Tylr Slidr Security & Risk Analysis

wordpress.org/plugins/tylr-slidr

The Easiest Way to Pull Your Flickr Photos into Wordpress.

10 active installs v1.6 PHP + WP 2.6+ Updated Jan 20, 2010
flickrflickrslidrphotosslideshow
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tylr Slidr Safe to Use in 2026?

Generally Safe

Score 85/100

Tylr Slidr has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The 'tylr-slidr' plugin version 1.6 exhibits a generally positive security posture based on the provided static analysis. The absence of known vulnerabilities and CVEs, combined with the presence of nonce and capability checks, suggests a development team that is mindful of security best practices. The plugin also demonstrates good data handling by exclusively using prepared statements for its SQL queries, mitigating the risk of SQL injection.

However, a significant concern arises from the complete lack of output escaping. With 21 total output points and 0% properly escaped, this presents a high risk for Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the front-end or admin area without proper sanitization can be exploited by attackers to inject malicious scripts. While the attack surface is small and there are no reported vulnerabilities, this lack of output escaping is a critical oversight that could be easily exploited.

In conclusion, the plugin has strengths in its lack of known vulnerabilities and secure SQL practices. Nevertheless, the pervasive issue of unescaped output significantly undermines its overall security, making it susceptible to XSS attacks. Addressing the output escaping is paramount to improving its security. The bundled TinyMCE library is a common component and not inherently a security risk unless outdated versions are present, which is not indicated here.

Key Concerns

  • 0% output properly escaped
Vulnerabilities
None known

Tylr Slidr Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tylr Slidr Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

0% escaped21 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
POSTHandler (tylr-slidr.php:331)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Tylr Slidr Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[tylr-slidr] tylr-slidr.php:122
WordPress Hooks 16
actionadmin_menutylr-slidr.php:98
filterplugin_action_linkstylr-slidr.php:99
actionadmin_post_tssettingstylr-slidr.php:101
actionwp_headtylr-slidr.php:102
actionadmin_headtylr-slidr.php:103
actionthe_contenttylr-slidr.php:104
filterwidget_texttylr-slidr.php:105
actionwidget_texttylr-slidr.php:106
filtertiny_mce_versiontylr-slidr.php:112
filtermce_external_pluginstylr-slidr.php:113
actionedit_form_advancedtylr-slidr.php:114
actionedit_page_formtylr-slidr.php:115
filtermce_buttonstylr-slidr.php:117
actionadmin_headtylr-slidr.php:132
actionadmin_footertylr-slidr.php:133
actionplugins_loadedtylr-slidr.php:802
Maintenance & Trust

Tylr Slidr Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedJan 20, 2010
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Tylr Slidr Developer Profile

tylerc083

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tylr Slidr

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tylr-slidr/resources/swfobject.v.2.2.js/wp-content/plugins/tylr-slidr/resources/jquery-ui/ui.core.js/wp-content/plugins/tylr-slidr/resources/jquery-ui/ui.draggable.js/wp-content/plugins/tylr-slidr/resources/jquery-ui/ui.resizable.js/wp-content/plugins/tylr-slidr/resources/jquery-ui/ui.dialog.js/wp-content/plugins/tylr-slidr/resources/jquery-ui/ts-jquery-ui.css
Script Paths
plugins/tylr-slidr/resources/swfobject.v.2.2.jsplugins/tylr-slidr/resources/jquery-ui/ui.core.jsplugins/tylr-slidr/resources/jquery-ui/ui.draggable.jsplugins/tylr-slidr/resources/jquery-ui/ui.resizable.jsplugins/tylr-slidr/resources/jquery-ui/ui.dialog.js
Version Parameters
tylr-slidr/resources/swfobject.v.2.2.js?ver=tylr-slidr/resources/jquery-ui/ui.core.js?ver=tylr-slidr/resources/jquery-ui/ui.resizable.js?ver=tylr-slidr/resources/jquery-ui/ui.dialog.js?ver=tylr-slidr/resources/jquery-ui/ts-jquery-ui.css?ver=

HTML / DOM Fingerprints

CSS Classes
ts-jquery-ui
HTML Comments
/* ************************************************************************** Plugin Name: Tylr Slidr Plugin URI: http://tylrslidr.com Description: The Easiest Way to Pull Your Flickr Photos into Wordpress. Version: 1.6 Author: Tyler Craft Author URI: http://www.tylercraft.com/ ************************************************************************** Copyright (C) 2008 tylercraft.com This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program. If not, see <http://www.gnu.org/licenses/>. **************************************************************************/
JS Globals
swfobject
Shortcode Output
[tylr-slidr]
FAQ

Frequently Asked Questions about Tylr Slidr