
Carousel, Recent Post Slider and Banner Slider Security & Risk Analysis
wordpress.org/plugins/spice-post-sliderDisplay your blog posts with a responsive, customizable slider that works smoothly on all devices.
Is Carousel, Recent Post Slider and Banner Slider Safe to Use in 2026?
Generally Safe
Score 100/100Carousel, Recent Post Slider and Banner Slider has a strong security track record. Known vulnerabilities have been patched promptly.
The spice-post-slider plugin version 2.2.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, implementing nonce checks, and performing capability checks for its single entry point (a shortcode). Furthermore, the absence of critical or high severity taint flows, along with no unpatched CVEs, suggests a generally well-maintained codebase.
However, a significant concern lies in the output escaping. With 67% of outputs properly escaped, it implies that approximately one-third of the 621 identified outputs are not sufficiently sanitized. This leaves a considerable surface area vulnerable to Cross-Site Scripting (XSS) attacks, especially given the plugin's history of a medium severity XSS vulnerability. The external HTTP request, while not inherently a vulnerability, should be monitored for potential exploitation if the target endpoint is compromised or if the request itself is formed using user-supplied data without proper sanitization.
In conclusion, while the plugin avoids some common critical vulnerabilities like raw SQL or significant taint flows, the substantial portion of unescaped output presents a tangible risk. The past XSS vulnerability reinforces this concern. Developers should prioritize improving output sanitization to mitigate the risk of XSS attacks.
Key Concerns
- Significant percentage of unescaped output
- Medium severity XSS vulnerability in history
- External HTTP request
Carousel, Recent Post Slider and Banner Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Carousel, Recent Post Slider and Banner Slider <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Carousel, Recent Post Slider and Banner Slider Code Analysis
Bundled Libraries
Output Escaping
Carousel, Recent Post Slider and Banner Slider Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Carousel, Recent Post Slider and Banner Slider Maintenance & Trust
Maintenance Signals
Community Trust
Carousel, Recent Post Slider and Banner Slider Alternatives
Banner Introduction Slider
banner-introduction-slider
A quick, easy way to add an Responsive header Banner Introduction Slider OR Responsive Banner Introduction Slider inside wordpress page OR Template.
Wave Slider
wave-slider
Simple Creative responsive Slider, Get in motion !!!!
Smart Slider 3
smart-slider-3
Responsive slider plugin to create sliders in visual editor easily. Build beautiful image slider, layer slider, video slider, post slider, and more.
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider
ml-slider
Slider, gallery, carousel plugin for WordPress. Build your image slider, video slider, post slider, YouTube slider, or WooCommerce product slider.
Prime Slider – Addons for Elementor
bdthemes-prime-slider-lite
Create responsive sliders using Elementor for hero sections, posts, logos, images, products, testimonials, and more.
Carousel, Recent Post Slider and Banner Slider Developer Profile
34 plugins · 63K total installs
How We Detect Carousel, Recent Post Slider and Banner Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/spice-post-slider/css/slick.css/wp-content/plugins/spice-post-slider/css/slick-theme.css/wp-content/plugins/spice-post-slider/css/spice-post-slider.css/wp-content/plugins/spice-post-slider/js/slick.js/wp-content/plugins/spice-post-slider/js/spice-post-slider.js/wp-content/plugins/spice-post-slider/include/admin/js/spice-post-slider-admin.js/wp-content/plugins/spice-post-slider/js/slick.js/wp-content/plugins/spice-post-slider/js/spice-post-slider.js/wp-content/plugins/spice-post-slider/include/admin/js/spice-post-slider-admin.jsspice-post-slider/css/slick.css?ver=spice-post-slider/css/slick-theme.css?ver=spice-post-slider/css/spice-post-slider.css?ver=spice-post-slider/js/slick.js?ver=spice-post-slider/js/spice-post-slider.js?ver=spice-post-slider/include/admin/js/spice-post-slider-admin.js?ver=HTML / DOM Fingerprints
spice-post-slider-wrappersps-slick-slidespice-post-slider-containersps-about-contentsps-about-sectionsps-plugin-wrap<!-- Main Spice_Post_Slider Class --><!-- Constructor function --><!-- Load the localisation file --><!-- Register Post Type -->+78 moredata-post-slider-iddata-slides-to-showdata-slides-to-scrolldata-infinitedata-dotsdata-arrows+20 moresps_slider_optionsjQuery[spice_post_sliderspice_post_slider_display