TC flexslider Security & Risk Analysis

wordpress.org/plugins/tc-flexslider

TC flexslider is an easy plugin to display Responsive Slider on your website.

10 active installs v1.0.0 PHP + WP 3.0.1+ Updated Apr 9, 2016
flexsliderslider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TC flexslider Safe to Use in 2026?

Generally Safe

Score 85/100

TC flexslider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The tc-flexslider plugin version 1.0.0 exhibits a seemingly strong security posture based on the provided static analysis. There are no detected dangerous functions, no direct SQL queries without prepared statements, no file operations, and no external HTTP requests. Furthermore, there's no recorded vulnerability history, which suggests a clean past. However, a significant concern arises from the output escaping. With 100% of the identified outputs not properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities if any user-controllable data is outputted directly into the frontend without sanitization. This is a critical oversight that undermines the plugin's otherwise good practices.

The plugin's attack surface is limited to two shortcodes, and importantly, none of these entry points are identified as unprotected. This, combined with the absence of critical or high-severity taint flows, suggests that within the analyzed scope, the direct pathways for attackers are well-guarded. The lack of known CVEs and unpatched vulnerabilities is a positive indicator of the developer's diligence or the plugin's current obscurity. Despite these strengths, the unescaped output remains a glaring weakness that could be exploited to inject malicious scripts into user-facing pages.

Key Concerns

  • Unescaped output
Vulnerabilities
None known

TC flexslider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TC flexslider Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

TC flexslider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

TC flexslider Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[tc-flexslider] public\tc-flexslider-view-old.php:59
[tc-flexslider] public\tc-flexslider-view.php:62
WordPress Hooks 4
actionwp_footerpublic\tc-flexslider-view-old.php:20
actionwp_footerpublic\tc-flexslider-view.php:20
actionwp_enqueue_scriptstc-flexslider.php:28
actionadmin_menutc-flexslider.php:38
Maintenance & Trust

TC flexslider Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedApr 9, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

TC flexslider Developer Profile

Imran Emu

7 plugins · 3K total installs

81
trust score
Avg Security Score
81/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TC flexslider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tc-flexslider/assets/css/tc-flexslider.css/wp-content/plugins/tc-flexslider/vendors/flexslider/flexslider.css/wp-content/plugins/tc-flexslider/vendors/flexslider/jquery.flexslider.js
Script Paths
tc-flexslider/vendors/flexslider/jquery.flexslider.js

HTML / DOM Fingerprints

CSS Classes
tc-flexsliderflex-caption
JS Globals
jQuery
Shortcode Output
<div class="flexslider"><ul class="slides">
FAQ

Frequently Asked Questions about TC flexslider