Super block slider – Image & content slider Security & Risk Analysis

wordpress.org/plugins/super-block-slider

Lightweight image & content slider for block and classic editor.

9K active installs v2.8.3.3 PHP 7.0.0+ WP 6.3+ Updated Dec 4, 2025
blockcontent-sliderimage-slidersliderslider-block
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 24, 2025
Safety Verdict

Is Super block slider – Image & content slider Safe to Use in 2026?

Generally Safe

Score 99/100

Super block slider – Image & content slider has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jan 24, 2025Updated 5mo ago
Risk Assessment

The static analysis of the 'super-block-slider' plugin version 2.8.3.3 indicates a generally good security posture concerning core development practices. The absence of dangerous functions, all SQL queries utilizing prepared statements, and 100% proper output escaping are commendable. Furthermore, the lack of file operations and external HTTP requests minimizes certain attack vectors.

However, several areas raise concerns. The plugin has a known medium severity vulnerability in its history, although it is currently patched. Crucially, the static analysis reveals a complete lack of nonce checks across all entry points. While the plugin has capability checks, the absence of nonce validation on its single shortcode entry point is a significant weakness that could allow for Cross-Site Request Forgery (CSRF) attacks if the shortcode's functionality is sensitive.

The vulnerability history, while showing a recently patched medium-severity issue, does highlight a past pattern of "Missing Authorization." This, combined with the current absence of nonce checks, suggests a recurring oversight in securing user-submitted data and actions. While the plugin demonstrates strengths in other areas, the lack of nonce validation on its entry points is a critical omission that warrants attention.

Key Concerns

  • Missing nonce checks on entry points
  • Past vulnerability: Missing Authorization
Vulnerabilities
1 published

Super block slider – Image & content slider Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-24682medium · 4.3Missing Authorization

Super Block Slider <= 2.7.9 - Missing Authorization

Jan 24, 2025 Patched in 2.8 (5d)
Version History

Super block slider – Image & content slider Release Timeline

v2.8.3.3Current
v2.8.3.2
v2.8.3
v2.8.2.4
v2.8.2.2
v2.8.2.1
v2.8.2
v2.8.1
v2.8
v2.7.91 CVE
v2.7.71 CVE
v2.7.61 CVE
v2.7.51 CVE
v2.7.31 CVE
v2.7.11 CVE
v2.71 CVE
v2.6.31 CVE
v2.6.21 CVE
v2.6.11 CVE
v2.61 CVE
Code Analysis
Analyzed Mar 16, 2026

Super block slider – Image & content slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Super block slider – Image & content slider Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[superblockslider] includes\superblockslider_post_type.php:87
WordPress Hooks 6
actioninitincludes\superblockslider_post_type.php:55
actionwp_enqueue_scriptsincludes\superblockslider_post_type.php:101
actionadmin_noticesincludes\superblockslider_post_type.php:123
actioninitsuper-block-slider.php:92
filtermanage_superblockslider_posts_columnssuper-block-slider.php:97
actionmanage_superblockslider_posts_custom_columnsuper-block-slider.php:107
Maintenance & Trust

Super block slider – Image & content slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version7.0.0
Downloads105K

Community Trust

Rating100/100
Number of ratings14
Active installs9K
Developer Profile

Super block slider – Image & content slider Developer Profile

Michael

1 plugin · 9K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Super block slider – Image & content slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/super-block-slider/build/index.asset.php/wp-content/plugins/super-block-slider/build/index.js/wp-content/plugins/super-block-slider/build/superblockslider.js/wp-content/plugins/super-block-slider/build/index.css/wp-content/plugins/super-block-slider/build/style-index.css
Script Paths
/wp-content/plugins/super-block-slider/build/index.js/wp-content/plugins/super-block-slider/build/superblockslider.js
Version Parameters
/wp-content/plugins/super-block-slider/build/index.js?ver=/wp-content/plugins/super-block-slider/build/superblockslider.js?ver=/wp-content/plugins/super-block-slider/build/index.css?ver=/wp-content/plugins/super-block-slider/build/style-index.css?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/superblockslider/
Shortcode Output
[superblockslider id="
FAQ

Frequently Asked Questions about Super block slider – Image & content slider