Slider Ultimate Security & Risk Analysis

wordpress.org/plugins/ultimate-slider

Add a responsive slider to any page with a block shortcode. Multiple slide effects. WooCommerce slider integration.

600 active installs v2.2.8 PHP + WP 4.0+ Updated Dec 2, 2025
carouselcarousel-sliderresponsive-sliderslideslider
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Slider Ultimate Safe to Use in 2026?

Generally Safe

Score 100/100

Slider Ultimate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'ultimate-slider' v2.2.8 plugin exhibits a mixed security posture. On the positive side, it demonstrates a strong commitment to secure coding practices by exclusively using prepared statements for SQL queries and not making external HTTP requests. The absence of known CVEs and a clean vulnerability history suggest diligent maintenance and a lack of past exploitable issues. However, concerns arise from the static analysis. A notable aspect is the presence of 11 AJAX handlers, with two of them lacking authentication checks, which presents a direct attack vector. Additionally, while taint analysis found no critical or high severity issues, a significant portion (54%) of output is not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs. The file operation, though singular, warrants attention if it involves user input. These factors, despite the strong SQL and external request practices, introduce tangible risks.

Key Concerns

  • AJAX handlers without authentication checks
  • High percentage of unescaped output
  • File operations present
Vulnerabilities
None known

Slider Ultimate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Slider Ultimate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
118
99 escaped
Nonce Checks
10
Capability Checks
4
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

46% escaped217 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
hide_review_ask (includes\ReviewAsk.class.php:87)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Slider Ultimate Attack Surface

Entry Points12
Unprotected2

AJAX Handlers 11

authwp_ajax_ewd_us_send_feature_suggestionincludes\AboutUs.class.php:14
authwp_ajax_ewd_us_get_post_idsincludes\CustomPostTypes.class.php:36
authwp_ajax_ewd_us_slides_update_orderincludes\CustomPostTypes.class.php:37
authwp_ajax_ewd_us_hide_upgrade_boxincludes\Dashboard.class.php:20
authwp_ajax_ewd_us_display_upgrade_boxincludes\Dashboard.class.php:21
authwp_ajax_us_welcome_add_slideincludes\InstallationWalkthrough.class.php:19
authwp_ajax_us_welcome_add_slider_pageincludes\InstallationWalkthrough.class.php:20
authwp_ajax_us_welcome_set_optionsincludes\InstallationWalkthrough.class.php:21
authwp_ajax_ewd_us_hide_review_askincludes\ReviewAsk.class.php:16
authwp_ajax_ewd_us_send_feedbackincludes\ReviewAsk.class.php:17
authwp_ajax_ewd_us_hide_helper_noticeultimate-slider.php:136

Shortcodes 1

[ultimate-slider] includes\template-functions.php:32
WordPress Hooks 41
actionadmin_menuincludes\AboutUs.class.php:16
actioninitincludes\Blocks.class.php:14
filterblock_categories_allincludes\Blocks.class.php:16
actionadmin_initincludes\CustomPostTypes.class.php:17
actioninitincludes\CustomPostTypes.class.php:18
actionadd_meta_boxesincludes\CustomPostTypes.class.php:21
actionsave_postincludes\CustomPostTypes.class.php:22
actionrestrict_manage_postsincludes\CustomPostTypes.class.php:25
filterparse_queryincludes\CustomPostTypes.class.php:26
filtermanage_ultimate_slider_posts_columnsincludes\CustomPostTypes.class.php:27
actionmanage_ultimate_slider_posts_custom_columnincludes\CustomPostTypes.class.php:28
filtermanage_edit-ultimate_slider_sortable_columnsincludes\CustomPostTypes.class.php:29
filterposts_clausesincludes\CustomPostTypes.class.php:30
filtermanage_edit-ultimate_slider_categories_columnsincludes\CustomPostTypes.class.php:31
filtermanage_edit-ultimate_slider_categories_columnsincludes\CustomPostTypes.class.php:32
filtermanage_ultimate_slider_categories_custom_columnincludes\CustomPostTypes.class.php:33
actionpre_get_postsincludes\CustomPostTypes.class.php:34
actionadmin_menuincludes\Dashboard.class.php:16
actionadmin_enqueue_scriptsincludes\Dashboard.class.php:18
actioncurrent_screenincludes\DeactivationSurvey.class.php:13
actionadmin_enqueue_scriptsincludes\DeactivationSurvey.class.php:18
actionadmin_footerincludes\DeactivationSurvey.class.php:19
actionadmin_menuincludes\InstallationWalkthrough.class.php:13
actionadmin_headincludes\InstallationWalkthrough.class.php:14
actionadmin_initincludes\InstallationWalkthrough.class.php:15
actionadmin_headincludes\InstallationWalkthrough.class.php:17
actionadmin_noticesincludes\ReviewAsk.class.php:14
actionadmin_enqueue_scriptsincludes\ReviewAsk.class.php:19
actioninitincludes\Settings.class.php:25
actioninitincludes\Settings.class.php:27
actionwidgets_initincludes\Widgets.class.php:7
filterwoocommerce_locate_templateincludes\WooCommerceIntegration.class.php:16
actioninitultimate-slider.php:122
actionplugins_loadedultimate-slider.php:124
actionadmin_noticesultimate-slider.php:126
actionadmin_noticesultimate-slider.php:127
actionadmin_enqueue_scriptsultimate-slider.php:129
actionwp_enqueue_scriptsultimate-slider.php:130
actionwp_headultimate-slider.php:131
actionwp_footerultimate-slider.php:132
filterplugin_action_linksultimate-slider.php:134
Maintenance & Trust

Slider Ultimate Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version
Downloads143K

Community Trust

Rating78/100
Number of ratings20
Active installs600
Developer Profile

Slider Ultimate Developer Profile

Rustaurius

21 plugins · 66K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
716 days
View full developer profile
Detection Fingerprints

How We Detect Slider Ultimate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-slider/assets/js/ewd-us-helper-install-notice.js/wp-content/plugins/ultimate-slider/assets/css/ewd-us-helper-install-notice.css/wp-content/plugins/ultimate-slider/assets/js/ewd-us-admin.js/wp-content/plugins/ultimate-slider/assets/css/ewd-us-admin.css/wp-content/plugins/ultimate-slider/assets/js/ewd-us.js/wp-content/plugins/ultimate-slider/assets/js/jquery.iframetracker.js/wp-content/plugins/ultimate-slider/assets/css/ewd-us.css/wp-content/plugins/ultimate-slider/assets/js/ultimate-lightbox.js+1 more
Version Parameters
ultimate-slider/assets/js/ewd-us-helper-install-notice.js?ver=ultimate-slider/assets/css/ewd-us-helper-install-notice.css?ver=ultimate-slider/assets/js/ewd-us-admin.js?ver=ultimate-slider/assets/css/ewd-us-admin.css?ver=ultimate-slider/assets/js/ewd-us.js?ver=ultimate-slider/assets/js/jquery.iframetracker.js?ver=ultimate-slider/assets/css/ewd-us.css?ver=ultimate-slider/assets/js/ultimate-lightbox.js?ver=ultimate-slider/assets/css/ewd-ulb-main.css?ver=

HTML / DOM Fingerprints

CSS Classes
ewd-us-admin-css
Data Attributes
data-slider-id
JS Globals
ewd_us_helper_noticeewd_us_admin_php_data
FAQ

Frequently Asked Questions about Slider Ultimate