
T&P Gallery Slider Security & Risk Analysis
wordpress.org/plugins/tp-gallery-sliderT&P Gallery Slider for WordPress is an image hover/click gallery as a WordPress plugin.
Is T&P Gallery Slider Safe to Use in 2026?
Use With Caution
Score 61/100T&P Gallery Slider has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The tp-gallery-slider plugin version 1.2 exhibits a mixed security posture. While it avoids dangerous functions, raw SQL, file operations, and external HTTP requests, significant concerns arise from its output handling and vulnerability history. The static analysis reveals that 100% of outputs are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. This is further supported by the plugin's vulnerability history, which shows one unpatched high-severity CVE specifically related to XSS. The presence of unsanitized paths in taint flows, although not classified as critical or high, adds to the potential for insecure data handling. The absence of nonce checks and capability checks on its single shortcode entry point is also a weakness. In conclusion, despite some good practices in preventing certain types of vulnerabilities, the critical issue of unescaped output and the historical pattern of XSS vulnerabilities represent a substantial risk that needs immediate attention.
Key Concerns
- Unpatched High Severity CVE
- 100% of outputs are not properly escaped
- No nonce checks on entry points
- No capability checks on entry points
- Taint flows with unsanitized paths
T&P Gallery Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
T&P Gallery Slider <= 1.2 - Unauthenticated Stored Cross-Site Scripting
T&P Gallery Slider Code Analysis
Output Escaping
Data Flow Analysis
T&P Gallery Slider Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
T&P Gallery Slider Maintenance & Trust
Maintenance Signals
Community Trust
T&P Gallery Slider Alternatives
jQuery googleslides
jquery-googleslides
Integrates the googleslides jQuery plugin to display your Google Photos, including Picasa and Google+ albums.
Cleaner Gallery
cleaner-gallery
A cleaner WordPress [gallery] that integrates with multiple Lightbox-type scripts.
Social Photo Fetcher
facebook-photo-fetcher
Allows you to automatically create Wordpress photo galleries from Facebook albums. Simple to use and highly customizable.
ThickBox
thickbox
Embed ThickBox into your posts and pages.
Easy Gallery Slider
easy-gallery-slider
Responsive slider uses the images attached to a post or page. Simple to customize and configure.
T&P Gallery Slider Developer Profile
2 plugins · 60 total installs
How We Detect T&P Gallery Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tp-gallery-slider/images/image_01_large.jpg/wp-content/plugins/tp-gallery-slider/images/image_01_thumb.jpg/wp-content/plugins/tp-gallery-slider/images/image_02_thumb.jpg/wp-content/plugins/tp-gallery-slider/images/image_03_thumb.jpg/wp-content/plugins/tp-gallery-slider/images/image_04_thumb.jpg/wp-content/plugins/tp-gallery-slider/images/image_05_thumb.jpg/wp-content/plugins/tp-gallery-slider/icons/cut.png/wp-content/plugins/tp-gallery-slider/icons/pic.pngHTML / DOM Fingerprints
tp_changetp_gallery_slidertp_previewtp_panel<!-- icon32 --><!-- description -->id="tp_width"id="tp_height"id="tp_thumbs"id="largeImage"id="description"id="tp_panel"+5 more[tp_gallery][tp_gallery post_id="id"]