
Tylr Slidr Security & Risk Analysis
wordpress.org/plugins/tylr-slidrThe Easiest Way to Pull Your Flickr Photos into Wordpress.
Is Tylr Slidr Safe to Use in 2026?
Generally Safe
Score 85/100Tylr Slidr has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'tylr-slidr' plugin version 1.6 exhibits a generally positive security posture based on the provided static analysis. The absence of known vulnerabilities and CVEs, combined with the presence of nonce and capability checks, suggests a development team that is mindful of security best practices. The plugin also demonstrates good data handling by exclusively using prepared statements for its SQL queries, mitigating the risk of SQL injection.
However, a significant concern arises from the complete lack of output escaping. With 21 total output points and 0% properly escaped, this presents a high risk for Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the front-end or admin area without proper sanitization can be exploited by attackers to inject malicious scripts. While the attack surface is small and there are no reported vulnerabilities, this lack of output escaping is a critical oversight that could be easily exploited.
In conclusion, the plugin has strengths in its lack of known vulnerabilities and secure SQL practices. Nevertheless, the pervasive issue of unescaped output significantly undermines its overall security, making it susceptible to XSS attacks. Addressing the output escaping is paramount to improving its security. The bundled TinyMCE library is a common component and not inherently a security risk unless outdated versions are present, which is not indicated here.
Key Concerns
- 0% output properly escaped
Tylr Slidr Security Vulnerabilities
Tylr Slidr Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Tylr Slidr Attack Surface
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Tylr Slidr Maintenance & Trust
Maintenance Signals
Community Trust
Tylr Slidr Alternatives
Meks Simple Flickr Widget
meks-simple-flickr-widget
Quickly display your Flickr photos inside WordPress widget.
Embed Google Photos album
embed-google-photos-album-easily
Embed Google Photos album using Player widget.
TZ Flickr Widget
tz-flickr-widget
Plugin has get your Flickr photostream in a sidebar easily without authentication.
Quick Flickr Widget
quick-flickr-widget
Display your Flickr photos in your sidebar.
GPP Slideshow
gpp-slideshow
A minimalist slideshow plugin that creates a new gallery post type. Add slideshows to widgets, posts, pages and gallery posts.
Tylr Slidr Developer Profile
2 plugins · 20 total installs
How We Detect Tylr Slidr
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tylr-slidr/resources/swfobject.v.2.2.js/wp-content/plugins/tylr-slidr/resources/jquery-ui/ui.core.js/wp-content/plugins/tylr-slidr/resources/jquery-ui/ui.draggable.js/wp-content/plugins/tylr-slidr/resources/jquery-ui/ui.resizable.js/wp-content/plugins/tylr-slidr/resources/jquery-ui/ui.dialog.js/wp-content/plugins/tylr-slidr/resources/jquery-ui/ts-jquery-ui.cssplugins/tylr-slidr/resources/swfobject.v.2.2.jsplugins/tylr-slidr/resources/jquery-ui/ui.core.jsplugins/tylr-slidr/resources/jquery-ui/ui.draggable.jsplugins/tylr-slidr/resources/jquery-ui/ui.resizable.jsplugins/tylr-slidr/resources/jquery-ui/ui.dialog.jstylr-slidr/resources/swfobject.v.2.2.js?ver=tylr-slidr/resources/jquery-ui/ui.core.js?ver=tylr-slidr/resources/jquery-ui/ui.resizable.js?ver=tylr-slidr/resources/jquery-ui/ui.dialog.js?ver=tylr-slidr/resources/jquery-ui/ts-jquery-ui.css?ver=HTML / DOM Fingerprints
ts-jquery-ui/*
**************************************************************************
Plugin Name: Tylr Slidr
Plugin URI: http://tylrslidr.com
Description: The Easiest Way to Pull Your Flickr Photos into Wordpress.
Version: 1.6
Author: Tyler Craft
Author URI: http://www.tylercraft.com/
**************************************************************************
Copyright (C) 2008 tylercraft.com
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
**************************************************************************/swfobject[tylr-slidr]