view acknowledges the good SQL handling and lack of past vulnerabilities but highlights the immediate and significant risks posed by the unprotected AJAX handlers and the potential for XSS due to poor output escaping.
Key Concerns
- AJAX handlers without authentication checks
- Low percentage of properly escaped output
- Dangerous function (unserialize) present
Sneakers Security Vulnerabilities
Sneakers Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Sneakers Attack Surface
AJAX Handlers 2
WordPress Hooks 26
Maintenance & Trust
Sneakers Maintenance & Trust
Maintenance Signals
Community Trust
Sneakers Alternatives
WP Featured Content and Slider
wp-featured-content-and-slider
A quick, easy way to add and display what features your company, product or service offers, using our shortcode OR template code or Gutenberg block.
HTML5 Slideshow Presentations
html5-slideshow-presentations
Create HTML5 slideshow presentations using our favorite cms, WordPress. Host your own presentations and share/present them anytime.
WP Content Slideshow
wp-content-slideshow
WP Content Slideshow is the perfect Slideshow for Wordpress. It displays up to 5 Posts or Pages with Tile, Description and Image for every Post.
Animate Slider
animate-slider
Animated Slideshow boost your theme through shortcode with a beautiful CSS3 animated image and content slideshow.
Featured Item Slider
featured-item-slider
Featured item slider is the perfect Slideshow for Wordpress. It displays up to 5 Posts or Pages with Title,Description and Image for every Post.
Sneakers Developer Profile
4 plugins · 2K total installs
How We Detect Sneakers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sneakers/css/sneakers.css/wp-content/plugins/sneakers/js/html5.js/wp-content/plugins/sneakers/js/sneaker.js/wp-content/plugins/sneakers/js/html5.js/wp-content/plugins/sneakers/js/sneaker.jsHTML / DOM Fingerprints
collapsible-containersneakers-stlyecollapsible-panelsneak<!--[if lt IE 9]><script src="js/html5.js" type="text/javascript"></script><![endif]-->+10 morename="collapsible-id="collapsible-for="collapsible-class="collapsible-container test class="collapsible-panel sneak"SNEAKERS_DIRSNEAKERS_URLSNEAKERS_BASENAMESNEAKERS_VERSION