
Superb slideshow gallery Security & Risk Analysis
wordpress.org/plugins/superb-slideshow-galleryThis is a strong, cross browser fade in slideshow script that incorporates some of your most requested features all rolled into one.
Is Superb slideshow gallery Safe to Use in 2026?
Mostly Safe
Score 84/100Superb slideshow gallery is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The superb-slideshow-gallery plugin v13.2 exhibits a mixed security posture. On the positive side, it has a very small attack surface, with only one shortcode identified and no AJAX handlers, REST API routes, or cron events. It also shows good practices in its handling of SQL queries, with 96% utilizing prepared statements and a healthy number of nonce checks. However, a significant concern is the low rate of proper output escaping, with only 47% of outputs being escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed on the frontend.
The plugin has a history of one high-severity vulnerability related to SQL injection, with the last reported incident in October 2023. While currently unpatched CVEs are zero, the presence of a past SQL injection vulnerability, even if addressed, warrants attention. The static analysis did not reveal any critical or high-severity taint flows, which is a positive sign, and there were no observed unsanitized paths. The absence of dangerous functions and file operations is also reassuring.
In conclusion, while the plugin demonstrates strengths in limiting its attack surface and securing its database interactions, the insufficient output escaping and past SQL injection vulnerability are notable weaknesses. Developers should prioritize addressing the output escaping issues to mitigate XSS risks. The history of an SQL injection vulnerability suggests a need for continued vigilance and thorough code reviews for any future updates.
Key Concerns
- Low percentage of properly escaped output
- History of high severity SQL injection vulnerability
Superb slideshow gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Superb slideshow gallery <= 13.1 - Authenticated (Subscriber+) SQL Injection via Shortcode
Superb slideshow gallery Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Superb slideshow gallery Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Superb slideshow gallery Maintenance & Trust
Maintenance Signals
Community Trust
Superb slideshow gallery Alternatives
Easy image slideshow
easy-image-slideshow
This is a lightweight JavaScript slideshow with manual navigation option. You can use this slideshow, if you need the manual navigation image gallery.
Card flip image slideshow
card-flip-image-slideshow
This Card flip image slideshow script utilizes CSS3 transform to rotate images with unhinge animation.
FP Responsive Slider
fp-responsive-slider
This plugin will display image as slideshow with several effects. You can manage the options from FP Resposive Slider's Settings page or from wid …
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Smart Slider 3
smart-slider-3
Responsive slider plugin to create sliders in visual editor easily. Build beautiful image slider, layer slider, video slider, post slider, and more.
Superb slideshow gallery Developer Profile
52 plugins · 19K total installs
How We Detect Superb slideshow gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/superb-slideshow-gallery/js/show.js/wp-content/plugins/superb-slideshow-gallery/js/show.jssuperb-slideshow-gallery/js/show.js?ver=HTML / DOM Fingerprints
id="fadeshow1"id="widget"SuperbSlideshowGallery[ssg-superb-slideshow]new SuperbSlideshowGallery ({wrapperid: "fadeshow1"wrapperid: "widget"